NIS Supply Chain Security: What ACN's FAQs MSB.13 to MSB.19 Clarify

On 24 July 2026 ACN published seven FAQs on NIS supply chain security. The four-phase process, the five minimum criteria for supply risk, why not every supply needs requirements, and how to handle public tenders, RTIs and mixed contracts.

September 27, 2026 7 min read

An IT provider's technician working on a client's network cabinet alongside the IT manager Made with AI
Contents
  1. In Brief
  2. The Four-Phase Process (FAQ MSB.13)
  3. Assessing Supply Risk: The Five Minimum Criteria (FAQ MSB.14)
  4. Not Every Supply Needs Requirements (FAQ MSB.15)
  5. Contracts Need the Substance, Not the Wording (FAQ MSB.16)
  6. Public Administrations: Requirements Tailored to What Is Procured (FAQ MSB.17)
  7. Temporary Groupings and Consortia (FAQ MSB.18)
  8. Mixed Contracts (FAQ MSB.19)
  9. Operational Checklist
  10. Frequently Asked Questions
  11. Conclusion
  12. Related Reading
  13. Official Sources

Applies to: essential and important NIS entities, public administrations procuring supplies and services, and suppliers bidding for or contracting with NIS entities.

On 24 July 2026, Italy's National Cybersecurity Agency (ACN) published new interpretive guidance on the process and security requirements NIS entities must adopt to protect their supply chain (ACN announcement). There are seven FAQs, MSB.13 to MSB.19, in the section on baseline security measures. They describe a four-phase process, set the minimum criteria for assessing the risk of a supply and make clear that requirements are tailored to the supply, not extended wholesale to every supplier (ACN FAQs on security measures and incident notification).

In Brief

  • Supply chain security follows four phases: risk assessment of the supply, identification of requirements, enforcement in tender documents and contracts, and periodic verification (MSB.13).
  • The risk assessment considers at least five criteria, from the supplier's access to systems to recovery times and costs (MSB.14).
  • Requirements are not needed for every supply, only for those with potential security impact (MSB.15).
  • Contracts do not have to include every baseline requirement or copy their wording: they must reflect their substantive content (MSB.16).
  • The Article 24 measure categories are tailored, up to excluding some, according to context, risk and the criticality of the service procured (MSB.17).
  • In a temporary grouping of companies (RTI), only the members delivering the security-relevant part of the contract must meet the measures (MSB.18); in mixed contracts, requirements apply proportionately to each service (MSB.19).

The Four-Phase Process (FAQ MSB.13)

ACN sets out the process the baseline security measures already describe for the supply chain and, for each phase, the point of the measure it refers to.

Phase What it requires Measure
Supply risk assessment The risk associated with supplies is assessed and documented. GV.SC-07, point 1
Identification of security requirements Based on the assessment, security requirements for the supply are defined, consistent with the measures applied to the entity's own network and information systems. GV.SC-01, point 1
Enforcement of requirements Requirements are included in requests for offers, tenders (including framework agreements and their documentation), contracts, agreements and conventions for supplies with potential security impact, unless there are justified and documented legal or technical reasons. GV.SC-05, point 1
Verification of requirements Compliance of supplies with the included requirements is verified periodically and documented. GV.SC-07, point 2

The phases are linked: requirements come from the risk assessment, enforcement covers the requirements so defined, and verification checks what was written into the contract documents. A requirement that sits in a contract without a documented assessment behind it, or is never verified, leaves part of the process uncovered.

Assessing Supply Risk: The Five Minimum Criteria (FAQ MSB.14)

For the first phase, point 1 of measure GV.SC-07 requires assessing at least the following criteria:

  1. the supplier's level of access to the NIS entity's network and information systems;
  2. the supplier's access to intellectual property and data, including on the basis of their criticality;
  3. the impact of a serious disruption of the supply;
  4. recovery times and costs if services become unavailable;
  5. the supplier's roles and responsibilities in governing the network and information systems.

This is a minimum: an entity may add its own criteria. In practice the five criteria become the columns of each supply assessment, and completing them is the evidence that the assessment was carried out and documented.

Not Every Supply Needs Requirements (FAQ MSB.15)

ACN clarifies that security requirements do not have to be defined for every supply. Point 1 of measure GV.SC-01 requires them for supplies with potential security impact, which FAQ MSB.8 defines as supplies whose compromise could affect the ability of network and information systems to withstand events that could compromise the availability, authenticity, integrity or confidentiality of data or services.

The first operational step is therefore to separate supplies with potential security impact from those without, and to document the criterion used.

