heldr.Supply chain check

Your supplier's cyber gap can become your NIS2 problem

Written by Heldr cyber team2 August 20268 min read

Critical suppliers need more than a contract. Know their access, dependencies and incident commitments.

In brief

  • Prioritise suppliers by business impact.
  • Record what systems and data they can access.
  • Test notification and recovery agreements before an incident.

Not every supplier is equally critical

Focus first on parties that can stop a core process, reach sensitive data or connect directly to your systems. Their safeguards belong in your own risk picture.

A small payroll provider can be more critical than a much larger office supplier. Size and contract value say little about operational dependency. Rank suppliers by what happens to your customers and employees when their service fails.

Turn promises into proof

Ask for concrete controls, named contacts and tested response times. A certificate helps, but it does not replace evidence about the service you actually use.

Translate promises into operating agreements. How quickly will the supplier notify you, what information will you receive, who leads recovery and how can you retrieve your data if the relationship ends? If the answer is only best effort, your continuity plan must account for that.

Look beyond the direct supplier

Your supplier often depends on cloud platforms, identity providers, data processors and software components of its own. You do not need a complete map of the internet, but you do need to know where one failure could affect several critical services at once.

Ask critical suppliers which subcontractors support your service and how changes are communicated. Concentration risk deserves special attention. Five contracts can still represent one dependency when every provider runs on the same underlying platform.

Test the relationship, not just the paperwork

Run a short exercise with one critical supplier. Simulate unavailable systems or stolen credentials and observe whether contact details, escalation routes and recovery assumptions still work. A ninety-minute exercise can reveal more than another questionnaire.

Close the loop by assigning every finding to an owner and date. Supplier risk management fails when reviews happen once during procurement and are never revisited as services, access and subcontractors change.

Sources and further reading

Last reviewed on 2 August 2026. Legislation and official guidance may change.

Not compliant yet?

Start the free AI Compliance Scan and know where you stand in 30 minutes.

Start the scan

Related within this theme