Skip to main content

NIS 2 Compliance: Why Companies Should Review Their Supplier Contracts Now

Contract management as a key component of efficient NIS 2 implementation

Robin Schmeisser

Robin Schmeisser

Created on 13. August 2026

Tablet-Business

When it comes to cybersecurity, many companies have traditionally focused on classic technical measures. However, with NIS 2, the scope is expanding significantly because, in the future, the EU will scrutinize not only the security of companies, but also their entire supply chains. This makes NIS 2 an essential topic for contract management as well. After all, in practice, many requirements can only be effectively implemented and demonstrated through contractual agreements with suppliers and service providers. 

NIS 2 views cybersecurity as a supply chain responsibility

According to Article 21 of the NIS 2 Directive*, affected entities must "take appropriate and proportionate technical, operational, and organisational measures to manage the risks posed to the security of network and information systems [...] and to prevent or minimise the impact of incidents [...]." These measures are intended not only to protect the organization itself, but also to take into account risks arising from relationships with direct suppliers and service providers.
The directive identifies supply chain security and security-related aspects of relationships between organizations and their direct suppliers as components of cyber risk management. Although NIS 2 does not prescribe how organizations should implement these requirements, contractual agreements are an important tool for establishing security requirements, defining responsibilities, and fulfilling reporting and documentation obligations to regulatory authorities. 

 

Which contracts are particularly relevant

Particular focus is placed on contracts with external IT and digital service providers, including cloud service providers, hosting providers, managed service providers, external IT operations service providers, software as a service (SaaS) providers, and service providers with privileged system access.
The deeper an external partner is integrated into critical business processes or IT systems, the more important it is to determine whether its security measures meet the company’s requirements.


Which contract provisions companies should review

The NIS 2 Directive does not contain any model clauses. However, Article 21 highlights various issues that those responsible should review in existing contracts or incorporate into future ones
 

1. Information security requirements

Under NIS 2, it is no longer sufficient to rely on suppliers to provide an adequate level of security. Contracts must clearly specify the minimum information security standards that service providers must meet. These include organizational and technical security measures, access controls, and encryption requirements, for example. 
(NIS 2 Directive, Article 21, Paragraph 2d).


2. Audit and verification rights

At the same time, NIS 2 requires ensuring the effectiveness of cyber risk management measures. Therefore, companies need the ability to verify the security measures of their service providers, including through:

  • Submission of certifications
  • Provision of audit reports
  • Evidence of implemented security measures
    (NIS 2 Directive, Article 21, Paragraphs 1 and 2d).


3. Reporting of security incidents

The directive requires affected organizations to report significant security incidents to the relevant authorities within specified timeframes. To ensure compliance, service providers must promptly notify their clients of security-related events. Contracts should therefore specify:

  • Definition of reportable incidents
  • Reporting deadlines
  • Information to be provided
  • Responsible contacts

A clear incident notification policy can prevent valuable time from being lost while an incident is already impacting business processes or IT systems.
(NIS 2 Directive, Article 21, Paragraph 2b, and Article 23)


4. Patch and vulnerability management

According to NIS 2, vulnerability management and the disclosure of security vulnerabilities are integral to effective cyber risk management. Relevant contractual provisions include how quickly providers must deploy critical security updates and report detected vulnerabilities and what escalation procedures apply in an emergency.
(NIS 2 Directive, Article 21, Paragraph 2e).


5. Business continuity and crisis management

The directive also requires measures to maintain business operations and manage crisis situations. If external partners provide critical services, the following aspects should be addressed in the contract:

  • Backup strategies
  • Disaster recovery procedures
  • Restart times
  • Support services in the event of a crisis
  • Communication channels during a security incident.

This ensures that external service providers are integrated into the organization’s resilience strategy. 
(NIS 2 Directive, Article 21, Paragraph 2c).


6. Use of subcontractors

Since suppliers often procure services from third parties themselves, companies must ensure transparency regarding these dependencies. This supports the directive’s goal of systematically addressing risks within the supply chain.
For example, contractual provisions may require the disclosure of key subcontractors, communication of security requirements throughout the supply chain, and notification of changes in the subcontractor network.
(NIS 2 Directive, Article 21, Paragraph 2d).


How AI-powered contract management supports NIS 2 implementation

Reviewing existing contracts for NIS 2-related requirements can quickly become overwhelming, especially for larger organizations. Often, several hundred contracts require analysis, evaluation, and modification, if necessary. 
Smart contract management software, such as Fabasoft Contracts, can significantly accelerate this process. AI-powered checklists automatically review contracts for specific content. The AI analyzes the content of existing contracts, identifies potential risks, and presents the results in a clear, organized manner. When adjustments are necessary, the system assists with revising contracts and drafting supplemental agreements. 
Structured analyses and the integrated AI chat function ensure that all necessary information and documents are accessible at any time.


Would you like to learn more about how smart contract management supports NIS 2 compliance? Book a demo now


*) Note: This article focuses exclusively on the requirements of the EU NIS 2 Directive (Directive (EU) 2022/2555). National implementing laws may contain additional or different requirements.