NIS2: Secure Your Weakest Link

The NIS2 directive requires organisations to actively manage the cybersecurity of their entire digital ecosystem. Article 21 goes beyond contractual guarantees: it demands effective verification of the controls implemented by every supplier and ICT provider. For CISOs, responsibility no longer stops at their own infrastructure.

This practical guide shows you how to build a NIS2 third-party due diligence programme at scale, based on evidence review rather than self-declarations.

In this guide, you will find:

  • The NIS2 regulatory landscape: scope, Essential vs Important entities, and the French transposition timeline
  • Article 21 decoded: the "weak link" obligation and supply chain risk management
  • Why threat intelligence and surface scanning are not enough to prove NIS2 compliance
  • A 5-step, evidence-based due diligence strategy you can deploy across your ecosystem
  • The Eramet & Tilkal case study: from a 592 to an 857/1000 score through collaborative remediation

Get the guide

The key figures

21

Article 21, the core of NIS2 third-party obligations

10

NIS2 control domains assessed

5

steps to a scalable due diligence programme

857/1000

the score Tilkal reached after remediation (from 592)

Start your NIS2 gap analysis with our experts

See how CyberVadis helps you verify, segment and continuously improve your third parties to meet NIS2 Article 21. Book a personalised demo to see how it applies to your ecosystem.