Skip to Content

Your Supplier Got Hacked. It Just Became Your Incident.

Supply chain security is no longer a boilerplate clause
September 16, 2026 by
Your Supplier Got Hacked. It Just Became Your Incident.

Monday, 6:50 a.m. Your IT provider — three people, very good, who have run your backups for eight years — calls before opening hours. They were encrypted over the weekend. Their remote administration tool, the one with permanent access to your servers, is compromised.

By 7:15, the question is no longer theirs. It is yours: was your data touched? Are your backups clean? And if they are, how do you prove it?

You were not attacked. You are in an incident anyway.

What NIS2 actually requires about your suppliers

This is one of the most underestimated points of the directive. Among the minimum measures in-scope entities must implement, Article 21 names supply chain security specifically, including security-related aspects of the relationships between the entity and its direct suppliers or service providers.

It goes further: entities must take into account the vulnerabilities specific to each direct supplier, along with the overall quality of their products and cybersecurity practices. In other words, compliance does not stop at your technical perimeter. It includes the people you handed a key to.

You are also somebody's supplier

The most visible effect of NIS2 on the ground is not regulatory inspection. It is the supplier questionnaire. Entities in scope must assess their direct suppliers, so they do, at scale, including companies that are not themselves in scope.

An industrial SME supplying a large group ends up answering cybersecurity requirements no law imposes on it directly, but on which its listing depends. In B2B tenders, demonstrable governance is becoming an award criterion alongside price and lead time.

The five layers of a realistic third-party programme

There is no need to aim for a bank's apparatus. Here is what an SME can sustain, and what is enough to demonstrate a genuine approach:

  1. The inventory. The list of your suppliers and providers, with what each actually accesses: your premises, your data, your systems, or none of it. This step produces the most surprises.
  2. Criticality. Not all suppliers are equal. The one hosting your ERP and the one delivering office supplies do not warrant the same effort. Three tiers are enough.
  3. Assessment, proportionate to the tier. For critical suppliers: certification evidence, audit results, continuity plan. For the rest: a short questionnaire, or nothing.
  4. The contract. Obligation to notify an incident, within what deadline and to whom; audit rights; requirements cascading to their own subcontractors; reversibility and data return terms.
  5. The exit. What happens if the provider disappears, is acquired, or is unavailable for three weeks. The most frequently missing piece, and the only one that matters on the day it happens.

Why the annual questionnaire is not enough

Self-declared questionnaires have real value: they open the conversation and document an approach. Taken alone, they have three weaknesses any auditor will spot.

They are declarative: nobody verifies. They are dated: a March answer says nothing about October, and providers change infrastructure, subcontractors and staff mid-year. And they are disconnected from the contract: the box "yes, we notify incidents" gets ticked while the signed contract sets no notification deadline at all.

What turns a questionnaire into a system is the chain: the supplier becomes an asset, the asset carries a risk, the risk calls for a control, the control gets tested and evidenced. Without that chain, you have one more binder.

The advantage of a native Odoo GRC: your suppliers are already there

This is where integration changes the nature of the work. In a siloed GRC platform, you re-create your supplier list, maintain it twice, and hope it stays in sync with the one procurement uses. It never does.

Prism GRC is a native Odoo module: your suppliers are already in the database, with their contracts, orders, contacts and history. Concretely:

  • The supplier becomes a mapped asset, with no double entry, linked to its existing Odoo record.
  • Criticality rests on real data: purchase volume, dependency, nature of the access granted.
  • Third-party risks live in the same register as your other risks, on the same scale and the same risk appetite, instead of a parallel ranking.
  • Controls are shared: a 24-hour incident notification requirement in supplier contracts serves NIS2, ISO 27001 and CyFun at once.
  • Supplier incidents attach to the asset concerned, making recurrence visible and documenting the decision to renew the contract, or not.
  • Periodic reviews are scheduled and traced in the Odoo chatter, where the exchanges with that supplier already live.

Frequently asked questions

Do you have to assess every supplier?

No, and it would be counterproductive. The directive targets direct suppliers and expects a risk-proportionate approach. A credible programme assesses a few dozen critical suppliers seriously rather than several hundred superficially.

What if a critical supplier refuses to answer?

The refusal is itself information, and it should be recorded as an accepted risk, with the person accepting it and the date. A documented risk owned by management is a defensible position in front of an auditor; silence is not.

Does DORA apply to non-financial companies?

Directly, no: DORA applies to financial entities and, through them, to their ICT service providers. But if you supply IT services to a bank, an insurer or a payment provider, its requirements will reach you by contract.

Take action

Prism Technology is an official Odoo partner in Belgium, based in Walloon Brabant. We built Prism GRC, a native Odoo module for managing risks, controls, incidents and multi-framework compliance. In 30 minutes, we take your ten most critical suppliers and look at what you could actually demonstrate about them today.

👉 Book your 30-minute demo — Contact us

NIS2: You Have 24 Hours, and the Clock Starts Without You
The incident notification procedure, step by step