Supply chain

Critical suppliers, the supplier register and the controls on the digital supply chain that NIS 2 requires.

All articles

September 27, 2026

NIS Supply Chain Security: What ACN's FAQs MSB.13 to MSB.19 Clarify

On 24 July 2026 ACN published seven FAQs on NIS supply chain security. The four-phase process, the five minimum criteria for supply risk, why not eve…

April 16, 2026

ACN NIS Platform: Relevant Suppliers and What Organizations Must Submit

The ACN platform requires NIS subjects to submit a filtered list of 'relevant NIS suppliers' during the annual update window (15 April-31 May) - not …

February 17, 2026

NIS 2 Supply-Chain Security: Managing Critical Suppliers and High-Impact Procurements

NIS 2 supply-chain security is a governance obligation covering supplier identification, risk assessment, contractual integration, and lifecycle moni…

February 05, 2026

EU Cybersecurity Act Revision - COM(2026) 11: What Changes and Why It Matters

The European Commission's January 2026 proposal to revise the EU Cybersecurity Act: supply-chain risk governance, simplified certification (ECCF), EN…

February 02, 2026

NIS 2 supplier register and supply-chain controls: practical guide for an auditable vendor inventory

NIS 2 baseline includes supply-chain security as a dedicated control area (GV.SC). This guide covers what a NIS 2-ready supplier register must contai…

January 31, 2026

Cybersecurity Monthly Report - January 2026 (Italy, EU, Global)

Aegister’s January 2026 monthly cybersecurity report: EU cybersecurity package with Cybersecurity Act revision and NIS 2 simplification amendments, D…

January 30, 2026

NIS 2 Governance Controls (GV): Policies, Roles, and Accountability Model

The NIS 2 Governance (GV) domain defines cybersecurity direction, accountability, and oversight. Practical guide to implementing GV controls: context…

June 03, 2025

DORA in Italy: Implementation, Compliance, and Operational Resilience

Italy transposes the EU's Digital Operational Resilience Act (DORA) with new obligations for financial institutions on ICT risk, incident response, a…

January 31, 2025

Cybersecurity Monthly Report - January 2025 (Italy, EU, Global)

Aegister's January 2025 monthly cybersecurity report: DORA goes live, NIS 2 registration milestones, key vulnerabilities (VPN/edge), ransomware polic…