Torna al Blog

    NIS2 supplier qualification: a practical guide with checklist and questionnaire

    11 ottobre 2026

    NIS2 requires essential and important entities to know which suppliers can affect the security of their systems, assess the risk of each supply, put security requirements into contracts and verify them over time. In Italy these obligations are set out in the baseline security measures of the National Cybersecurity Agency (ACN), under the GV.SC category of the National Cybersecurity Framework. Entities placed on the NIS list in 2025 must have them in place by 31 October 2026, after which the ACN can start audits and inspections. This guide explains what the measures require, how to build a supplier qualification procedure in seven steps and which evidence to keep ready.

    Leggi questo articolo in italiano: Qualifica fornitori NIS2: guida pratica alle misure ACN.

    In short

    • Who is affected: essential and important entities under Italian Legislative Decree 138/2024, which transposes the NIS2 Directive. SMEs outside the scope are drawn in as suppliers to NIS entities.
    • Deadline: 31 October 2026 for entities listed since 2025; 31 July 2027 for those added in 2026.
    • What is needed: a supplier inventory, a risk assessment of each supply, security requirements in contracts, documented periodic verification.
    • Every year, on top: reporting relevant suppliers (ICT or non-substitutable) to the ACN between 15 April and 31 May.
    • The critical point: doing the work is not enough, you have to be able to prove it.

    What the ACN baseline measures require on the supply chain

    The baseline security measures are defined by ACN Determination no. 379907/2025, which updated the earlier no. 164179/2025, and are built on the Italian National Framework for Cybersecurity and Data Protection, itself derived from the NIST Cybersecurity Framework. The supplier category is GV.SC, cybersecurity supply chain risk management, complemented by the inventory of services provided by suppliers in the asset management category. The table summarizes the requirements for essential entities; important entities follow the same structure with fewer requirements, so check the annex for your own category.

    Measure What it requires Evidence to keep
    GV.SC-01 Involve the information security function in procurement from the design of the supply, and define security requirements consistent with your own measures, based on the risk assessment. Procurement procedure that requires the security function’s opinion; requirements by type of supply.
    GV.SC-02 Define and communicate the security roles and responsibilities assigned to third-party staff. List of external contacts with security roles, included in the security organization.
    GV.SC-04 Keep an up-to-date inventory of suppliers with a potential security impact, including at least the contact person and the type of supply. Supplier register with criticality, contact, type of supply, date of last update.
    GV.SC-05 Include security requirements in requests for quotation, tenders, contracts and agreements, unless justified and documented regulatory or technical reasons apply. Contracts and specifications with security clauses; written justification for exceptions.
    GV.SC-07 Assess and document the risk of each supply and periodically verify compliance with the requirements. Assessment sheet per supplier; log of periodic checks.
    ID.AM-04 Keep an inventory of IT services provided by suppliers, including cloud services. Inventory of external services linked to suppliers and systems.

    Measure GV.SC-01 also lists the areas in which requirements should be defined, where applicable: supplier reliability and ability to guarantee support and maintenance over time, roles and responsibilities, personnel reliability, compliance and audit, vulnerability management, business continuity and disaster recovery, identity and access control, physical security, training, data security, network protection, event monitoring, incident management and reporting, secure development, maintenance and security updates, end of supply with return and deletion of data, and subcontracting. It is the natural outline for a qualification questionnaire.

    Suppliers “with an impact” and “relevant” suppliers are not the same list

    This is the most common confusion. The baseline measures require an inventory of all suppliers whose supplies have a potential impact on security of information systems and networks: a broad internal list used to manage risk.

    ACN Determination no. 127437 of 13 April 2026 introduced a separate obligation to report relevant suppliers to the ACN as part of the annual information update, between 15 April and 31 May. A supplier is relevant if it meets at least one of two criteria:

    • ICT supply falling under the digital infrastructure and ICT service management activities in Annex I of the Italian NIS decree: cloud, data centres, DNS, managed services and managed security services;
    • non-substitutable supply, whose interruption would significantly affect the NIS entity’s services because no alternative can be activated in time. The ACN FAQs give non-redundant connectivity and electricity as examples.

