NIS2 Article 21(2)(d): supply chain security
Under measure (d), your suppliers' security becomes part of yours. A questionnaire tells you what a supplier says about itself. Our free check shows you what anyone can see on its domain today, and turns what we find into questions you can put to them.
Written by the SkyQon engineering team · Last checked against the legal texts on 2 October 2026
What the Directive requires
Article 21(2)(d) of Directive (EU) 2022/2555 asks for supply chain security, including the security side of your relationship with each direct supplier or service provider. Article 21(3) goes further: you have to take into account the weaknesses specific to each direct supplier and the overall quality of its products and security practices, including how it develops software securely.
For the digital providers it covers, Implementing Regulation (EU) 2024/2690 asks for a written supply chain security policy, with criteria for choosing suppliers and regular checks on how their security holds up.
Official text: Directive (EU) 2022/2555 · Implementing Regulation (EU) 2024/2690
What the supplier check gives you
The supplier check runs the same scan as our ordinary free check and gives the same Domain Check Score, only on your supplier's domain. On top of that you get:
- Up to six questions for the supplier, each next to the observation it came from, such as an expired certificate or a DMARC policy that doesn't stop spoofing.
- Questions only about what we actually saw. If we couldn't measure something, we don't make it the supplier's problem.
- Nothing kept. We don't save the result, there is no shareable report grading the supplier, and we don't contact them.
A typical case
Your payroll provider emails you invoices every month. The check shows its domain has a DMARC policy that doesn't block spoofing, so anyone could send a convincing invoice in its name. That gives you a fair, specific question for your next call: how do they stop fake invoices going out under their name? It is a better start than a forty-question form.
This is a composite of things we often see, not a specific customer.
What it doesn't tell you
We only see the supplier's public domain. Its contracts, development process, staff and internal systems are invisible to us, and this is not an audit of the supplier. It also says nothing about your own supplier process. How you choose suppliers, what you put in the contract and how often you review them is the part of measure (d) only you can show.
What an assessor expects
Assessors look for a supplier register, a clear idea of which suppliers are critical, and signs that you keep reviewing them after the contract is signed. Notes on what you checked, when, and what you asked are what make that review visible.
Checking suppliers every day
Supplier Monitoring is an add-on that re-checks the suppliers you register every day, using the same score as this free check. It tells you when one slips and lets you export a signed supplier register. It is evidence for your own review process. It is not a statement about the supplier.
More about the free supplier check · Supplier Monitoring pricing
Check a supplier before you send the questionnaire
All you need is the supplier's domain. We keep nothing afterwards.
The other measures
Article 21(2) has ten measures in total. Most of them are about how you work inside the company, and we can't see those from outside. Our longer guide goes through all ten and says which ones leave something visible.
- All ten measures: what counts as evidence
- 21(2)(e) Maintenance and vulnerability handling
- 21(2)(f) Showing that your measures work
- 21(2)(g) Basic cyber hygiene
- 21(2)(h) Cryptography and encryption
- A one-page NIS2 summary for your managing director
We explain the law here as plainly as we can, but this is not legal advice. NIS2 reaches you through your own country's law, and the details differ from one country to the next.