Irish SMEs manage third-party and supply-chain cyber risk under NIS2 by recognising that their customers are now being regulated — and their auditors are coming for suppliers next. Even SMEs not directly in scope are affected: NIS2 requires regulated organisations to assess the security of their entire supply chain, so if your customer is in scope, you are too by extension.
The practical path is to understand the landscape, prepare your defences, and turn compliance into a competitive advantage — being ready to demonstrate adequate controls when enterprise customers, insurers, and procurement teams start asking hard questions.
Why supply chain security matters now
If you supply products or services to larger organisations, the security landscape has fundamentally changed. Four forces are driving supply chain security in Ireland.
NIS2 Supply Chain Cascade
The NIS2 Directive requires regulated organisations to assess the security of their entire supply chain. If your customer is in scope, you are too — by extension.
Cyber Insurance Requirements
Insurers now routinely ask about supply chain risk. If your customer suffers a breach through your systems, both your insurance and theirs come into play.
Enterprise Procurement Standards
Large organisations are adding cybersecurity requirements to procurement. Security questionnaires are now standard in RFPs, tenders, and contract renewals.
High-Profile Supply Chain Attacks
SolarWinds, Kaseya, MOVEit — attackers increasingly target smaller suppliers to reach larger organisations. Your customers know this.
Frequently Asked Questions
I'm a small supplier — why would a large company audit me?
Because attackers target the weakest link. Large organisations have invested heavily in their own security, so attackers look for easier entry points — their suppliers. The SolarWinds attack compromised 18,000 organisations through a single software vendor. Under NIS2, your customers are legally required to assess your security. Size doesn't exempt you.
What happens if I fail a customer security audit?
The immediate risk is losing the contract or being placed on a remediation plan with a deadline. Longer term, failing audits damages your reputation in the market — procurement teams talk. Some organisations maintain approved supplier lists, and failing an audit can remove you from that list entirely.
Do I need to be ISO 27001 certified?
Rarely. Most enterprise customers want to see appropriate controls, not necessarily a formal certification. Documented policies, configured security settings, staff training, and an incident response plan will satisfy the vast majority of supplier audits. Certification is a bonus, not a requirement — unless your specific customer mandates it.
How does NIS2 affect me as a supplier?
NIS2 Article 21(2)(d) specifically requires in-scope organisations to address 'supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.' This means your customers must assess your security posture, and you must be able to demonstrate adequate controls.
What's the difference between this and the NIS2 compliance page?
The NIS2 compliance page covers the directive broadly — who's in scope, what's required, penalties, and timelines. This page focuses specifically on the supply chain angle: what happens when your customers are in scope and start auditing you. Many Irish SMEs aren't directly regulated by NIS2 but are indirectly affected through their customer relationships.
Related reading
- Supply Chain Cyber Risk for Irish SMEs: What NIS2 and DORA Actually Require — NIS2 and DORA both mandate supply chain cyber risk management. Here's what Irish SMEs — as suppliers and buyers — are required to do.
- DORA for ICT Suppliers in Ireland: What Non-Financial SMEs Are Now Required to Do — DORA affects Irish tech and IT suppliers to financial services, not just banks. If a financial client sent you DORA requirements, here's what it means and what you must do.