NIS2 Directive: Secure your software supply chain
Supplier security, vulnerability management, fines up to 10 million euros
The European NIS2 directive requires essential and important entities to secure their software supply chain, including third-party components.
NIS2 Directive Timeline
December 14, 2022
NIS2 Adoption
Publication in the EU Official Journal (2022/2555)
January 16, 2023
Entry into Force
The directive officially enters into force
October 17, 2024
National Transposition
Deadline for transposition into Member States' law
2025 and beyond
Enforcement and Sanctions
Progressive enforcement by national authorities
Who is affected by NIS2?
18 essential and important sectors
Essential entities
- Energy (electricity, oil, gas, hydrogen)
- Transport (air, rail, maritime, road)
- Banking and financial market infrastructures
- Health (hospitals, laboratories, medical device manufacturers)
- Drinking water and wastewater
- Digital infrastructure (DNS, cloud, data centers)
- Public administration
- Space
Important entities
- Postal and courier services
- Waste management
- Chemical industry
- Food industry
- Manufacturing (medical devices, electronics, machinery)
- Digital services (marketplaces, search engines, social networks)
- Research
NIS2 Requirements for Software Supply Chain
What the directive mandates
Component Inventory
Know and document third-party software components
- Complete mapping of direct and transitive dependencies
- Documentation of versions in use
- Traceability of component origins
Vulnerability Management
Detect and fix security flaws
- Continuous monitoring of known vulnerabilities (CVE)
- Fast remediation process for critical flaws
- Documentation of measures taken
Supplier Security
Evaluate and monitor your providers
- Due diligence on critical suppliers
- Contractual security requirements
- Regular review of security practices
Incident Reporting
Notify authorities in case of incident
- Early warning within 24 hours
- Full notification within 72 hours
- Final report within one month of the incident
How LibTracker Helps You with NIS2
Your technical building block for supply chain compliance
What LibTracker covers
- Automatic inventory of all your dependencies (SBOM)
- Real-time CVE monitoring with alerts
- Audit history for your certifications
- SBOM export in standard formats (SPDX, CycloneDX)
- Documentation of your software supply chain
What LibTracker does not cover
NIS2 is an organizational directive. LibTracker is a technical tool that does not replace:
- Overall governance and risk analysis
- Organizational incident management
- Business continuity and recovery plans
- Staff training and awareness
- Non-software supplier audits
Risks of NIS2 Non-Compliance
Significant sanctions for organizations
Financial Sanctions
Up to €10M or 2% of revenue
for essential entities
Up to €7M or 1.4% of revenue
for important entities
Management Liability
- Personal liability of executives
- Temporary ban from management positions
- Mandatory cybersecurity training
Operational Risks
- Activity suspension for serious breaches
- Publication of sanctions by authorities
- Loss of trust from customers and partners
Security Risks
- Undetected vulnerabilities in your dependencies
- Increased exposure to cyberattacks
- Supply chain compromise
