Already a CyberVadis client ? You can access your account here
The NIS2 directive requires organisations to actively manage the cybersecurity of their entire digital ecosystem. Article 21 goes beyond contractual guarantees: it demands effective verification of the controls implemented by every supplier and ICT provider. For CISOs, responsibility no longer stops at their own infrastructure.
This practical guide shows you how to build a NIS2 third-party due diligence programme at scale, based on evidence review rather than self-declarations.
In this guide, you will find:

Get the guide
Article 21, the core of NIS2 third-party obligations
NIS2 control domains assessed
steps to a scalable due diligence programme
the score Tilkal reached after remediation (from 592)