
NIS2 Supply Chain Requirements: What Suppliers Outside the Scope Still Owe
NIS2 flow-down explained: why customers send the questionnaire, the five standard contract clauses, and how to answer with evidence you already hold.

Lead Auditor and Consultant
Iulian Bozdoghina is a veteran cybersecurity strategist with over 15 years of experience in securing automotive supply chains and critical infrastructure. He specializes in TISAX®, ISO 27001, and the emerging NIS2/DORA regulatory landscape.

NIS2 flow-down explained: why customers send the questionnaire, the five standard contract clauses, and how to answer with evidence you already hold.

A TISAX label covers all ten NIS2 Article 21 measures, per ENX's own expert opinion. Here is the control mapping and the five gaps it leaves open.

TISAX awareness training is assessed under VDA ISA control 2.1.3 and graded on a 0–5 maturity scale. Here is the scope, the refresh cadence, and the evidence you need to reach level 3.

A TISAX label lasts three years. Miss the recertification window and it lapses on the ENX portal, visible to every OEM. Here is how to plan backwards.

Moving from ISO 27001 to TISAX®? The control-by-control map to VDA ISA 6.0.3: what carries over, what is partial, and what has no ISO equivalent.

Does ISO 27001 cover TISAX? A certified 2022 ISMS covers roughly 70-80% of the VDA ISA catalogue. Here is exactly where they overlap and where the gap is.

The ISO 27001 Statement of Applicability is the first document auditors open: what it must contain, where it fails, and how to keep it audit-ready.

NIS2 essential entity criteria: how sector and size decide essential vs important, the size-exempt categories, and what classification really changes.

VDA ISA 6.0.3 explained: catalogue structure, version timeline, what changed in the 6.0 line, and what suppliers should expect next.

What automotive supplier TISAX requirements actually mean in OEM procurement, which assessment level you need, what drives it, and how to read the contract clause.

ISO/IEC 27001:2013 certificates expired on October 31, 2025. Here is the practical path back to certification for organisations that did not transition in time.

Why leading automotive, aerospace, and technology companies trust ITIS-Secure to take them from security gaps to full certification — fast. Learn our 7-step methodology for TISAX®, ISO 27001, and NIS2.

What changed for TISAX® in 2026: VDA ISA 6.0.3, label deadlines, and a step-by-step readiness roadmap for automotive suppliers.

A comprehensive implementation guide for SMEs facing the NIS2 Directive. Learn the 7 core steps to achieving a defensible compliance posture.

For mid-sized automotive tier suppliers and technology service providers, hiring a full-time Chief Information Security Officer (CISO) is often prohibitively expensive and unnecessary for day-to-da...

The ISO 27001:2022 transition deadline has passed. What changed, the 11 new Annex A controls, and how to update your ISMS if you are still on 2013.

In the enterprise security space, there is a dangerous misconception that running an automated vulnerability scanner constitutes a "penetration test."

The updated Network and Information Security Directive (NIS2) completely overhauls the cybersecurity landscape across the European Union. Unlike its predecessor, NIS2 aggressively expands the scope...

Despite millions of dollars invested in Next-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), and [Cloud Security Posture Management (CSPM) tools](/blog/cspm-finding-misconfigura...

For organizations navigating the complex landscape of information security compliance, deciding between ISO/IEC 27001 and TISAX® (Trusted Information Security Assessment Exchange) is a critical str...

For modern enterprises, the traditional "castle and moat" security model is obsolete. Remote workforces, SaaS sprawl, and multi-cloud environments (AWS, Azure, GCP) have permanently dissolved the c...

The financial sector is the primary target for advanced cybercrime syndicates and state-sponsored attacks. In response to the growing systemic risk posed by digital interconnectedness, the European...

For automotive suppliers, the mandate for cybersecurity has never been more complex. Today's connected vehicles contain upwards of 100 million lines of code, transforming them into mobile data cent...

The rapid migration to public cloud infrastructure (AWS, Azure, GCP) has fundamentally altered enterprise risk profiles. While cloud providers guarantee the security *of* the cloud, the customer re...

A cyberattack is no longer a question of "if," but "when." When a ransomware syndicate breaches your network or a critical supplier is compromised, executive leadership has minutes—not days—to make...

Securing an ISO/IEC 27001 certification is a rigorous process involving multiple layers of assessment. For many organizations, the terminology surrounding the audit lifecycle—Stage 1, Stage 2, inte...

Despite massive investments in Next-Generation Firewalls, Endpoint Detection, and overarching Zero-Trust Architectures, the most vulnerable layer in an...

You can outsource your payroll, your cloud hosting, and your customer service, but you cannot legally outsource your risk. Modern enterprises operate within deeply interconnected digital supply cha...