Third-party risk · TPRM · NIS2

Third-Party Risk & NIS2

Your suppliers and subcontractors have become your primary attack surface. We set up a proportionate third-party risk management (TPRM) programme that meets NIS2 supply-chain requirements.

The risk has moved to your suppliers

Most major incidents now flow through a third party: service provider, software vendor, hosting provider, subcontractor. A weak link in your supply chain compromises your data, services and reputation, however strong your own security is.

The NIS2 directive draws the consequences: in-scope entities must manage supplier and supply-chain risk, with accountability reaching up to management. One-off questionnaires are no longer enough.

You need a living TPRM programme: identify critical third parties, assess them at the right level of scrutiny, contract the right clauses and monitor risk over time.

Our 4-step approach

A TPRM programme your teams can actually run, without adding unmanageable bureaucracy.

01

Third-party mapping and criticality

Inventory of your suppliers and subcontractors, identification of critical third parties and segmentation by risk level (data processed, access, operational dependency).

02

Proportionate assessment framework

Defining due-diligence tiers, questionnaires matched to criticality, leveraging existing certifications (ISO 27001, SOC 2) to avoid redundant assessments.

03

Contractual and NIS2 requirements

Security clauses, incident-notification obligations, audit rights and alignment with the NIS2 directive and your regulatory obligations.

04

Continuous monitoring and governance

Periodic reassessment, third-party risk indicators, treatment plan and management reporting to anchor accountability at the right level.

What you get

  • A map of third parties with their criticality level
  • A reusable, multi-tier due-diligence framework
  • Questionnaire and security-clause templates
  • A third-party risk dashboard and treatment plan
  • A monitoring setup aligned with NIS2 expectations
  • Executive-ready reporting

Who is it for?

  • Entities in scope of NIS2 (directly or via their customers)
  • Software vendors and companies with many subcontractors and cloud dependencies
  • Scale-ups whose customers demand serious supplier management
  • IT and security leaders wanting to industrialise supplier assessments

Frequently asked questions

Am I in scope of NIS2?

NIS2 significantly broadens the scope to many sectors and company sizes, including indirectly through customers who impose their requirements on you. A quick scoping settles your situation.

Do I need to audit every supplier?

No, and it would be counterproductive. Effort is concentrated on critical third parties, with assessment depth tuned to real risk and existing certifications reused.

How is TPRM different from a simple questionnaire?

A questionnaire is a snapshot. TPRM is a continuous programme: mapping, contracting, monitoring and governance over time, with clear accountability.

Can we rely on suppliers’ ISO 27001 or SOC 2?

Yes, fully. A current, relevant certification lowers the assessment level required. The programme is designed to build on that evidence rather than duplicate it.

Take back control of your supplier risk

In 30 minutes we identify your critical third parties and the most useful TPRM foundation for NIS2. You leave with clear priorities.