Compliance decisions
NIS2 supplier checks for employee AI
NIS2 is a directive implemented through national law. First establish the entity, sector, size and relevant jurisdiction, then assess the AI supplier’s role and risks under the applicable requirements. Article 21 includes direct-supplier security, but a generic AI subscription does not establish the customer’s or vendor’s legal status.
For Security leaders, legal teams and procurement at potentially covered EU entities
The dossier separates legal applicability from evidence about a proposed AI supplier.
Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.01
Identify the entity and national framework
Record the legal entity, activities, countries of establishment and relevant service delivery. NIS2 includes sector, size and other scope conditions; the applicable national implementation and any relevant sector-specific rules must be checked. Do not assume a group brand has one uniform status across all entities.
The fictional dossier concerns an EU manufacturing entity considering staff AI drafting. It deliberately leaves the actual national-law determination with the legal owner. The exercise provides the facts and questions needed for that decision, not an invented ruling that the company is essential or important.
Source context: NIS2: Directive (EU) 2022/2555
02
Define what the supplier can affect
Identify the service, data access, integration and business dependency. A standalone drafting account differs from an AI feature with broad access to a shared repository. Include the direct supplier and relevant onward dependencies rather than treating the brand displayed to the employee as the whole supply chain.
For the example, staff propose copying internal support material into an external assistant. The first evaluation can use invented text without a repository connection. That reduces the initial data exposure but does not, by itself, settle supplier security or NIS2 applicability.
Source context: NIS2: Directive (EU) 2022/2555
03
Ask for evidence related to the risk
Article 21 includes security-related aspects of relationships with direct suppliers and service providers. It directs attention to supplier-specific vulnerabilities, overall product quality and cybersecurity practices, including secure development procedures. Assess the evidence against the service actually used.
Useful questions address vulnerability handling, security updates, access control, incident cooperation, continuity and the data/connection boundary. A questionnaire score is not proof that those practices operate. Identify what a document establishes, what a technical test can show and which facts remain unverified.
Source context: NIS2: Directive (EU) 2022/2555
04
Connect supplier findings to the entity’s measures
NIS2’s risk-management approach also addresses incident handling, business continuity, effectiveness assessment, training, access and other measures. A supplier review should identify how its findings affect the entity’s own controls and responsibilities, not simply record a pass or fail badge.
The directive requires appropriate and proportionate measures, with relevant factors including exposure, size, likelihood and severity. Keep the reasoning specific to the proposed use. Do not state that every supplier must hold an invented NIS2 certificate or that one AI security product satisfies the entire framework.
Source context: NIS2: Directive (EU) 2022/2555
05
Keep local-law uncertainty actionable
The worked dossier assigns separate legal, procurement and security questions. If applicability remains unresolved, record the exact missing fact or authority to check. If a supplier control is unverified, identify the evidence owner and the permitted interim scope, such as an invented-data evaluation.
Review changes to the supplier, integrations, data or operational dependency. Keep the applicable national-law conclusion linked to the supplier evidence, while preserving the difference between a source-based legal requirement, a fictional example and an observed test result.
Source context: NIS2: Directive (EU) 2022/2555
Put it into practice
NIS2 AI supplier dossier
A fictional manufacturing company evaluates an external drafting service. The dossier keeps the applicability decision separate from supplier-control evidence.
Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.
Applicability
Entity, activities, country and national law
Supplier risk
Service, access, vulnerabilities and dependency
Decision
Actual scope, controls, owners and evidence
| Dossier field | Populated fictional fact | Evidence or decision needed |
|---|---|---|
| Entity and establishment | Example Components SAS, established in France, 300 staff in the exercise. | Legal owner verifies the actual sector, size/group rules and French implementing requirements. |
| Proposed service | External AI drafting for internal support instructions. | Business owner records the task, users and permitted data. |
| Connection and data | Initial proposal includes repository access; first evaluation removes that connection. | Security verifies actual permissions and data paths before any real deployment. |
| Supplier security | No verified development, vulnerability or incident evidence exists in the fictional proposal. | Procurement obtains service-specific evidence and assigns follow-up questions. |
| Continuity and dependency | Manual drafting is available in the example. | Operational owner assesses real outage effects rather than assuming the fallback settles risk. |
| Applicable duties | Entity/national-law conclusion is not established by this exercise. | Record the actual legal basis and any sector-specific interaction before claiming compliance. |
| Interim decision | Use invented instructions only while material questions are resolved. | Do not represent the teaching evaluation as approval for real company data. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
nis2-ai-supplier-dossier.mdInspect
# NIS2 AI supplier dossier
Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.