    For each relevant supplier the entity reports name, tax code, registered office, the CPV codes of the supplies and the relevance criterion met. Relevant suppliers are therefore a subset of the inventory: it is easier to keep a single supplier register with an attribute that flags them than two lists that must be kept aligned.

    The qualification procedure in seven steps

    1. Inventory of suppliers with a security impact

    Start from the supplier master data in your ERP and the active contracts, not from a new spreadsheet. Select the suppliers that access systems, networks, data or plants, those that provide IT and cloud services, and those on which business continuity depends. For each one, record the contact person, type of supply, systems and data involved and services provided.

    2. Criticality classification

    Criticality is based on the five factors measure GV.SC-07 asks you to assess: level of access to systems, access to data and intellectual property, impact of a serious interruption, recovery time and cost, and the supplier’s role in running the systems. A three-level matrix is enough for most SMEs.

    Level When Examples What to request
    High Administrative access to systems, critical data, non-substitutable supply. MSPs and systems support, cloud hosting the ERP, single connectivity provider, ERP or MES software vendor. Full questionnaire, certifications (ISO/IEC 27001 with scope), evidence on backup and incidents, full clauses, annual review.
    Medium Limited or occasional access, non-critical internal data, alternatives available. Plant maintenance with remote support, departmental SaaS, consultants with user accounts. Short questionnaire, essential clauses, review every two years.
    Low No access to systems or data, easily replaceable supply. Catalogue hardware, IT consumables. Self-declaration, standard purchasing terms.

    3. Security requirements by level

    From the seventeen areas listed in GV.SC-01, choose the ones that apply to each level and type of supply. A cloud provider must answer on continuity, data and deletion at the end of the contract; a maintenance contractor with remote support on remote access, authentication and session logging. Requirements must be consistent with the measures the company applies to itself: you cannot demand multi-factor authentication from a supplier if your own administrative access does not use it, and vice versa.

    4. Questionnaire and evidence

    A single questionnaire, modular by level, avoids inventing different questions for each supplier. The minimum questions for a high-criticality supplier:

    • Do you have a certified ISO/IEC 27001 management system? With which scope, certification body and expiry date? Does the scope cover the service you provide to us?
    • How do you manage vulnerabilities, and how quickly do you apply critical security updates?
    • How do your staff access our systems? Are accounts personal, protected by multi-factor authentication and logged?
    • How quickly will you notify us of an incident affecting our data or services, and to whom?
    • What are the RTO and RPO of the service? When did you last test a restore?
    • Do you use subcontractors for the service? Which ones, and under which security requirements?
    • How do you return and delete our data at the end of the contract?

    Every answer should point to a document: certificate, policy, test report. An answer without evidence counts as a gap to clarify.

    5. Contract clauses

    The ACN FAQs make clear that there is no universal clause to copy into every contract: contractual requirements follow from the risk assessment of each supply. The clauses that recur in contracts with high-criticality suppliers cover incident notification within defined times, the right to audit or to request evidence, access and authentication requirements, vulnerability management, service continuity, limits and requirements for subcontracting, and return and deletion of data on termination. If the supplier processes personal data, the processor agreement under Article 28 GDPR should be handled at the same time. When a clause cannot be included, for example with a large cloud provider on standard terms, measure GV.SC-05 requires the exception to be justified and documented.

    6. Assessment and decision

    The assessment sheet brings together answers, evidence and gaps, and ends with an explicit decision: qualified, qualified with reservations and a remediation plan, or not qualified. The decision is made by people, with a date and a name. If the supplier is qualified with reservations, the remediation plan has deadlines that someone tracks.

    7. Monitoring and requalification

    Compliance must be verified periodically, not only at first qualification. The natural triggers are certificate expiry, contract renewal, a change of service or scope, and an incident involving the supplier. A deadline register with automatic reminders turns requalification from an exceptional event into routine.

