Skip to content

Compliance · EU · Essential & important entities

NIS2 Directive

The EU directive extending cybersecurity obligations across essential and important entities — with explicit supply-chain security duties under Article 21.

All frameworks

Who's in scope

Medium and large entities in essential and important sectors across the EU, and suppliers within their scope.

What it requires

  • Adopt risk-management measures proportionate to the threat, including supply-chain security (Art. 21).
  • Assess the security posture of direct suppliers and service providers.
  • Report significant incidents within defined deadlines.

How TrustQuant helps

  • Automated vendor evaluation to satisfy Article 21 supply-chain oversight.
  • Standardised resilience ratings that make supplier comparisons defensible.
  • Continuous evidence that reduces the cost of demonstrating compliance.

This guide is for preparation only and is not legal advice. Confirm your specific obligations with qualified counsel.

Demonstrate NIS2 with verified evidence

Continuous, real-time posture evidence — mapped to the standards your buyers ask about.