NIS 2: EU adopts the supply chain Toolbox — what ILR will check
On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.
Verifiable fact — On 13 February 2026, the NIS Cooperation Group adopted the EU ICT Supply Chain Security Toolbox. Takeaway — Under NIS 2, supplier management is now prescriptive (Art. 21(2)(d) and Implementing Regulation 2024/2690) and must be evidenced in Luxembourg.
The case
On 13 February 2026, the European Commission published the “EU ICT Supply Chain Security Toolbox” adopted by the NIS Cooperation Group (Member States, Commission, ENISA). It sets a common approach to identify, assess and mitigate ICT supply chain risks, with risk scenarios and practical measures — including reducing dependencies on high‑risk suppliers. Official source: “Toolbox to improve ICT supply chain security” (published 13/02/2026; last updated 13/02/2026) on the Commission’s “Shaping Europe’s digital future” website. See the announcement and official downloads here: digital-strategy.ec.europa.eu.
This Toolbox lands in a framework already clarified by:
- Article 21(2)(d) of Directive (EU) 2022/2555 (NIS 2), mandating “security in relation to the supply chain, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”; official text: EUR‑Lex. eur-lex.europa.eu
- Implementing Regulation (EU) 2024/2690 of 17 October 2024, which turns these requirements into technical expectations: entities “establish, implement and apply a supply chain security policy governing the relationships with their direct suppliers/service providers”, with appropriate security clauses in contracts. Official text: EUR‑Lex (recital 14 and annex). eur-lex.europa.eu
In Luxembourg, the ILR is the competent NIS 2 authority for the vast majority of sectors. The Commission’s portal confirms the national contact points (NISS@ILR): digital-strategy.ec.europa.eu. To structure your programme, an outsourced CISO can steer supplier risk governance and compliance.
The legal reasoning
- Main legal basis: NIS 2, Art. 21(1) and (2), requiring “cybersecurity risk-management measures” covering at least ten domains; point (d) explicitly addresses the supply chain. Text and Recital (90) on a coordinated approach to critical chains: EUR‑Lex. eur-lex.europa.eu
- Technical details: Regulation (EU) 2024/2690 sets “technical and methodological requirements” for several categories of entities. Under Art. 21(2)(d), it details the expected components of a supply chain policy and the need to embed security clauses in supplier contracts. eur-lex.europa.eu
- Recent recommendations: the Toolbox adopted on 13/02/2026 proposes sample measures (diversifying critical suppliers, minimum security requirements, dependency assessments, risk scenarios) and fits the Cooperation Group’s mandate (Art. 14 NIS 2) and Recital (90). Official document: “Toolbox to improve ICT supply chain security”. digital-strategy.ec.europa.eu
- ENISA technical guides: ENISA’s “NIS2 Technical Implementation Guidance” of 26/06/2025 links Art. 21(2) with Regulation 2024/2690, including a “Supply chain security” domain with controls, evidence and mappings to standards (ISO, NIST). enisa.europa.eu
In short, supply chain security is no longer optional: it is a documented, verifiable and enforceable obligation. The 2026 Toolbox serves as a “common yardstick” to assess proportionality under NIS 2. For local context and ILR specifics, see NIS 2 Luxembourg.
What this changes in practice
For executives/DPOs/CISOs in Luxembourg (banks under CSSF excluded from ILR’s scope but subject to DORA; critical industry; digital providers; energy; health; public sector…), ILR can now rely on:
- Art. 21(2)(d) NIS 2 and Regulation 2024/2690 to require a formal, living supply chain policy (scope, roles, assessment cycle, requirements by criticality, contract clauses, audit rights). eur-lex.europa.eu
- The 2026 Toolbox to check high-impact scenarios (single‑supplier dependency, third‑party software components, MSP/MSSP, higher‑risk third countries, critical network equipment) and mitigations (diversification, SBOM transparency, exit/reversibility plans). digital-strategy.ec.europa.eu
- ENISA’s 2025 guide to benchmark your setup against expected controls, e.g., supplier criticality classification, security‑by‑contract with minimum measures, due‑diligence evidence, continuous oversight and coordinated response to supply chain vulnerabilities (VEX, joint management). enisa.europa.eu
Alignment examples
- Critical cloud provider: clauses mandating phishing‑resistant MFA, exportable logging, incident notification within NIS 2 timelines, audit/test evidence, and reversibility plan; basis: 2024/2690 (annex — access, logging, continuity) and Toolbox (diversification/backup plan). eur-lex.europa.eu
- OT/energy maintainer: documented segmentation, controlled remote access with PAM, contractual vulnerability remediation timelines, targeted annual audit; basis: Art. 21(2) and ENISA technical measures. eur-lex.europa.eu
- MSP/MSSP: requirements on environment segregation, secrets management, proof of 24/7 monitoring and co‑signed incident playbooks; basis: 2024/2690 (MSP/MSSP categories) and Toolbox (dependency reduction and concentration assessment). eur-lex.europa.eu
Common pitfalls
- “Shelf‑ware” policy. Regulation 2024/2690 requires an applied supply chain policy, not a static PDF. ENISA recommends KPIs (clause coverage, audit rate, remediation timelines) and hard evidence. eur-lex.europa.eu
- Only focusing on tier‑1 suppliers. The Toolbox stresses structural dependencies and concentration: look at tier‑2/tier‑3 (software components, your supplier’s subcontractors). Map SPOFs and switch‑over feasibility. digital-strategy.ec.europa.eu
- Vague contract clauses. 2024/2690 calls for “adequate” clauses aligned to Art. 21(2) measures. Translate them into measurable requirements (MFA, encryption, logs, patching timelines, testing, notification, reversibility) with expected evidence and audit rights. eur-lex.europa.eu
- No criticality criteria. Without a scoring grid (impact, substitutability, network/data exposure, sovereignty), proportionality cannot be justified. ENISA provides mappings and example controls by domain. enisa.europa.eu
- Forgetting EU certification linkage. NIS 2 Art. 24 allows the EU to mandate certified products/services/processes under the Cybersecurity Act for certain entities/categories. Anticipate these in procurement. Text: NIS 2 Art. 24. op.europa.eu
Official sources
- European Commission — EU ICT Supply Chain Security Toolbox (published 13 February 2026, official page with download): digital-strategy.ec.europa.eu
- ENISA — NIS2 Technical Implementation Guidance (26 June 2025): enisa.europa.eu
- EUR‑Lex — Directive (EU) 2022/2555 (NIS 2), notably Art. 21(2)(d) and Recital (90): eur-lex.europa.eu
- EUR‑Lex — Implementing Regulation (EU) 2024/2690 (17 October 2024): eur-lex.europa.eu
- European Commission — NIS 2 implementation in Luxembourg (ILR/NISS contacts): digital-strategy.ec.europa.eu
Practically, for May–August 2026 in Luxembourg, the bar is higher: your contracts and supply chain evidence must reflect, in black and white, Art. 21(2)(d) and 2024/2690, and integrate the Toolbox 2026 operational recommendations. Start with a focused cybersecurity audit, then get in touch for a prioritised remediation plan.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →