Secure the supplier chain NIS2 holds you responsible for

Register the supplier, check it on criteria you set yourself, get the answers and documents out of it, then assess it as a risk in your NIS2 risk area and put a costed plan on what has to come down.

Unlimited users  •  Free onboarding and support  •  No commitment

A supplier record at the centre of a mapped chain, with a questionnaire card going out to it, a document coming back, and a decision card carrying a cost beside it
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The supplier overview in .legal filtered to legal entities of the data processor type, each row carrying its country, the assets it sits behind, an approval tick, a NIS2 risk level and a classification level

Supply-chain security under NIS2 Meridian knew who its suppliers were. It could not say what any of them would cost.

Anders Krogh is CISO at Meridian Nordic, an energy group running around 1,200 active suppliers and processors behind the metering platform, the customer portal and the field work. As an essential entity under NIS2 he is answerable for that chain, and the list he inherited told him who everyone was and nothing about what any of them could do to him. Now a supplier is checked on Meridian's own criteria, asked for the answers and documents Anders actually needs, and then assessed as a risk in its own right, with a plan and a price on the ones that matter.

  • The check happens once, on criteria Meridian set, and the result decides who gets looked at hardest.
  • Suppliers answer and upload from their own inbox, so a chase for a certificate stops being an email thread.
  • The suppliers behind a critical system are visible from the system itself, subcontractors included.
  • A supplier risk ends in a decision, not a colour: accept it, avoid it, or bring it down for a stated cost.

  • Your criteria, not ours

    Build the check you want, weight it yourself, and read a risk level that came out of your own answers.

  • No login for suppliers

    They answer and upload documents from their own inbox, with no account and nothing to install.

  • The supplier as a risk

    Assess the supplier itself against concrete scenarios in a NIS2 risk area, with a justification on record.

  • A plan with a cost

    Accept it, avoid it or bring it down, and say what bringing it down is expected to cost.

A long plain list of supplier plates with nothing attached to any of them, and the evidence lying loose on a separate slab away from the list

Supply-chain security under NIS2 A list of suppliers is not supply-chain security

Almost everybody has the list. What NIS2 asks about is what you did with it, and that is where most supply-chain work quietly stops.

  • The list says who a supplier is, not what would happen to you if they went down.
  • The evidence you gathered sits in a shared drive, so nobody can show what was checked, or when.
  • The one supplier everybody worries about is usually the one nobody has documented, because they are too big to chase.
A supplier classification called NIS2 classification open in its builder, with a risk levels and intervals section, a single-select question asking whether the supplier is critical, and per-question toggles for required and question weighting

Supply-chain security under NIS2 Decide who deserves the scrutiny

Not every supplier needs the same treatment, and you should be the one deciding which is which. The classification is a questionnaire you build and answer yourself about the supplier, and it hands back a risk level.

  • Weight the sections, the questions and each answer option, and set the intervals that turn a set of answers into a level.
  • Nothing is scored for you, and nothing happens on its own: the level tells you who to look at, you decide what to send them.
  • Read the level rather than the number. The score runs the other way round to the level, which is exactly the sort of detail worth knowing before your first demo.
One audit being set up in .legal from a data processor audit template, with a filterable list of legal entities and several of them ticked to receive the same questionnaire, each carrying its own type, country, contact slot and classification

Supply-chain security under NIS2 Ask once, and let them answer from their inbox

You design the questionnaire: their security measures, their sub-suppliers, the certificate you want a copy of. Then you send it, to one supplier or to a whole group of them at once.

  • The supplier needs no account. They open a link, answer, upload what you asked for, and it all lands on their record.
  • A group send gives every legal entity its own instance and its own contact, so responses stay separate and you can see who has opened and who has submitted.
  • Reminders to non-responders go automatically after 7, 14 and 21 days. The cadence is fixed, so plan around it rather than expecting to tune it.
One large supplier block with no envelope going to it, and a single report document registered against it instead

Supply-chain security under NIS2 The supplier who will not fill in your questionnaire

Every security team has the same three or four of them: too large to care, and too central to drop. There is a route for that, and it does not involve sending anything.

