Your Supply Chain Is In Scope by Kai London
NIS2 makes supply-chain security a named risk management measure, which means an entity has to be able to show how it chooses, contracts with, assures and monitors its suppliers — not merely that it asked them some questions. This book is a programme design guide for that obligation.
What the book covers
Scoping the supplier estate
Discovery across procurement, IT and shadow arrangements, and deciding which relationships are in scope.
Risk-based tiering
Segmenting suppliers by consequence and access, so effort is proportionate and defensible.
Contractual measures
Security requirements, notification windows, audit and testing rights, subcontracting and exit.
Assurance methods
Certifications, attestations, testing, on-site review and continuous monitoring — and when each is appropriate.
Ongoing oversight
Re-assessment cadence, issue management, escalation and supplier remediation tracking.
Supervisory evidence
The documented trail showing the programme exists, operates and informs decisions.
General guidance, not legal advice; member-state implementations differ, so take qualified advice on your obligations. Independent, with no endorsement by or affiliation with any regulator or standards body.
Who it is for
Essential and important entities — their CISOs, third-party risk and procurement teams, contract and legal functions, and internal audit.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.