This text is for general information only. It does not constitute legal advice or a recommendation for any specific factual situation.
Regulation meets the contract
NIS2 increases the importance of cybersecurity risk management, including supplier-side risk. In practice, organisations need to combine security procedures, contractual requirements and real oversight of service delivery.
What to include in contracts
- security requirements and organisational standards,
- notification obligations in case of an incident,
- audit rights or alternative verification mechanisms,
- requirements for subcontractors,
- business continuity and exit planning,
- liability for breaches of security obligations.
The greatest value comes from consistency between procedures, contracts and procurement practice. Without it, an organisation may have formal documents that do not work during an incident.
Sources
NIS2 Directive: EUR-Lex.