Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
All posts
Pavel Láska

The five evidence artefacts that cover roughly 80% of Article 21(2)(d)

Supplier inventory, risk classification, per-supplier assessment evidence, decision trail, reaction plan — what each has to look like to hold up under a supervisory inquiry. The 80% is a practitioner’s number, not a measured statistic, and the 20% it leaves out is named at the end.

  • nis2
  • article-21
  • practical

When a supervisory authority or an auditor gets to the supply chain part of NIS2, they don't ask how you feel about your suppliers. They ask for artefacts — specific, dated, attributable records. Having spent years preparing for exactly those conversations from the practitioner's side, we'd say five artefacts answer most of what Article 21(2)(d) will be tested on. Call it roughly 80%. That's a practitioner's number, not a measured statistic — and the remaining 20% is real, so we'll name it at the end.

The five, in the order an inquiry tends to reach for them: a supplier inventory, a risk classification, per-supplier assessment evidence, a decision trail, and a reaction plan. Here's what each one actually has to look like to hold up.

01 — A maintained supplier inventory, tagged by service and data

Every supplier that touches your regulated services or processes your regulated data, with the service named and the data type tagged. The operative word is maintained — live, owned, and dated, not a CSV attached to an email from last spring. Sub-processors of those suppliers are identified separately, because "who else is under this contract" is a question that arrives early in any inquiry.

The failure mode isn't missing the inventory entirely — almost everyone has one. It's having three: procurement's vendor list, IT's systems list, and the spreadsheet the last audit produced, none of which agree. One inventory, one owner, one last-updated date.

02 — A documented risk classification

A two- or three-tier scheme works for most mid-market entities: tier by data sensitivity, service criticality, and how replaceable the supplier is. Top tier gets the full assessment; lower tiers get lighter touch. The load-bearing word here is documented — lighter-touch is a recorded decision with criteria, not an absence of attention.

What an auditor is checking isn't whether your scheme matches some template. It's whether the classification exists on paper, whether it was applied consistently, and whether you can explain why the payroll processor sits a tier above the office-plant company. Proportionality is a defence only when it's written down.

03 — Per-supplier assessment evidence on a known cadence

For each supplier that clears the classification bar: what you asked, what they answered, what evidence backed the answers — SOC 2 report, ISO 27001 certificate, sub-processor list, security policy, breach history, continuity plan — who reviewed it on your side, when, and when it next needs re-reviewing.

This is the artefact with the most moving parts, because the inputs come from outside and age at different speeds. A certificate on a three-year cycle, an audit report that goes stale after twelve months, a sub-processor list that can be wrong a quarter after it arrived. "On a known cadence" means each of those has a next-review date somebody owns — not that everything gets looked at every January.

Supplier evidence becomes questionnaire answersFour supplier-provided evidence artefacts on the left — ISO 27001 certificate, SOC 2 Type II report, sub-processor list, DPA — each mapped to specific items in the buyer's supplier questionnaire on the right, with one item marked manual to show that AI never closes the loop.Supplier evidenceYour supplier questionnaireISO 27001 certificateValid · 2025–2028SOC 2 Type II reportAudit · Mar 2026Sub-processor listv2 · Apr 2026DPASigned · Jan 2026Are sub-processors disclosed?ISO 27001 certified — current?SOC 2 Type II in date?DPA in place with you?Incident notification SLA?BC/DR tests · last 12 mo?MANUALTheir certs.Your answers — with citations and a reviewer sign-off.

04 — A defensible decision trail

Approving a supplier is easy. Showing — three years later, after staff turnover, possibly under regulator scrutiny — how you approved them, on what evidence current at the time, and who signed: that's the part that takes infrastructure. In our experience this is the artefact mid-market entities are most often missing entirely.

A decision trail that holds up records the decision itself (approve, reject, or accept-with-risk, with the reason), the evidence version it was based on, the person who made it, and the date. The test is unforgiving: if the reviewer leaves, does the answer leave with them? If yes, you have institutional memory, not a decision trail.

05 — A reaction plan for material change

Suppliers' postures drift. Certificates expire mid-cycle. Sub-processors get added without notice. Breaches happen in month seven of a twelve-month review calendar. Article 21(2)(d) expects you to treat those events as triggers for re-assessment, not as items for next year's annual review.

The plan doesn't need to be elaborate. It needs to name the events that trigger a re-review, who gets notified, and what the re-review covers. What it must not be is implicit — "we'd obviously look at it" is the answer that collapses under the follow-up question "show me the last time you did."

The remaining 20%

The five artefacts cover the operational core, not the whole clause. What's left: the contractual layer — ENISA's implementation guidance names eight specific contract requirements to embed in supplier agreements, and the artefacts above evidence the relationship rather than the contract terms. Coordinated EU risk assessments under Article 22, where they exist for your sector, have to be taken into account in your own assessments. And sector-specific supervision can go deeper — a bank's supervisor asks different follow-ups than a food distributor's. The five artefacts are where an inquiry starts; your sector decides where it ends.

Two ways to find your gaps

If you want the quick, self-serve version: the NIS2 readiness check scores your setup across four NIS2 categories — governance, supplier risk, incident response, evidence — in about five minutes, no call required.

If you want the thorough version done for you: the NIS2 Supplier Exposure Assessment is a fixed-scope engagement — we inventory your supplier exposure, classify it, and hand over an audit-ready report with the gaps named and prioritised. And if you'd rather read further first, the Article 21(2)(d) deep dive is the long-form version of this post's skeleton.

Follow on LinkedIn

Release announcements on LinkedIn.

Follow the company page for pilot dates, product milestones, and the work as it ships. Public, low-volume, no inbox to clutter.

Follow Shards Cybersecurity