The National Cybersecurity Agency has published new interpretative clarifications on the process and security requirements to be implemented to safeguard the supply chain security of NIS 2 entities, with the aim of facilitating their application by the entities concerned
To support NIS entities in adopting security measures to protect their supply chains, FAQ MSB.13 sets out the four stages of the relevant process (assessment of the risk associated with the supply; identification of security requirements; enforcement of the requirements; and verification of compliance).
For the purposes of assessing the risk associated with the supply chain, FAQ MSB.14 lists the minimum criteria to be taken into account, whilst, with regard to the identification of security requirements and their enforcement, FAQs MSB.15 and MSB.16, respectively, clarify that the NIS entity is not required to define such requirements for all its suppliers and, consequently, that not all the requirements set out in the basic security measures need necessarily be passed on to the supplier.
The MSB FAQs.17 also specifies that the application of the categories of measures set out in Article 24 of the NIS Decree must be adapted, up to and including the possible exclusion of certain measures (depending on the operational context, the level of risk and the criticality of the services entrusted by the individual public authority), and MSB FAQ 18 highlights that in cases where the successful tenderer is organised as a temporary consortium (RTI), the security measures may be fulfilled solely by those members that provide (even partially) the contractual service which has an impact on cybersecurity.
Finally, FAQ MSB.19 specifies that, including in the case of mixed contracts, the application of security requirements must be tailored, taking into account their proportionality, relevance and adequacy in relation to the specific services awarded.