When a supervisory authority or an auditor gets to the supply chain part of NIS2, they don't ask how you feel about your suppliers. They ask for artefacts — specific, dated, attributable records. Having spent years preparing for exactly those conversations from the practitioner's side, we'd say five artefacts answer most of what Article 21(2)(d) will be tested on. Call it roughly 80%. That's a practitioner's number, not a measured statistic — and the remaining 20% is real, so we'll name it at the end.
The five, in the order an inquiry tends to reach for them: a supplier inventory, a risk classification, per-supplier assessment evidence, a decision trail, and a reaction plan. Here's what each one actually has to look like to hold up.
01 — A maintained supplier inventory, tagged by service and data
Every supplier that touches your regulated services or processes your regulated data, with the service named and the data type tagged. The operative word is maintained — live, owned, and dated, not a CSV attached to an email from last spring. Sub-processors of those suppliers are identified separately, because "who else is under this contract" is a question that arrives early in any inquiry.
The failure mode isn't missing the inventory entirely — almost everyone has one. It's having three: procurement's vendor list, IT's systems list, and the spreadsheet the last audit produced, none of which agree. One inventory, one owner, one last-updated date.
02 — A documented risk classification
A two- or three-tier scheme works for most mid-market entities: tier by data sensitivity, service criticality, and how replaceable the supplier is. Top tier gets the full assessment; lower tiers get lighter touch. The load-bearing word here is documented — lighter-touch is a recorded decision with criteria, not an absence of attention.
What an auditor is checking isn't whether your scheme matches some template. It's whether the classification exists on paper, whether it was applied consistently, and whether you can explain why the payroll processor sits a tier above the office-plant company. Proportionality is a defence only when it's written down.
03 — Per-supplier assessment evidence on a known cadence
For each supplier that clears the classification bar: what you asked, what they answered, what evidence backed the answers — SOC 2 report, ISO 27001 certificate, sub-processor list, security policy, breach history, continuity plan — who reviewed it on your side, when, and when it next needs re-reviewing.
This is the artefact with the most moving parts, because the inputs come from outside and age at different speeds. A certificate on a three-year cycle, an audit report that goes stale after twelve months, a sub-processor list that can be wrong a quarter after it arrived. "On a known cadence" means each of those has a next-review date somebody owns — not that everything gets looked at every January.
04 — A defensible decision trail
Approving a supplier is easy. Showing — three years later, after staff turnover, possibly under regulator scrutiny — how you approved them, on what evidence current at the time, and who signed: that's the part that takes infrastructure. In our experience this is the artefact mid-market entities are most often missing entirely.
A decision trail that holds up records the decision itself (approve, reject, or accept-with-risk, with the reason), the evidence version it was based on, the person who made it, and the date. The test is unforgiving: if the reviewer leaves, does the answer leave with them? If yes, you have institutional memory, not a decision trail.
05 — A reaction plan for material change
Suppliers' postures drift. Certificates expire mid-cycle. Sub-processors get added without notice. Breaches happen in month seven of a twelve-month review calendar. Article 21(2)(d) expects you to treat those events as triggers for re-assessment, not as items for next year's annual review.
The plan doesn't need to be elaborate. It needs to name the events that trigger a re-review, who gets notified, and what the re-review covers. What it must not be is implicit — "we'd obviously look at it" is the answer that collapses under the follow-up question "show me the last time you did."
The remaining 20%
The five artefacts cover the operational core, not the whole clause. What's left: the contractual layer — ENISA's implementation guidance names eight specific contract requirements to embed in supplier agreements, and the artefacts above evidence the relationship rather than the contract terms. Coordinated EU risk assessments under Article 22, where they exist for your sector, have to be taken into account in your own assessments. And sector-specific supervision can go deeper — a bank's supervisor asks different follow-ups than a food distributor's. The five artefacts are where an inquiry starts; your sector decides where it ends.
Two ways to find your gaps
If you want the quick, self-serve version: the NIS2 readiness check scores your setup across four NIS2 categories — governance, supplier risk, incident response, evidence — in about five minutes, no call required.
If you want the thorough version done for you: the NIS2 Supplier Exposure Assessment is a fixed-scope engagement — we inventory your supplier exposure, classify it, and hand over an audit-ready report with the gaps named and prioritised. And if you'd rather read further first, the Article 21(2)(d) deep dive is the long-form version of this post's skeleton.