With the impending enforcement of the Cyberbeveiligingswet (the Dutch implementation of NIS2) on August 15, the responsibility for cybersecurity is shifting fundamentally. Securing your own IT infrastructure is no longer sufficient. Under the new legislation, directors are held directly accountable for the digital security of their entire supply chain.
Mapping and enforcing NIS2 supply chain security requirements for vendors is no longer a theoretical exercise, but a strict compliance mandate. Companies must immediately request proof of security from their IT and software suppliers. Failing to do so means bearing the risks if a supply chain incident occurs.
Duty of care doesn't stop at your front door
The NIS2 directive introduces a comprehensive duty of care. Organizations in essential and important sectors must proactively manage risks. A significant portion of those risks lies outside the organization itself: with SaaS solutions, cloud providers, and AI vendors.
The Dutch National Cyber Security Centre (NCSC) and the Digital Trust Center emphasize that attackers increasingly target the 'weakest link' in the chain. A vulnerability at a smaller software vendor can paralyze the operational continuity of a major institution. Conducting periodic vendor audits and maintaining a proper Information Security Management System (ISMS) are therefore mandatory steps.
From policy to demonstrable control
Many organizations currently still send standard Excel questionnaires to their vendors. Under NIS2, this is unscalable and difficult to verify. You must be able to continuously demonstrate that your suppliers comply with applicable standards (such as ISO 27001 or specific regional norms) and that they have adequate incident response plans in place.
This development does not stand alone. As we wrote earlier regarding the EU AI Act in practice, various European directives are now converging into a stricter, integrated supervisory framework where accountability takes center stage.
Automating vendor management with IRMA
When depending on dozens or hundreds of vendors, manual verification is unsustainable. Vendor management must become an integral, dynamic part of your risk management. This is where intelligent automation offers a solution.
With tools like PrudAI's IRMA (Intelligent Risk Management), organizations can maintain a clear overview of the compliance status across their entire supply chain. IRMA allows you to efficiently orchestrate vendor assessments, flag deviations early, and automatically capture audit trails. Furthermore, it demonstrates that PrudAI itself, as a sovereign AI provider, meets these stringent supply chain security and data governance requirements.
Would you like to know how PrudAI and IRMA can support your organization in setting up watertight vendor management and securing NIS2 compliance? Please contact us for a strategic advisory session.