Contracts Need the Substance, Not the Wording (FAQ MSB.16)

For the enforcement phase, ACN makes two points:

  • requests for offers, tenders, contracts, agreements and conventions do not have to include every requirement of the baseline measures: they include those identified by the supply risk assessment, consistent with the measures applied to the entity's own systems;
  • requirements do not have to reproduce the text of the NIS measures: it is enough that they reflect their substantive content.

A contract clause can therefore use the language of the contract and of the service procured, as long as it can be traced to the measure it implements.

Public Administrations: Requirements Tailored to What Is Procured (FAQ MSB.17)

FAQ MSB.17 answers a precise question: are the main measure categories listed in Article 24 of the NIS decree (risk analysis, incident handling, business continuity, supply chain security, security in system development and maintenance) a minimum set that Administrations must always apply?

The answer is no. Their application must be tailored, up to excluding some of them, according to the operating context, the risk level and the criticality of the services procured by each Administration. ACN gives the example of non-ICT services such as cleaning, security guarding without digital tools like video surveillance, or design work without BIM: the administration keeps its general cybersecurity risk-management obligations, but the requirements applied to the supplier must match the subject of the contract and its actual risk profile.

Temporary Groupings and Consortia (FAQ MSB.18)

When the winning bidder is a temporary grouping of companies (RTI) or a consortium, the security measures must be met only by the members delivering, even partially, the part of the contract with cybersecurity impact. ACN refers to the different roles and division of work within the grouping, and to the NIS principles of accountability, adequacy and proportionality, consistent with a risk-based approach.

For the buyer, this means stating which parts of the service have security impact. For a bidder in an RTI, it means documenting which company delivers those parts.

Mixed Contracts (FAQ MSB.19)

In contracts combining services of different kinds, for example ICT and non-ICT components, requirements apply according to their proportionality, relevance and adequacy to the specific services procured. ACN asks buyers to avoid imposing blanket obligations that do not fit the nature of the contract or the cybersecurity risk actually identified.

Operational Checklist

  1. List supplies and identify those with potential security impact (MSB.8, MSB.15), documenting the criterion.
  2. Assess and document the risk of each such supply using at least the five GV.SC-07 criteria (MSB.14).
  3. Derive security requirements from the assessment, consistent with the measures applied to your own systems (GV.SC-01).
  4. Include the requirements in tender documents and contracts, in a form suited to the service; document the legal or technical reasons for any exception (GV.SC-05, MSB.16).
  5. In mixed contracts and awards to RTIs, tie requirements only to the services and members with security impact (MSB.18, MSB.19).
  6. Verify supplier compliance periodically and keep the evidence (GV.SC-07, point 2).

Frequently Asked Questions

Must a NIS entity include security requirements in every supply contract?

No. Under FAQ MSB.15, requirements are defined for supplies with potential impact on the security of network and information systems, identified using the definition in FAQ MSB.8.

Must contracts reproduce the text of the NIS security measures?

No. FAQ MSB.16 states that reflecting the substantive content of the applicable measures is enough, and that not every baseline requirement has to be included.

Must a cleaning contractor meet every Article 24 requirement?

No. FAQ MSB.17 states that, for non-ICT services such as cleaning, the requirements applied to the supplier must match the subject of the contract and the actual risk, while the administration keeps its general risk-management obligations.

In an RTI, must every company meet the security measures?

No. Under FAQ MSB.18, the measures must be met only by the members delivering, even partially, the part of the contract with cybersecurity impact.

Conclusion

FAQs MSB.13 to MSB.19 add no new obligations: they explain how to apply those already in the baseline measures proportionately. The core is traceability: from the documented supply risk assessment to the requirements, from the requirements to the contracts, and from the contracts to periodic verification.

We can help you build this process, from supply assessment to contract clauses and periodic verification, through NIS 2 consulting and our Virtual CISO service.

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 17, 2026

NIS 2 Supply-Chain Security: Managing Critical Suppliers and High-Impact Procurements

NIS 2 supply-chain security is a governance obligation covering supplier identification, risk assessment, contractual integration, and lifecycle moni…

February 02, 2026

NIS 2 supplier register and supply-chain controls: practical guide for an auditable vendor inventory

NIS 2 baseline includes supply-chain security as a dedicated control area (GV.SC). This guide covers what a NIS 2-ready supplier register must contai…

January 30, 2026

NIS 2 Governance Controls (GV): Policies, Roles, and Accountability Model

The NIS 2 Governance (GV) domain defines cybersecurity direction, accountability, and oversight. Practical guide to implementing GV controls: context…