NIS2

The EU directive on a high common level of cybersecurity, which requires essential and important entities to manage cybersecurity risks, including in their supply chain (Directive (EU) 2022/2555).

Member states had to apply it from 18 October 2024. Article 21 lists the risk-management measures entities must take, and supply chain security, including the security of relationships with direct suppliers and service providers, is one of them (Article 21(2)(d)). For organisations in scope, knowing what their suppliers change is part of a legal duty.

Source: Directive (EU) 2022/2555 ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.