Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.1.15 Protection of information in cooperation with suppliers

Control Overview

This control requires the organization to establish a robust third-party risk management framework to evaluate and monitor the cybersecurity posture of its suppliers. To prevent security incidents caused by a compromised upstream dependency, the organization must ensure that all third-party services and products meet its internal information security requirements. This involves conducting rigorous pre-onboarding assessments, categorizing suppliers by criticality, establishing legally binding security and privacy terms, and conducting periodic reviews to manage ongoing supply chain risks.

note

Applicability Note: This control is fully applicable to the anDREa platform, particularly across critical cloud infrastructure, SaaS vendors, and development sub-processors.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement is seamlessly driven by our ISO/IEC 27001-based ISMS, treating supply chain security as an extension of our own internal risk posture.

anDREa manages third-party risk through a structured lifecycle. Before onboarding any vendor, we conduct a formal SIA Instructions to understand data flows, architecture, and potential vulnerabilities. Suppliers are added to a centralized inventory and assigned a criticality level based on their access to systems and data. High-criticality vendors must provide formal security assurances (e.g., ISO 27001 certifications, SOC 2 reports) and execute comprehensive Data Processing Agreements (DPAs) and Non-Disclosure Agreements (NDAs). Supplier access to our environments is strictly governed by our core identity management framework, ensuring third-party accounts are monitored and bounded by least-privilege principles.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.19 - Information security in supplier relationshipsMandates requirements for mitigating the information security risks associated with the use of supplier products and services.
Pre-Onboarding EvaluationSIA RegisterThe mandatory risk assessment blueprint used to analyze and approve a vendor's technical controls prior to engagement.
Centralized InventoryanDREa Supplier ListThe master ledger tracking all active third parties, mapped by their criticality classification and operational dependencies.
Vendor DossiersSupplier FoldersCentralized audit repositories containing signed contracts, DPAs, NDAs, and validated external security certifications.
Operational ReviewsanDREa Supplier ListDocumented evaluations tracking ongoing vendor performance, continuous risk ratings, and certification renewals.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Supplier impact assessments, contracts, dossiers, and access boundaries are fully operationalized and managed. Continuous Improvement: To optimize readiness for upcoming NIS 2 audits, maintain an explicit cross-reference in your NIS 2 register that links critical suppliers directly to any designated "essential" or "important" service infrastructure dependencies.