Monday, 6:50 a.m. Your IT provider — three people, very good, who have run your backups for eight years — calls before opening hours. They were encrypted over the weekend. Their remote administration tool, the one with permanent access to your servers, is compromised.
By 7:15, the question is no longer theirs. It is yours: was your data touched? Are your backups clean? And if they are, how do you prove it?
You were not attacked. You are in an incident anyway.
Key points
- NIS2 explicitly lists supply chain security among the minimum risk management measures (Article 21).
- The directive requires taking into account the vulnerabilities specific to each direct supplier and the quality of their cybersecurity practices.
- For financial entities, DORA has required a register of contractual arrangements with ICT third-party providers since January 2025.
- ISO/IEC 27001:2022 covers the topic through its supplier relationship and cloud service controls.
- An annual questionnaire filled in by the supplier themselves is not a third-party risk programme.
What NIS2 actually requires about your suppliers
This is one of the most underestimated points of the directive. Among the minimum measures in-scope entities must implement, Article 21 names supply chain security specifically, including security-related aspects of the relationships between the entity and its direct suppliers or service providers.
It goes further: entities must take into account the vulnerabilities specific to each direct supplier, along with the overall quality of their products and cybersecurity practices. In other words, compliance does not stop at your technical perimeter. It includes the people you handed a key to.
You are also somebody's supplier
The most visible effect of NIS2 on the ground is not regulatory inspection. It is the supplier questionnaire. Entities in scope must assess their direct suppliers, so they do, at scale, including companies that are not themselves in scope.
An industrial SME supplying a large group ends up answering cybersecurity requirements no law imposes on it directly, but on which its listing depends. In B2B tenders, demonstrable governance is becoming an award criterion alongside price and lead time.
The five layers of a realistic third-party programme
There is no need to aim for a bank's apparatus. Here is what an SME can sustain, and what is enough to demonstrate a genuine approach:
- The inventory. The list of your suppliers and providers, with what each actually accesses: your premises, your data, your systems, or none of it. This step produces the most surprises.
- Criticality. Not all suppliers are equal. The one hosting your ERP and the one delivering office supplies do not warrant the same effort. Three tiers are enough.
- Assessment, proportionate to the tier. For critical suppliers: certification evidence, audit results, continuity plan. For the rest: a short questionnaire, or nothing.
- The contract. Obligation to notify an incident, within what deadline and to whom; audit rights; requirements cascading to their own subcontractors; reversibility and data return terms.
- The exit. What happens if the provider disappears, is acquired, or is unavailable for three weeks. The most frequently missing piece, and the only one that matters on the day it happens.
Why the annual questionnaire is not enough
Self-declared questionnaires have real value: they open the conversation and document an approach. Taken alone, they have three weaknesses any auditor will spot.
They are declarative: nobody verifies. They are dated: a March answer says nothing about October, and providers change infrastructure, subcontractors and staff mid-year. And they are disconnected from the contract: the box "yes, we notify incidents" gets ticked while the signed contract sets no notification deadline at all.
What turns a questionnaire into a system is the chain: the supplier becomes an asset, the asset carries a risk, the risk calls for a control, the control gets tested and evidenced. Without that chain, you have one more binder.
The advantage of a native Odoo GRC: your suppliers are already there
This is where integration changes the nature of the work. In a siloed GRC platform, you re-create your supplier list, maintain it twice, and hope it stays in sync with the one procurement uses. It never does.
Prism GRC is a native Odoo module: your suppliers are already in the database, with their contracts, orders, contacts and history. Concretely:
- The supplier becomes a mapped asset, with no double entry, linked to its existing Odoo record.
- Criticality rests on real data: purchase volume, dependency, nature of the access granted.
- Third-party risks live in the same register as your other risks, on the same scale and the same risk appetite, instead of a parallel ranking.
- Controls are shared: a 24-hour incident notification requirement in supplier contracts serves NIS2, ISO 27001 and CyFun at once.
- Supplier incidents attach to the asset concerned, making recurrence visible and documenting the decision to renew the contract, or not.
- Periodic reviews are scheduled and traced in the Odoo chatter, where the exchanges with that supplier already live.
Frequently asked questions
Do you have to assess every supplier?
No, and it would be counterproductive. The directive targets direct suppliers and expects a risk-proportionate approach. A credible programme assesses a few dozen critical suppliers seriously rather than several hundred superficially.
What if a critical supplier refuses to answer?
The refusal is itself information, and it should be recorded as an accepted risk, with the person accepting it and the date. A documented risk owned by management is a defensible position in front of an auditor; silence is not.
Does DORA apply to non-financial companies?
Directly, no: DORA applies to financial entities and, through them, to their ICT service providers. But if you supply IT services to a bank, an insurer or a payment provider, its requirements will reach you by contract.
Take action
Prism Technology is an official Odoo partner in Belgium, based in Walloon Brabant. We built Prism GRC, a native Odoo module for managing risks, controls, incidents and multi-framework compliance. In 30 minutes, we take your ten most critical suppliers and look at what you could actually demonstrate about them today.
👉 Book your 30-minute demo — Contact us