July 2026. NIS2 and DORA make supply-chain risk explicitly a board topic. Dutch organisations — and their vendors — must explain which vendors are critical, which assurance they provide and how incidents escalate.
One vendor register
- tiers: critical / important / standard based on impact and data;
- tags: NIS2, DORA, GDPR, ISO per vendor;
- contract clauses: audit, notification, exit, subprocessors;
- review frequency linked to tier — not everything annual equally.
Due diligence without copy-paste
Standard questionnaire + library (ISO certificate, SOC, pentest summary). Escalation on exceptions. Log what you accept and why — auditors and supervisors want decisions.
More: vendor management, NIS2, DORA.
Concentration risk — one cloud for everything — is DORA theme and ISO risk. Document alternatives or accepted residual risk in management review.
Contract clauses that deliver evidence
Standardise clauses: incident notification within X hours, audit rights, exit within Y days, subprocessor notification, patch SLA. Legal and security review together before signing — no fixing afterwards.
Concentration risk: document when one vendor stacks critical functions — alternative, exit plan or accepted risk in management review.
Annual vendor review: assurance renewed? Chain incidents? Vendor scope change? Update tier and evidence.
Next steps in your ISMS
Turn this article into one concrete action in your risk register or improvement plan: owner, deadline, expected evidence. Discuss progress in the next management review — auditors and chain partners want decisions, not policy intent alone. Link where possible to existing ISO 27001, NIS2 or GDPR documentation so you do not maintain parallel folders.
Questions on scope, certification or chain requirements? Use our readiness overview and knowledge base for deeper guidance. This article does not replace legal or audit advice for your situation.
Share relevant findings briefly with line management and procurement — compliance becomes workable when the whole organisation recognises the same priorities. Repeat the chosen action quarterly in team meetings and update evidence locations in your SoA or control plan so surveillance samples are easy to answer.
