why-supply-chain
Most small web agencies think of NIS2 as a rule about their own security: patch your servers, enable MFA, have an incident plan. That is half of it. The other half — and the part regulators are increasingly focusing on — is Article 21(2)(d), which makes supply chain security an explicit legal requirement for every essential and important entity.
For a web agency, the supply chain is not an abstract concept. It is your hosting provider, your CDN, your plugin vendors, the freelance developer who had admin access last spring, the email platform you configure for clients, and the backup service nobody has checked in two years. Under NIS2, the security of those vendors is your problem — and you must be able to demonstrate how you manage that risk.
📜 Article 21(2)(d)
Entities must address security risks relating to "the relationships between each entity and its direct suppliers or service providers." It is a direct legal duty, not best practice.
🔗 You Are in Two Chains
As an agency you sit in the middle: your clients depend on you, and you depend on dozens of vendors. NIS2 obligations flow in both directions.
🧾 Evidence Over Promises
Supervisory authorities expect documented vendor assessments, contract clauses and exit plans — not a policy document that says "we choose reputable vendors."