NIS2 · Third-party security

Your Supply Chain Is In Scope by Kai London

NIS2 makes supply-chain security a named risk management measure, which means an entity has to be able to show how it chooses, contracts with, assures and monitors its suppliers — not merely that it asked them some questions. This book is a programme design guide for that obligation.

Coming soonAll books

What the book covers

Scoping the supplier estate

Discovery across procurement, IT and shadow arrangements, and deciding which relationships are in scope.

Risk-based tiering

Segmenting suppliers by consequence and access, so effort is proportionate and defensible.

Contractual measures

Security requirements, notification windows, audit and testing rights, subcontracting and exit.

Assurance methods

Certifications, attestations, testing, on-site review and continuous monitoring — and when each is appropriate.

Ongoing oversight

Re-assessment cadence, issue management, escalation and supplier remediation tracking.

Supervisory evidence

The documented trail showing the programme exists, operates and informs decisions.

General guidance, not legal advice; member-state implementations differ, so take qualified advice on your obligations. Independent, with no endorsement by or affiliation with any regulator or standards body.

NIS2 Article 21ISO 27036DORANIST CSF 2.0

Who it is for

Essential and important entities — their CISOs, third-party risk and procurement teams, contract and legal functions, and internal audit.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.