  • Close the check out with an auditor's report instead: upload the document or register a link against the supplier.
  • No email goes out at all, and the supplier's status shows that a report is in place.
  • We do not tie that route to a named assurance standard, so what counts as a good enough report stays your judgement.
A supplier assessed inside a NIS2 risk area in .legal, with its linked risk level, its exposure in euros and the exposure left after mitigation, above one risk scenario carrying a consequence, a probability, a risk level and the date it was assessed

Supply-chain security under NIS2 Then assess the supplier as a risk, not just as a record

This is where the newer half of the story sits. With the Enterprise Risk Management add-on, released in August 2026, a supplier is an entity you assess, alongside processes and assets.

  • Put the supplier in a NIS2 risk area with its own matrix and appetite, add concrete scenarios, and state consequence and probability with a justification on each.
  • Decide what happens next: accept it, avoid it by stopping the activity, or mitigate it with a plan that carries an estimated cost and the exposure left afterwards.
  • A relationship graph shows the connections you have already mapped between your entities, so an inherited risk is something you can see and follow rather than something you assume.
Two separate measuring frames standing side by side over the same supplier block, with no connection drawn between them

Supply-chain security under NIS2 Two checks on the same supplier, and they do not feed each other

We would rather tell you this than let you find it in a demo. There are two ways to put a number on a supplier here, and they are separate mechanics.

  • The classification is your own questionnaire, answered internally, producing a level. The risk assessment is scenarios against a matrix, in the risk add-on. Neither updates the other.
  • We build the plan, not the filling-in. The level and the assessment both come out of judgements you made, not out of anything we worked out for you.
  • The platform documents your supplier chain, it does not watch it. Nothing is scanned and nothing arrives on its own, so there is no incident reporting and no alerting here.
.legal in practice

Features for supply-chain security under NIS2

The supplier, and the chain behind it

Suppliers sit as legal entities with their sub-suppliers registered centrally on them, and a Suppliers tab on an asset shows which of them sit behind that system, subcontractors included.

A classification you design

Weight the sections, the questions and each answer option, set the intervals that turn an answer set into a risk level, and use the level to decide who gets looked at hardest.

One check, many suppliers

Send the same questionnaire to a whole group of legal entities at once. Each gets its own instance and its own contact, and you follow who has opened it and who has submitted.

For the supplier that will not answer

Close the check out with an auditor's report instead. Upload the document or register a link, and the supplier's status shows a report is in place. No email is sent to them at all.

Supplier risk in a NIS2 risk area (add-on)

Assess the supplier against concrete scenarios in a risk area with its own matrix and appetite, with a justification required on both consequence and probability. This sits in Enterprise Risk Management, a paid add-on that shipped in August 2026.

Accept it, avoid it, or price the fix

Three named treatments for a supplier risk: accept, avoid or mitigate. Mitigation is the one that produces a plan, and that plan carries a cost you can put in front of whoever approves the spend.

Supply-chain security under NIS2 Frameworks this covers

One framework, and the part of it this page is about.

  • icon-framework-NIS2

    NIS2

    The supply-chain security an essential entity has to run: which suppliers sit behind your services, what you checked, what they answered, and what you decided about the risk.

    Read about NIS2
.legal compliance platform

Secure your supplier chain with...

Do you need to get on top of the suppliers behind your services? We recommend the following modules for that task.

Vendor Management

Where suppliers live, and the audit engine behind the classification, the questionnaires and the auditor's report route.

Explore Vendor Management

Information Security Management

Where the NIS2 framework, its controls and your security documentation sit, next to the supplier work on this page. Enterprise Risk Management, which assesses the supplier itself, is a separate paid add-on.

Explore Information Security Management

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
Use cases

Find the job you need done

Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.

Book demo

12 use cases

Compliance & GRC lead

Run awareness training that reaches every colleague

Send out training and policies, chase the stragglers automatically, and prove every colleague completed it. You bring the material, we run the rails.
See awareness training
Compliance & GRC lead

Manage compliance across a group of companies

Run every company in the group from one platform, document once at group level, and still report entity by entity. Delivered by the Group Companies add-on.
See group compliance
Legal counsel

Run due diligence on your vendors

Classify a vendor on your own criteria, get the answers and documents you need with no login for them, and move the approved ones straight into contracts.
See vendor due diligence
Compliance & GRC lead

Multi-framework compliance: do the work once

Do a control once and it counts across every framework it maps to, with a simulated score on the ones you haven't started yet.
See multi-framework compliance
CISO & IT security

Get NIS2-ready without starting from scratch

Build on the ISO 27001 work you've already done, switch NIS2 on, and let a simulated score show how far ahead you already are.
See NIS2 readiness
Compliance & GRC lead

