NIS2 · May 2026 · 8 min.

NIS2 and Cyber Intelligence: Why Questionnaires Are No Longer Enough

NIS2 Art. 21(d) demands active supply chain security. Annual questionnaires do not meet this requirement — continuous Cyber Intelligence does.

What NIS2 Art. 21(d) Really Requires

NIS2 Art. 21(d) mandates 'supply chain security' as one of ten minimum measures. The BSI interpretation is clear: sending annual questionnaires is insufficient. What is required is risk-based, continuous management of all critical suppliers — with documented assessment, ongoing monitoring and demonstrable measures when risks are identified.

The Questionnaire Problem

Questionnaires measure self-disclosure — not the actual security situation. A supplier can answer all questions correctly and still have unpatched critical CVEs, leaked credentials on the dark web or active ransomware indicators.

Cyber Intelligence as NIS2 Evidence

Darkscope provides the technical foundation for NIS2-compliant supply chain security: daily external security assessment of all suppliers, automatic documentation of all monitoring results, immediate alerts on risk increases, and audit-ready evidence for BSI inspections.

Frequently Asked Questions

Welche Unternehmen fallen unter NIS2?
Unternehmen ab 50 Mitarbeitern oder 10 Mio. € Umsatz in 18 kritischen Sektoren. Nutzen Sie unseren Compliance-Check für eine erste Einschätzung.
Reicht ISO 27001 für NIS2-Compliance?
ISO 27001 ist eine gute Basis aber nicht ausreichend. NIS2 fordert zusätzlich aktives Lieferantenmonitoring und Meldepflichten die ISO 27001 nicht abdeckt.
Back to Knowledge Hub

See Darkscope in Action

Get a personalised demo and see how Darkscope protects your supply chain in real time.

Request Demo →