Skip to content

Use cases · Procurement, suppliers and customers

For procurement and third-party risk

Your third parties' exposure, dated. Upstream, it is what NIS2 asks for in Article 21(3). Downstream, it is what stops you paying an invoice your customer never sent.

Upstream: your suppliers

Vulnerabilities specific to each direct supplier

The text does not ask for a general policy: it asks you to take into account what is specific to each third party, one by one. Here is what that looks like on a list of direct suppliers.

Your direct suppliers

  • Managed IT
  • Payroll
  • Logistics
  • Line-of-business vendor
  • Maintenance

05/2024access to that vendor's environment offered for sale — twenty-two months before your annual review

NIS2 requires taking into account the vulnerabilities specific to each direct supplier — Article 21(3). A self-assessment questionnaire does not establish that; a dated exposure does.

Directive (EU) 2022/2555, Article 21(3). The diagram is illustrative.

Downstream: your customers

The other side of the contract

No regulation requires you to look at your customers. The risk exists all the same: a compromised customer does not shut you down, they write to you — and the message comes from a perfectly legitimate address.

Your direct customers

  • Large account
  • Distributor
  • Reseller
  • Public-sector customer
  • Export account

02/2024this distributor's accounting mailbox present in a credential batch — four months before the request to change bank details

A compromised customer does not stop your production: they write to you. Payment fraud comes through a legitimate mailbox, and nothing in the message looks wrong. Knowing how long that account's credentials have been circulating is what lets you doubt at the right moment.

Schematic. The dates are illustrative and describe no real case.

The moments that matter

Before signing, and during the contract

  • When selecting a supplier

    What has already circulated about a candidate, and since when. A supplier exposed for two years is not a supplier exposed since yesterday.

  • When onboarding a customer

    Before opening a credit line or payment terms, knowing what is already circulating about the counterparty and its executives.

  • At annual review

    What has changed since the last review, dated, to bring hard facts to a discussion that usually stays declarative.

  • In the compliance file

    A written record of what was checked and when, to file in the NIS2 or DORA documentation.

What the text asks for

A declaration is not a verification

Article 21(3) of Directive (EU) 2022/2555 asks you to take into account the vulnerabilities specific to each direct supplier. A questionnaire filled in by the supplier says what the supplier declares, on the day they declare it — and there is nothing else to be drawn from it.

An exposure observed from the outside, dated and sourced, can be verified without depending on the third party's goodwill. That is true of a supplier, and just as true of a customer, whom nobody thinks to ask.

Start with your critical third parties

A list of suppliers and customers is enough to see what the archive adds to your last questionnaire round.

Book a demo