    Evidence to keep ready for an ACN inspection

    From 1 November 2026 the ACN moves from its support phase to supervision. For the supply chain, an inspector will expect to find:

    • the approved qualification procedure, with the security function involved in procurement;
    • the dated, up-to-date inventory of suppliers with a security impact and of external services;
    • the criticality classification and the criteria used;
    • risk assessment sheets per supply, with questionnaires and collected evidence;
    • contracts with security clauses and the justification for exceptions;
    • the log of periodic checks and remediation plans;
    • consistency between the internal inventory and the list of relevant suppliers reported to the ACN.

    If this information lives in separate files, the real work starts on the day of the inspection. If it is linked together, you only need to extract it.

    The most common mistakes

    • A hundred-question questionnaire for everyone. Suppliers do not answer, and critical suppliers answer the same way as irrelevant ones. Proportionality to risk is a requirement, not a concession.
    • Accepting an ISO 27001 certificate without reading its scope. A certificate covering the head office says nothing about the cloud service delivered to you from another site.
    • Qualify once and forget. The measures require documented periodic verification.
    • Keeping the supplier register separate from the ERP. New suppliers come in through purchasing and nobody assesses them.
    • Ignoring subcontractors. The risk often sits one link further down: the MSP that relies on a third-party remote access service.

    If your company is the supplier

    Many manufacturing and service SMEs are not NIS entities themselves but supply customers that are. For them, NIS2 arrives as questionnaires, certificate requests and contract clauses. The most effective strategy is to prepare a single package of answers and documents once (policies, access and vulnerability management, incident response plan, continuity) and keep it up to date, instead of starting from scratch for every customer. An ISO/IEC 27001 management system makes that package credible and verifiable.

    How we handle it with JobTracker3 Compliance

    In JobTracker3 Compliance the supplier register starts from the master data and purchasing of the JobTracker3 ERP, so a new supplier cannot skip qualification. Each supplier has questionnaires, certificates with expiry dates, a score and a qualification status, and is linked to the IT assets and services it provides, to the risks in the ISO/IEC 27001 management system and, when it processes personal data, to the processing activities in the GDPR register. Deadlines raise reminders and every record is dated and attributed, so the evidence for an inspection is already linked to the requirements. The same approach covers ISO/IEC 27001 controls A.5.19 to A.5.22 and ISO 9001 §8.4 on external providers.

    Eulogika applies these measures to its own management system, certified to ISO/IEC 27001:2022, and supports companies in NIS2 compliance and ISO 27001 certification projects.

    Frequently asked questions

    Is supplier qualification mandatory under NIS2?

    Yes, for essential and important entities. Article 21 of the NIS2 Directive, and Article 24 of the Italian Legislative Decree 138/2024 that transposes it, include supply chain security among the risk management measures, and the ACN baseline measures in the GV.SC category require a supplier inventory, risk assessment of supplies, contractual requirements and periodic checks.

    What is the deadline in Italy?

    Entities placed on the NIS list in 2025 must adopt the baseline measures by 31 October 2026. For entities added in 2026, ACN Determination no. 127434/2026 sets the deadline at 31 July 2027.

    What is a relevant NIS supplier?

    A provider of ICT services falling under Annex I of the Italian NIS decree, such as cloud, data centres and managed services, or a non-substitutable supplier whose interruption would significantly affect the NIS entity’s services. Relevant suppliers must be reported to the ACN every year between 15 April and 31 May.

    Is an ISO 27001 certified supplier enough?

    Not on its own. Certification is strong evidence, but you must check that its scope covers the service provided, that it is still valid, and that the specific requirements of the supply, such as incident notification times and data deletion, are in the contract.

    How often should suppliers be reassessed?

    The measures require documented periodic verification without setting a single frequency. A common practice is annual review for high-criticality suppliers and every two years for medium-criticality ones, with earlier requalification when certificates expire, contracts are renewed, the service changes or after an incident.

    Do you need to set up supplier qualification before 31 October, or answer your customers’ NIS2 questionnaires? Contact us: we start from the supplier list you have today.

    Sources