Supply chain security is a NIS2 measure (Art. 24 of Legislative Decree 138/2024). Nispo keeps the ICT supplier register with criticality, questionnaires and deadlines.

Supplier register

The supplier table shows compliance, risk category and the next deadline at a glance.

  • Risk category — every supplier classified by how critical its service is
  • Compliance status — outcome of the questionnaire and of the required documents
  • Next deadline — contracts, DPAs and certifications, with advance notice
Supplier register · sample data 42 active · 7 critical
SupplierRiskComplianceNext deadline
Hosting Nord S.r.l.Data centre and housing High Compliant 31 Dec 2026DPA
Gestionale Cloud S.p.A.Cloud ERP High To review In 3 daysCyber questionnaire
Rete Servizi ITIT systems support Medium Compliant 15 May 2027Contract
Paghe Online S.r.l.Payroll processing Medium Pending —Questionnaire sent
Stampa & ArchivioDocument management Low Out of scope —Not required

Supply chain

For each supplier: which data they process, where, with which sub-suppliers and who owns them in your team.

  • Guided inventory — structured records by category: cloud, software, managed services, hardware
  • Internal owner — every supplier has an owner in your team, with dedicated notifications
  • Cyber questionnaires — send, collect and archive your suppliers’ security assessments
Supplier record · example High criticality

Gestionale Cloud S.p.A.

Software and cloud services · Cloud ERP
Owner
M. Ferri · IT Manager
Data processed
Customer records, invoicing
Location
EU · Italy
Sub-suppliers
Hosting Nord S.r.l. · data centre
Questionnaire
Due in 3 days
DPA
Signed · renewal 31 Dec 2026
ISO/IEC 27001
Valid certificate

The ACN process

For supplies with a security impact ACN describes four phases. Nispo keeps the register and documentation for each; contracts and decisions remain yours.

PhaseACN referenceWhat Nispo does
Risk assessment of the supplyGV.SC-07Criticality, data processed, location, sub-suppliers and internal owner for each supplier
Security requirements consistent with the riskGV.SC-01Security questionnaires and required documents (DPAs, certifications) recorded per supplier
Requirements in new, renewed or extended contractsGV.SC-05Archive of contract documents and contract and DPA deadlines with reminders
Periodic verification that requirements are metGV.SC-07Compliance status per supplier, questionnaire and certification deadlines
Relevant NIS suppliers in the annual update (15 April – 31 May)Det. 127437/2026Generates the file of relevant suppliers to upload to the ACN portal, from the register

A 30-minute demo: we show you the supplier register and how it connects to the rest of your NIS2 requirements.