NIS2

European Union · Directive on measures for a high common level of cybersecurity SIGNET support: Compliance enablement — supply-chain security evidence

What it is

NIS2 is the EU directive setting cybersecurity obligations for essential and important entities across sectors from energy and transport to digital infrastructure. Among its most consequential requirements is supply-chain security: in-scope organisations must manage the cybersecurity risk of their direct suppliers and service providers, and be able to evidence that they do.

The directive is maintained by the European Commission. Official reference →

How SIGNET supports it

NIS2 sits in SIGNET's compliance enablement tier. SIGNET does not make an organisation NIS2-compliant; it gives the procurement function — where supply-chain risk is actually contracted for — the data structures that turn the directive's supplier obligations into evidence rather than assertion.

Supplier security posture becomes verifiable data: certifications and attestations travel as W3C Verifiable Credentials on the supplier's record and within qualification cases, checkable at onboarding and at award. Security requirements become enforceable data: eligibility thresholds are machine-readable Policy objects applied within the sourcing process, not clauses discovered at audit. And the evidence trail is native: every qualification decision, award, and change is an append-only, hash-chained Event with provenance, so when a regulator asks how supplier risk was assessed and who approved the award, the answer is a tamper-evident record, not a reconstruction.

Where it lives in the standard