Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.1.26 Securing the supply chain together

Control Overview

This control mandates that the organization adopts a comprehensive, "all-hazards" risk management approach to secure its network, information systems, and physical environments from vulnerabilities within the broader supply chain. Rather than assessing suppliers in isolation, the organization must account for systemic business risks introduced by third-party products and services. Proportional, legally enforceable digital resilience agreements must be established, and suppliers must demonstrably prove they meet these standards. Crucially, the framework must include mechanisms to promptly inform downstream recipients of threat control measures during a significant cyber event, and the entire supply chain risk posture must undergo an annual evaluation.

note

Applicability Note: This control is fully applicable to the anDREa platform and directly dictates how we govern our multi-tiered technical ecosystem, software dependencies, and infrastructure providers.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement builds on our existing supplier policies within our ISO/IEC 27001-based ISMS, expanding them into a unified, risk-tiered supply chain ecosystem.

anDREa enforces supply chain security through an explicit, auditable tracking framework that catalogs all vendors by their business importance and NIS 2 relevance. We acknowledge that smaller organizations possess limited contractual leverage over industry hyper-scalers (such as Microsoft and Google). To address this reality without compromising security, our policy mandates rigorous, independent verification loops. We compensate for non-negotiable standard terms by performing detailed Supplier Impact Assessments (SIAs) (Supplier List), conducting structural gap analyses, enforcing formal management risk-acceptance protocols, and maintaining continuous operational oversight via upstream security bulletins and third-party SOC 2 Type II reports.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.21 - Managing information security in the information and communication technology (ICT) supply chainMandates processes for identifying, assessing, and mitigating the security risks associated with the entire upstream ICT supply chain.
ISO/IEC 27001A.05.19 - Information security in supplier relationships, A.05.20 - Addressing information security within supplier agreements, A.05.22 - Monitoring, review and change management of supplier services, A.05.23 - Information security for use of cloud servicesCross-referenced core sub-frameworks governing individual vendor relationships, agreements, operational change management, and cloud infrastructure.
Strategic DirectoryanDREa Supplier List (Risk Tiers)The definitive repository where all suppliers are traceably mapped, categorized by importance, and evaluated for NIS 2 regulatory relevance. (Supplier List)
Risk ArchitectureSupplier Impact Assessments (SIAs)Formal technical and operational evaluations executed to uncover, log, and treat potential supply chain vulnerabilities. (Supplier List)
Continuous AssurancePeriodic Security ControlsActive monitoring files verifying that third-party code packages, APIs, and cloud services continue to adhere to internal security standards.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Supply chain importance mapping, hyper-scaler gap treatments, multi-layered ISO control cross-referencing, and continuous assurance monitoring loops are fully operationalized.