Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.1.18 Monitoring, evaluation and change management of supplier services

Control Overview

This control mandates that the organization establishes a risk-based framework to continuously monitor and evaluate active suppliers. Rather than relying solely on pre-onboarding checks, the organization must dynamically adjust its oversight based on vendor criticality. This requires tracking ongoing service performance, reviewing security posture shifts (such as reviewing updated SOC 2 reports), managing changes in vendor services (e.g., changes in infrastructure, sub-contractors, or hosting locations), and taking corrective actions if a supplier falls short of agreed-upon security standards.

Applicability Note: This control is fully applicable to the anDREa platform and governs the ongoing oversight of all active critical infrastructure and software dependencies.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving away from static checklist reviews toward an active, risk-proportional monitoring model.

anDREa enforces a tier-based review cadence driven entirely by vendor criticality. While low-risk utilities follow an extended lifecycle, high-criticality suppliers are subjected to comprehensive annual reviews. This process evaluates technical reliability, security incident history, and compliance updates. Crucially, any operational or technical changes initiated by a supplier—such as rolling out new capabilities, modifying data center regions, or onboarding new sub-processors—must be formally logged and triaged via our internal change management ticketing system to guarantee our security baseline is never degraded.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.22 - Monitoring, review and change management of supplier servicesMandates regular monitoring, review, and auditing of supplier service delivery against agreed information security terms.
Operational GovernanceRisk-Based Supplier Review CadenceFramework text defining review cycles (e.g., annual vs. triennial) based on vendor data access and criticality.
Vendor PortfoliosActive Supplier DossiersDocumented performance logs, audit summaries, updated certification tracking, and past security incident histories. (anDREa Supplier List)
Change ManagementSupplier Change Tracking TicketsThe formal IT ticketing registry where vendor infrastructure changes or sub-processor updates are reviewed, risk-assessed, and approved. (Issues and Risk Logging)
Continuous AssurancePeriodic Controls Security LogsOperational verification data confirming that third-party integrations continue to behave within baseline security parameters. (anDREa Supplier List)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Criticality-based review cadences, change management ticketing workflows, and corrective tracking protocols are fully operationalized. Continuous Improvement: Explicitly incorporating NIS 2 terminology like "essential dependency" directly into the vendor directory will further ease alignment for upcoming regulatory audits, though it does not represent a functional gap.