Back to Publications
Regulatory Brief · NexCyber

NIS2 Article 21.2 in practice: the 13 by 13 supplier audit matrix

17 May 2026By NexCyber Editorial NexCyber

Navigating the complexities of NIS2 compliance, particularly Article 21.2, can be daunting and costly. While some consulting firms, such as KPMG, might charge upwards of 80,000 EUR for a comprehensive supplier audit, NexCyber offers a streamlined solution that automates this process in just two hours. This article delves into how NexCyber's innovative 13 by 13 supplier audit matrix simplifies compliance and ensures that competent authorities accept your supplier register.

Navigating the complexities of NIS2 compliance, particularly Article 21.2, can be daunting and costly. While some consulting firms, such as KPMG, might charge upwards of 80,000 EUR for a comprehensive supplier audit, NexCyber offers a streamlined solution that automates this process in just two hours. This article delves into how NexCyber's innovative 13 by 13 supplier audit matrix simplifies compliance and ensures that competent authorities accept your supplier register.

Understanding the 13 Supplier Types

The NIS2 Directive mandates that organizations maintain a robust supplier management framework. This involves categorizing suppliers into distinct types, each with unique risk profiles and compliance requirements. NexCyber's matrix includes the following 13 supplier types:

  1. 1Cloud Service Providers: These suppliers offer scalable computing resources over the internet, necessitating stringent data protection measures.
  1. 1Software as a Service (SaaS) Providers: SaaS vendors deliver software applications online, requiring robust access controls and data integrity protocols.
  1. 1Managed Service Providers (MSPs): MSPs manage IT services for businesses, making them critical to operational continuity and security.
  1. 1IT Asset Recovery (ITAR) Vendors: These suppliers handle the disposal and recycling of IT equipment, posing potential data leakage risks.
  1. 1Hardware Vendors: Suppliers of physical IT components, whose security vulnerabilities can impact the entire network.
  1. 1Telecommunications Providers: They ensure connectivity and communication, necessitating strict compliance with data transmission standards.
  1. 1Data Center Operators: Responsible for housing critical infrastructure, requiring enhanced physical and cybersecurity measures.
  1. 1Network Equipment Suppliers: Provide essential networking hardware, where security flaws can compromise network integrity.
  1. 1Outsourced IT Support: External teams providing IT support, requiring oversight to protect sensitive information.
  1. 1Consulting Firms: Offer strategic advice and solutions, often accessing confidential business data.
  1. 1Logistics and Supply Chain Partners: Integral to the delivery of goods and services, with potential exposure to sensitive information.
  1. 1Payment Processors: Handle financial transactions, demanding rigorous data protection and fraud prevention measures.
  1. 1Third-Party Software Developers: Develop applications that integrate into existing systems, necessitating secure code practices.

The 13 NIS2 Supplier Controls

To ensure compliance with NIS2 Article 21.2, organizations must implement a set of 13 controls across their supplier network. These controls are designed to mitigate risks and ensure the secure management of supplier relationships:

  1. 1Access Control: Ensuring that only authorized personnel can access sensitive data and systems.
  1. 1Data Encryption: Protecting data in transit and at rest to prevent unauthorized access.
  1. 1Incident Response: Establishing protocols for responding to security incidents involving suppliers.
  1. 1Risk Assessment: Regularly evaluating supplier risk profiles and adjusting controls accordingly.
  1. 1Audit and Monitoring: Continuously monitoring supplier activities and conducting regular audits.
  1. 1Service Level Agreements (SLAs): Defining clear expectations and responsibilities in contracts with suppliers.
  1. 1Business Continuity Planning: Ensuring suppliers have plans in place to maintain operations during disruptions.
  1. 1Data Protection: Implementing measures to protect personal data handled by suppliers.
  1. 1Security Training: Providing suppliers with regular cybersecurity training and awareness programs.
  1. 1Compliance Verification: Regularly verifying supplier compliance with relevant regulations and standards.
  1. 1Change Management: Managing changes in supplier services or products to prevent security lapses.
  1. 1Exit Strategy: Planning for the secure termination of supplier relationships.
  1. 1Performance Metrics: Measuring supplier performance against established security and operational benchmarks.

Matrix Walkthrough: An Example Row in Depth

To illustrate the practical application of the 13 by 13 matrix, let's examine a specific row: Cloud Service Providers. This example demonstrates how each control is applied to this supplier type.

  • Access Control: Cloud service providers must implement strict identity and access management systems to ensure only authorized users can access cloud resources. This involves multi-factor authentication and regular access reviews.
  • Data Encryption: Data stored and processed by cloud providers must be encrypted using industry-standard protocols. This protects against unauthorized data access and breaches.
  • Incident Response: Cloud providers should have a robust incident response plan that includes notification procedures for clients in the event of a security breach.
  • Risk Assessment: Organizations must regularly assess the risk associated with their cloud providers, considering factors such as data sensitivity and provider security posture.
  • Audit and Monitoring: Continuous monitoring of cloud service usage and regular audits of provider compliance with security controls are essential.
  • SLAs: Contracts with cloud providers should include SLAs that specify security responsibilities and data protection commitments.
  • Business Continuity Planning: Cloud providers should demonstrate their ability to maintain service availability during disruptions, with documented recovery plans.
  • Data Protection: Providers must comply with data protection regulations, such as GDPR, ensuring that personal data is handled securely.
  • Security Training: Cloud providers should participate in cybersecurity training programs to stay informed about emerging threats and best practices.
  • Compliance Verification: Organizations should regularly verify that cloud providers comply with relevant security standards and regulations.
  • Change Management: Any changes to cloud services should be managed carefully to avoid introducing new security vulnerabilities.
  • Exit Strategy: Organizations should have a clear plan for data retrieval and secure deletion when terminating cloud services.
  • Performance Metrics: Regularly review cloud provider performance against security and operational metrics to ensure continued compliance and service quality.

Next Step with NexCyber

NexCyber's 13 by 13 supplier audit matrix provides a comprehensive framework for managing supplier compliance under NIS2 Article 21.2. By automating the supplier audit process, NexCyber not only reduces costs but also ensures that your organization meets regulatory requirements efficiently. To experience the benefits of NexCyber's solution, try our free assessment today at [nexcyber.eu/assess?utm_source=editorial&utm_campaign=nis2-art-212-13-by-13-supplier-matrix](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=nis2-art-212-13-by-13-supplier-matrix).