Operational methodology to meet the supply chain security obligation

NIS2 & Compliance
NIS2 Supply Chain Guide: From Art. 21 to the Provider Register
Article 21.2.d of NIS2 requires essential and important entities to manage the security of their direct suppliers and service providers as part of their risk management policy. This guide explains what the article actually requires, how it relates to the ENS and DORA, and proposes a phased implementation plan with checklists and a reusable supplier assessment questionnaire template.
Article 21.2.d of NIS2 requires essential and important entities to manage the security of their direct suppliers and service providers as part of their risk management policy. This guide explains what the article actually requires, how it relates to the ENS and DORA, and proposes a phased implementation plan with checklists and a reusable supplier assessment questionnaire template.
The preview of this whitepaper includes the executive summary, regulatory context and methodological approach that frames the rest of the document. Download to access full templates, matrices and checklists.
Gorka Gonzalo
Founder & CEO
Founded Hodeitek in 2023 and runs the company. A cybersecurity and AI expert, he sets the technical and product direction of HodeiShield and personally leads the most critical engagements — from defense strategy to applying AI in threat detection. He is the client's direct point of contact: whoever scopes the work also answers for the result.
“This whitepaper is the clearest guide I've seen on NIS2 in 2026.”
The Esquema Nacional de Seguridad (RD 311/2022) sets the minimum security requirements for the information systems of Spanish public administrations and of the companies that provide services to them. This guide explains how to determine a system's category, what Annex II requires, how the audit and certification process with ENAC works, and provides a phased adequacy plan with a reusable checklist and template.
NIS2, DORA and the ENS all agree that provider risk cannot be outsourced away by subcontracting the service, which turns third-party risk management (TPRM) into a mandatory compliance function. This document explains what each framework requires on third parties, the five criteria blocks that separate a functional TPRM platform from the rest, and provides a reusable evaluation matrix for RFP/RFI processes.
Regulation (EU) 2022/2554 (DORA) has applied directly across the EU since 17 January 2025 and governs how financial entities must manage ICT risk, classify and notify incidents, test their resilience (including TLPT) and manage their technology providers. This manual translates DORA's five pillars into a step-by-step implementation plan, with an exhaustive checklist per pillar and a reusable ICT provider factsheet template.