Supply chain
Critical suppliers, the supplier register and the controls on the digital supply chain that NIS 2 requires.
All articles
NIS Supply Chain Security: What ACN's FAQs MSB.13 to MSB.19 Clarify
On 24 July 2026 ACN published seven FAQs on NIS supply chain security. The four-phase process, the five minimum criteria for supply risk, why not eve…
ACN NIS Platform: Relevant Suppliers and What Organizations Must Submit
The ACN platform requires NIS subjects to submit a filtered list of 'relevant NIS suppliers' during the annual update window (15 April-31 May) - not …
NIS 2 Supply-Chain Security: Managing Critical Suppliers and High-Impact Procurements
NIS 2 supply-chain security is a governance obligation covering supplier identification, risk assessment, contractual integration, and lifecycle moni…
EU Cybersecurity Act Revision - COM(2026) 11: What Changes and Why It Matters
The European Commission's January 2026 proposal to revise the EU Cybersecurity Act: supply-chain risk governance, simplified certification (ECCF), EN…
NIS 2 supplier register and supply-chain controls: practical guide for an auditable vendor inventory
NIS 2 baseline includes supply-chain security as a dedicated control area (GV.SC). This guide covers what a NIS 2-ready supplier register must contai…
Cybersecurity Monthly Report - January 2026 (Italy, EU, Global)
Aegister’s January 2026 monthly cybersecurity report: EU cybersecurity package with Cybersecurity Act revision and NIS 2 simplification amendments, D…
NIS 2 Governance Controls (GV): Policies, Roles, and Accountability Model
The NIS 2 Governance (GV) domain defines cybersecurity direction, accountability, and oversight. Practical guide to implementing GV controls: context…
DORA in Italy: Implementation, Compliance, and Operational Resilience
Italy transposes the EU's Digital Operational Resilience Act (DORA) with new obligations for financial institutions on ICT risk, incident response, a…
Cybersecurity Monthly Report - January 2025 (Italy, EU, Global)
Aegister's January 2025 monthly cybersecurity report: DORA goes live, NIS 2 registration milestones, key vulnerabilities (VPN/edge), ransomware polic…