Build one risk register for the whole organisation

One register across GDPR, NIS2, AI and information security, where each risk area keeps its own matrix, scale and appetite. Delivered by the Enterprise Risk Management add-on.
See the risk register
CISO & IT security

Run your ISMS in one platform

The frameworks you answer to, the controls beneath them and the documentation that proves the work happened, all three in one module, with status updating itself from completed tasks.
See how the ISMS runs
DPO

From twelve spreadsheets to one record of processing

Your GDPR documentation already exists, it just lives in spreadsheets. Export what you have and we structure it in .legal for you, typically inside two weeks.
See the move off spreadsheets

Frequently Asked Questions about supply-chain security under NIS2

What does supply-chain security under NIS2 actually look like in .legal?

As a sequence rather than a feature. You register the supplier, classify it on criteria you set yourself, send it a questionnaire and collect the documents you asked for, and then, with the Enterprise Risk Management add-on, assess the supplier itself against concrete scenarios in a NIS2 risk area and decide what to do about the result. The platform stands the sequence up and keeps the record of it. It does not tell you which suppliers are in scope, and it does not judge your chain for you.

Getting NIS2-ready without starting from scratch

How do we decide which suppliers to look at hardest?

With a classification you design. You choose the questions that matter to you, weight the sections, the questions and each answer option, and set the percentage intervals that turn a set of answers into a risk level. Nothing is scored for you. One thing worth knowing before a demo: the score runs the opposite way to the level, so a higher score means a lower risk. That is why we talk about the level and not the number, and why you should too.

Running the due diligence check itself

Is the classification the same thing as the risk assessment of the supplier?

No, and this is the seam most people find on their first demo, so we would rather say it here. The classification is a questionnaire you designed and answer yourself about the supplier, and it produces a risk level. The risk assessment in Enterprise Risk Management is a different mechanic: the supplier is an entity in a risk area, assessed against concrete scenarios on a matrix you configured. They sit side by side and they do not feed each other. A classification level does not become a risk assessment, and a risk assessment does not update a classification.

Does the supplier need a login to answer us?

No. You register a contact person on the supplier and pick that contact when you send. The link arrives in their own inbox, and they can both answer the questions and upload the documentation without ever creating an account. How they pull the answers together internally is up to them, and whatever comes back is filed against that supplier.

Can we send the same check to a lot of suppliers at once?

Yes. One questionnaire goes out to a whole group of legal entities in a single send, and each one still gets its own instance with its own contact, so responses stay split per supplier. You see how many have opened it and how many have submitted. Reminders to anyone who has not responded go out automatically after 7, 14 and 21 days, and that cadence is fixed rather than something you configure.

Our biggest suppliers refuse to fill in our questionnaire. What then?

You close the check out with an auditor's report instead of sending anything. Either exclude the supplier from the send with the auditor's report as the reason and upload the document, which then also appears under that supplier's documents, or register it directly from the supplier's audit tab with a responsible person and a document or a link. No email goes to the supplier, and the status shows that a report is in place. We do not tie that route to any named assurance standard, so what the report has to be is your call.

Can we risk-assess a supplier, or only document it?

You can assess it. Suppliers are one of the entity types Enterprise Risk Management assesses, alongside processes and assets, so a supplier is assessed directly rather than only inheriting risk from a system it sits behind. You choose which entities a risk area assesses, so nothing is attached by default, and you then add scenarios to the supplier and state consequence and probability with a justification on each. Enterprise Risk Management is a paid add-on that was released on 14 August 2026, and it sits beside the risk assessment you may already be using rather than replacing it.

Can we see which suppliers sit behind a critical system?

Yes. Each asset has a Suppliers tab showing the legal entities linked to it, including subcontractors, and sub-suppliers are registered centrally on the supplier itself rather than typed in again everywhere it is used. With the risk add-on there is also a relationship graph, and read from the supplier end it shows the same connections the other way round: which systems and processes a given supplier sits behind, so the reach of one supplier's risk is something you can actually see.

If a supplier has an incident, does .legal report it for us?

No, and we would rather be plain about it than let you find out later. There is no incident reporting to an authority in the platform, no statutory timers and no submission of any kind. What you get is the record: what you knew about the supplier, when you checked it, what it answered, how you assessed it and what you decided to do. We build the plan, not the filling-in. The platform documents your supply chain, it does not monitor it, so it is not a detection tool of any kind.

One incident log for GDPR and NIS2

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell