Compliance · EU · Essential & important entities
NIS2 Directive
The EU directive extending cybersecurity obligations across essential and important entities — with explicit supply-chain security duties under Article 21.
All frameworks
Who's in scope
Medium and large entities in essential and important sectors across the EU, and suppliers within their scope.
What it requires
- Adopt risk-management measures proportionate to the threat, including supply-chain security (Art. 21).
- Assess the security posture of direct suppliers and service providers.
- Report significant incidents within defined deadlines.
How TrustQuant helps
- Automated vendor evaluation to satisfy Article 21 supply-chain oversight.
- Standardised resilience ratings that make supplier comparisons defensible.
- Continuous evidence that reduces the cost of demonstrating compliance.
This guide is for preparation only and is not legal advice. Confirm your specific obligations with qualified counsel.
Demonstrate NIS2 with verified evidence
Continuous, real-time posture evidence — mapped to the standards your buyers ask about.