Notes on NIS2 and supply chain assurance.
Plain-English writing on NIS2 compliance, supplier risk management, and the practical realities of mid-market cybersecurity. Practitioner-written — calm, factual, and honest about what we know and what's still settling.
- Pavel Láskanis2contractssupply-chain
The eight supplier-contract clauses in the NIS2 implementing regulation
Article 21(2)(d) is one line. The implementing regulation’s annex turns it into eight contract requirements — binding for the digital entity types it lists, best practice for everyone else. What each clause does, and how to retrofit at renewal.
Read the post - Pavel Láskanis2transpositioncentral-europe
One directive, four calendars: NIS2 in Slovakia, Czechia, Germany, and Austria
Slovakia live since January 2025, Czechia since November 2025, Germany overnight, Austria arriving 1 October 2026. One directive, four national calendars, mapped for the buyer.
Read the post - Pavel Láskanis2article-21practical
The five evidence artefacts that cover roughly 80% of Article 21(2)(d)
Supplier inventory, risk classification, per-supplier assessment evidence, decision trail, reaction plan — what each has to look like to hold up under a supervisory inquiry. The 80% is a practitioner’s number, not a measured statistic, and the 20% it leaves out is named at the end.
Read the post - Pavel Láskanis2supply-chainarticle-21
Most NIS2 obligations have a playbook. Supply chain security doesn’t.
Awareness training has a playbook. Incident response has a runbook. Patching is procedural. Supply chain security is structurally different — the evidence lives with external parties, in a dozen formats, expiring unevenly. The essay-length version of the argument.
Read the post - Pavel Láskanis2supplier-sidepractical
How to answer the NIS2 supplier questionnaire your customer just sent you
A long-time customer just sent you a sixty-question security questionnaire that wasn’t there last year. NIS2 happened. Here’s the five-step flow that makes the fourth one easy.
Read the post - Pavel Láskanis2soc2compliance
Why your SOC 2 doesn’t satisfy NIS2 (and what does)
A SOC 2 report covers a lot of NIS2 — but the parts it doesn’t cover are the parts NIS2 cares about most: supply chain, effectiveness review, management training. A practical crosswalk and a closing-the-gap plan.
Read the post
Release announcements on LinkedIn.
Follow the company page for pilot dates, product milestones, and the work as it ships. Public, low-volume, no inbox to clutter.
Follow Shards Cybersecurity