Your suppliers' risk is your risk — mapped once, not per regulation.
No regulation is called supply-chain risk — the obligations arrive attached to others. NIS2 addresses supplier relationships as a risk-management measure, DORA requires a register of ICT third-party arrangements, the Cyber Resilience Act reaches the components a manufacturer ships, and ISO 27001 and SOC 2 both ask whether supplier controls are defined and operating. The regimes word it differently; none of them want a different answer.
This makes it an operating problem with a duplication tax. A supplier assessed once can answer every regime. Assessed per regulation, the same vendor collects several questionnaires a year while the register drifts from reality between them.
Who it applies to
Any organization in scope for one of those regimes — which is nearly every organization with suppliers. What changes per regime is emphasis: who counts as critical, how deep the subcontracting chain must be documented, how often reassessment is expected. The underlying practice — know, assess, monitor, prove — is one practice.
One record, every regulation
The mechanism is a single record per supplier — services provided, data touched, criticality, assessment status, certification, next review — that each regime reads from. The NIS2 entry, the DORA register row, the ISO control evidence and the SOC 2 control cite the same underlying facts, so they cannot disagree with each other. When an assessment changes, every framework's view of that supplier changes with it.
What it asks, in operating terms
Across every regime that references it, supplier oversight reduces to the same handful of asks — one record answers them all.
| What the regimes ask | Where it is answered |
|---|---|
| Know your suppliers and what depends on them | Supplier register · services, data, criticality — one record each |
| Assess risk from what the supplier is to you | Assessment workflow · inherent risk scored, reassessed by criticality |
| Monitor certification, contract and SLA status through the year | TPRM connectors · status current from the systems that hold it |
| Document the chain behind critical arrangements | Supplier register · subcontracting chains documented per arrangement |
| Prove the oversight to each regime that asks | Per-regime exports · same facts, each framework’s shape |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a supplier register is made of:
- Suppliers
- 89 · one record each
- Critical arrangements
- 17 · chains documented
- Regime citations
- NIS2 · DORA · CRA · ISO 27001 · SOC 2
- Assessments
- current · 3 flagged for review
- Evidence
- sealed · sha256:b72c…10f9
Where teams usually start
With a demo walked through by TruSecure — the supplier register loaded with a handful of your own vendors, one record shown answering several regimes at once. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
Every sub-processor you inherit is another jurisdiction to assess. Ours is one, in the EEA, with none discontinued in the last 24 months.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2, DORA, and the Cyber Resilience Act each impose supply-chain or third-party risk obligations, but they largely reference the same underlying practice: assess, monitor, and prove oversight of vendors. TruSecure maintains one supplier risk record that maps to every regulation that references it.