Software supply-chain controls for NIS2 readiness
Engineering practices that make third-party software, build paths, and supplier responsibilities easier to understand and govern.
Create an evidence-backed inventory
ENISA guidance on supply-chain cybersecurity emphasises visibility and coordinated risk management. Engineering teams should be able to identify critical software, services, suppliers, and dependencies involved in delivering an important business service.
Protect the path to production
Control who can change source, workflows, dependencies, artefacts, and release configuration. Use review, protected automation, short-lived credentials, traceable artefacts, and recovery procedures proportionate to the service risk.
- Assign owners for critical dependencies.
- Record approved sources and update policy.
- Separate build, approval, and production permissions.
- Test supplier outage and compromise scenarios.
Connect procurement and operations
Contractual expectations matter only when teams know how to act on them. Define notification paths, evidence access, change communication, continuity expectations, and the technical fallback when a supplier cannot meet them.