Supply chain risk: responsibility does not end at your firewall
Your own security level is only as high as that of your service providers. Yet many organizations treat supplier review as a one-time questionnaire that gets filled in and forgotten. NIS2 turns it into a continuous obligation. isidaten manages suppliers, contracts and processors as traceable objects instead of an Excel silo.
Most security concepts stop at the edge of the own network. Yet a significant share of risk sits outside it: with the cloud provider, the maintenance contractor, the software supplier. Your own security level is only as high as that of the partners you hand data and access to. When something goes wrong there, it is still your responsibility.
The questionnaire that gets filed and forgotten
In many organizations supplier review consists of a one-time questionnaire. It is sent at the start of the relationship, returned filled in, filed in a folder and never looked at again. That produces a piece of paper, but no security. Whether the provider still runs the same safeguards two years later, nobody knows. Third-party risk is not a state you establish once, but one that changes constantly.
NIS2 turns the optional into an obligation
With NIS2, supply chain security is explicitly part of the risk management duties. Affected entities must assess and control the risks of their providers and suppliers, not once, but continuously. A voluntary diligence becomes a duty you have to prove. Anyone showing up with a collection of old PDF questionnaires has made the same evidence mistake as at any other deadline.
What continuous supplier management means
isidaten treats third parties not as an attachment but as traceable objects:
- Questionnaires with status: security and data protection questionnaires are sent, tracked by status and assessed once returned, instead of getting lost in an inbox.
- Contracts with deadlines: contracts and their deadlines are held with reminders, so renewal, termination and reassessment do not hang on one person's calendar.
- Processors and data transfers: who processes which data and where is documented, including the transfers that need a legal basis.
- Recurring assessment: the review is not a one-time act but a repeatable process with a traceable history.
One object base: supplier, contract, risk, evidence
The difference is where a recognized supplier risk goes. In isidaten the supplier is the same object across all areas: questionnaire, contract, processor and risk register all reference the same provider instead of holding it multiple times in separate tools and folders. A recognized gap therefore does not stay stuck in a filed document but can be carried on as a risk with a measure and a documented decision. Scattered single documents become a coherent state that an audit can follow.
The link to NIS2
For entities under NIS2 this closes one of the most common gaps: the supply chain as a blind spot. Anyone who keeps suppliers, contracts and processors in one place and connects them to risk management can not only claim the required diligence but prove it. How isidaten maps this we show on our solutions page, or directly in a demo.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.