Supply chain security is a NIS2 measure (Art. 24 of Legislative Decree 138/2024). Nispo keeps the ICT supplier register with criticality, questionnaires and deadlines.
Supplier register
The supplier table shows compliance, risk category and the next deadline at a glance.
- Risk category — every supplier classified by how critical its service is
- Compliance status — outcome of the questionnaire and of the required documents
- Next deadline — contracts, DPAs and certifications, with advance notice
| Supplier | Risk | Compliance | Next deadline |
|---|---|---|---|
| Hosting Nord S.r.l.Data centre and housing | High | Compliant | 31 Dec 2026DPA |
| Gestionale Cloud S.p.A.Cloud ERP | High | To review | In 3 daysCyber questionnaire |
| Rete Servizi ITIT systems support | Medium | Compliant | 15 May 2027Contract |
| Paghe Online S.r.l.Payroll processing | Medium | Pending | —Questionnaire sent |
| Stampa & ArchivioDocument management | Low | Out of scope | —Not required |
Supply chain
For each supplier: which data they process, where, with which sub-suppliers and who owns them in your team.
- Guided inventory — structured records by category: cloud, software, managed services, hardware
- Internal owner — every supplier has an owner in your team, with dedicated notifications
- Cyber questionnaires — send, collect and archive your suppliers’ security assessments
Gestionale Cloud S.p.A.
- Owner
- M. Ferri · IT Manager
- Data processed
- Customer records, invoicing
- Location
- EU · Italy
- Sub-suppliers
- Hosting Nord S.r.l. · data centre
- Questionnaire
- Due in 3 days
- DPA
- Signed · renewal 31 Dec 2026
- ISO/IEC 27001
- Valid certificate
The ACN process
For supplies with a security impact ACN describes four phases. Nispo keeps the register and documentation for each; contracts and decisions remain yours.
| Phase | ACN reference | What Nispo does |
|---|---|---|
| Risk assessment of the supply | GV.SC-07 | Criticality, data processed, location, sub-suppliers and internal owner for each supplier |
| Security requirements consistent with the risk | GV.SC-01 | Security questionnaires and required documents (DPAs, certifications) recorded per supplier |
| Requirements in new, renewed or extended contracts | GV.SC-05 | Archive of contract documents and contract and DPA deadlines with reminders |
| Periodic verification that requirements are met | GV.SC-07 | Compliance status per supplier, questionnaire and certification deadlines |
| Relevant NIS suppliers in the annual update (15 April – 31 May) | Det. 127437/2026 | Generates the file of relevant suppliers to upload to the ACN portal, from the register |
FAQ
The answers are on the FAQ page, together with every other question about Nispo and NIS2.
A 30-minute demo: we show you the supplier register and how it connects to the rest of your NIS2 requirements.