NIS2Art. 21(2)(d)voice-validated
NIS2 Art21d: Art. 21(2)(d)
Network and Information Security Directive 2 (EU 2022/2555)
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Essential and important entities must implement supply chain security measures, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers. Entities must take into account the specific vulnerabilities of each direct supplier and service provider, and the overall quality of products and cybersecurity practices of their suppliers and service providers.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1195.001 | 1. Attackers compromise software supply chains to introduce malicious code into products, directly violating NIS2 Art. 21(2)(d) requirements for assessing supplier product quality and cybersecurity practices. This enables initial access to essential and important entities. | 90% |
| T1195.002 | 1. Attackers compromise hardware supply chains by embedding malicious components or altering devices, directly undermining NIS2 Art. 21(2)(d) mandates for evaluating supplier product quality and security. This provides initial access to critical infrastructure. | 80% |
| T1195.003 | 1. Attackers compromise development tools or environments used by suppliers, injecting malicious code into legitimate software. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, which includes their development security, to prevent such initial access. | 80% |
| T1547.001 | 1. Attackers use compromised software from the supply chain to establish persistence by modifying registry run keys or startup folders. NIS2 Art. 21(2)(d) requires entities to assess supplier product quality and cybersecurity, preventing such persistent footholds. | 70% |
| 1. Attackers exploit vulnerabilities in third-party software or services, gained via supply chain compromise, to escalate privileges. NIS2 Art. 21(2)(d) mandates assessing specific vulnerabilities of suppliers, directly mitigating this privilege escalation vector. | 70% | |
| T1027.002 | 1. Malicious software introduced via a compromised supply chain often uses packing to evade detection. NIS2 Art. 21(2)(d) requires entities to evaluate the overall quality and cybersecurity practices of suppliers, which includes preventing the delivery of obfuscated threats. | 60% |
| T1003.001 | 1. Attackers, having gained access through a supply chain compromise, dump credentials from LSASS memory. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, aiming to prevent such credential access within their systems. | 60% |
| T1087.001 | 1. After initial access via a supply chain compromise, attackers discover local accounts to understand the environment and identify targets. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, which should include controls to limit post-compromise discovery. | 60% |
| 1. Attackers use remote system discovery to map the network after gaining access through a supply chain compromise. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, which should include network visibility and segmentation to limit discovery. | 60% | |
| T1021.001 | 1. Attackers use compromised credentials or vulnerabilities, potentially introduced via the supply chain, to move laterally using RDP. NIS2 Art. 21(2)(d) mandates assessing supplier vulnerabilities and cybersecurity practices to prevent such lateral movement. | 70% |
| 1. Attackers collect sensitive data from local systems after gaining access through a supply chain compromise. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, which should include data protection and monitoring to prevent data collection. | 70% | |
| T1071.001 | 1. Attackers use standard application layer protocols for command and control, blending malicious traffic with legitimate communications, often from compromised supply chain software. NIS2 Art. 21(2)(d) requires assessing supplier cybersecurity practices, including network security. | 60% |
| 1. Attackers exfiltrate collected data over established command and control channels, potentially using compromised supply chain elements as conduits. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, including data loss prevention. | 70% | |
| 1. Ransomware, potentially delivered via a compromised supply chain, encrypts data for impact. NIS2 Art. 21(2)(d) mandates assessing supplier product quality and cybersecurity practices to prevent such destructive attacks. | 80% | |
| 1. Attackers inhibit system recovery mechanisms, often after gaining access through a supply chain compromise, to maximize impact. NIS2 Art. 21(2)(d) requires entities to assess supplier cybersecurity practices, including backup and recovery integrity. | 70% |
Defending mitigations · 7
| Mitigation | What it does | Confidence |
|---|---|---|
| M1051 | 1. Implementing robust supply chain security directly addresses NIS2 Art. 21(2)(d) by ensuring entities assess and manage security risks associated with direct suppliers and service providers, covering product quality and cybersecurity practices. | 90% |
| M1048 | 1. Regular vulnerability scanning of third-party products and services directly supports NIS2 Art. 21(2)(d) by identifying 'specific vulnerabilities' in supplier offerings, enabling proactive risk management. | 80% |
| M1017 | 1. Training users on supply chain risks, such as phishing or malicious software from untrusted sources, enhances the 'cybersecurity practices' aspect of NIS2 Art. 21(2)(d) by reducing human-factor vulnerabilities related to supplier interactions. | 70% |
| M1030 | 1. Network segmentation limits the blast radius of a supply chain compromise by isolating third-party components or services. This aligns with NIS2 Art. 21(2)(d) by containing the impact of vulnerabilities in supplier products or practices. | 70% |
| M1026 | 1. Implementing privileged account management for systems interacting with supplier products or services reduces the impact of potential compromise. This supports NIS2 Art. 21(2)(d) by limiting the damage from vulnerabilities in supplier cybersecurity practices. | 70% |
| M1035 | 1. Limiting access to resources for third-party software and services, based on least privilege, directly addresses NIS2 Art. 21(2)(d) by containing potential damage from compromised supplier products or weak cybersecurity practices. | 70% |
| M1047 | 1. Auditing and logging activities related to third-party software and services enables detection of anomalous behavior stemming from supply chain compromises. This supports NIS2 Art. 21(2)(d) by monitoring the 'cybersecurity practices' and products of suppliers. | 60% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-913 | 1. This weakness represents a failure to adequately manage security for assets provided or managed by third parties, directly violating NIS2 Art. 21(2)(d) requirements for supply chain security and assessment of supplier practices. | 90% |
| CWE-119 | 1. This common software vulnerability in supplier products can lead to arbitrary code execution, directly impacting the 'quality of products' and 'cybersecurity practices' that NIS2 Art. 21(2)(d) mandates entities to assess. | 80% |
| CWE-787 | 1. This critical software flaw in third-party components allows attackers to overwrite memory, leading to crashes or arbitrary code execution. NIS2 Art. 21(2)(d) requires entities to consider 'specific vulnerabilities' and 'quality of products' from suppliers. | 80% |
| CWE-200 | 1. This weakness in supplier software or services can lead to data breaches, directly undermining NIS2 Art. 21(2)(d) requirements for assessing supplier cybersecurity practices and product quality to protect sensitive information. | 70% |
| CWE-284 | 1. Weak access controls in supplier products or services can allow unauthorized access, directly conflicting with NIS2 Art. 21(2)(d) mandates for assessing supplier cybersecurity practices and product quality to prevent unauthorized actions. | 70% |
| CWE-502 | 1. This vulnerability in third-party applications allows remote code execution when processing untrusted data. NIS2 Art. 21(2)(d) requires entities to assess 'specific vulnerabilities' and 'quality of products' from suppliers to prevent such attacks. | 60% |
| CWE-434 | 1. This weakness in supplier web services allows attackers to upload malicious files, leading to system compromise. NIS2 Art. 21(2)(d) mandates assessing supplier cybersecurity practices and product quality to prevent such attack vectors. | 60% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0221 compute · voice-rubric self-validated