A fictional manufacturing company evaluates an external drafting service. The dossier keeps the applicability decision separate from supplier-control evidence.
| Dossier field | Populated fictional fact | Evidence or decision needed |
| --- | --- | --- |
| Entity and establishment | Example Components SAS, established in France, 300 staff in the exercise. | Legal owner verifies the actual sector, size/group rules and French implementing requirements. |
| Proposed service | External AI drafting for internal support instructions. | Business owner records the task, users and permitted data. |
| Connection and data | Initial proposal includes repository access; first evaluation removes that connection. | Security verifies actual permissions and data paths before any real deployment. |
| Supplier security | No verified development, vulnerability or incident evidence exists in the fictional proposal. | Procurement obtains service-specific evidence and assigns follow-up questions. |
| Continuity and dependency | Manual drafting is available in the example. | Operational owner assesses real outage effects rather than assuming the fallback settles risk. |
| Applicable duties | Entity/national-law conclusion is not established by this exercise. | Record the actual legal basis and any sector-specific interaction before claiming compliance. |
| Interim decision | Use invented instructions only while material questions are resolved. | Do not represent the teaching evaluation as approval for real company data. |
## Review steps
- Resolve jurisdiction and entity facts: Identify actual national implementation, sector, size/group and service-specific conditions.
- Evaluate the direct supplier: Ask for relevant secure-development, vulnerability, incident and access-control evidence.
- Document scope and follow-up: Separate the legal conclusion, supplier evidence and observed control results with accountable owners.
## Fictional evidence requests
- Legal: which national implementation and entity criteria govern Example Components SAS?
- Procurement: which legal supplier and service terms apply, including onward dependencies?
- Security: what access does the repository connection grant, and can the initial task run without it?
- Operations: what happens if the drafting service becomes unavailable or produces an incorrect result?
## Teaching disposition
Restrict this exercise to invented internal instructions with no repository connection. Obtain actual legal and supplier evidence before a real-data decision. No national law or supplier assurance has been invented for the scenario.
## Source and scope
Guide: https://aona.ai/resources/guides/nis2-employee-ai-supplier-review/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- NIS2: Directive (EU) 2022/2555: https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
Download nis2-ai-supplier-dossier.mdnis2-ai-supplier-dossier.csvInspect
Dossier field,Populated fictional fact,Evidence or decision needed
Entity and establishment,"Example Components SAS, established in France, 300 staff in the exercise.","Legal owner verifies the actual sector, size/group rules and French implementing requirements."
Proposed service,External AI drafting for internal support instructions.,"Business owner records the task, users and permitted data."
Connection and data,Initial proposal includes repository access; first evaluation removes that connection.,Security verifies actual permissions and data paths before any real deployment.
Supplier security,"No verified development, vulnerability or incident evidence exists in the fictional proposal.",Procurement obtains service-specific evidence and assigns follow-up questions.
Continuity and dependency,Manual drafting is available in the example.,Operational owner assesses real outage effects rather than assuming the fallback settles risk.
Applicable duties,Entity/national-law conclusion is not established by this exercise.,Record the actual legal basis and any sector-specific interaction before claiming compliance.
Interim decision,Use invented instructions only while material questions are resolved.,Do not represent the teaching evaluation as approval for real company data.
Download nis2-ai-supplier-dossier.csvBefore you proceed
Keep these distinctions clear
- A directive is not one identical national procedure
- Check the applicable implementation and entity conditions.
- A supplier score is not operating evidence
- Tie the conclusion to the service-specific documents and tests actually reviewed.
Apply it to employee AI use
Bring your actual data path.
Aona can help evaluate employee-AI visibility and sensitive-input controls within supported installed scope.
It does not classify an entity under NIS2, certify a supplier or replace the broader risk-management programme.
Use the invented drafting task to assess one data-input boundary while the legal and supplier dossier is completed.
Review your use caseFAQ
Questions for this decision
Does NIS2 apply to every organisation using AI?
Must every AI supplier have a NIS2 certificate?
Can removing a connector finish the supplier review?
Why is national-law status unresolved in the example?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- NIS2: Directive (EU) 2022/2555
Directive scope and Article 21 risk-management and direct-supplier security considerations, implemented through applicable national law.
law · checked 2026-09-21