Skip to main content
Regulator guide · Supply-chain security

A supplier attestation is written by the supplier. The monitoring record is not.

NIS2 carries supply-chain security requirements, and the evidence most programmes hold about their suppliers is a form those suppliers filled in about themselves. This page does not tell you what the directive obliges your entity to do. It describes something narrower and checkable: the dated, outside-in monitoring record ShadowMap holds on the suppliers you nominate, produced with the identical methodology applied to your own estate.

What this page is

A description of the monitoring evidence, its cadence and its limits — the material that sits underneath a supply-chain determination somebody else makes.

What it is not

A reading of NIS2, an applicability assessment, or EU regulatory counsel. We do not issue those, and a monitoring platform that offered to would be worth less, not more.

Scope of this page

A monitoring record, not a reading of the directive

Whether NIS2 binds your entity, which of its requirements attach, and what discharges them, are questions for your compliance function and its advisers. They are not questions a monitoring platform is in a position to answer, and this page does not try.

What we can be precise about is the other half of the problem. A supply-chain security requirement is answered with evidence about suppliers, and the evidence most programmes hold is a questionnaire response and a contract clause. Both are attestations. Both were written by the party being assessed, about a moment that has already passed, and neither one changes when the supplier's estate does. That is not a criticism of questionnaires — an attestation carries a signature and an observation cannot sign anything, which is why the form does not go away. It is an observation about what a file made only of attestations can and cannot demonstrate.

ShadowMap contributes the other kind of evidence: continuous outside-in monitoring of the suppliers you nominate, using the identical methodology applied to your own external estate — the same discovery, the same categories, the same arithmetic, the same bands. Nothing is installed, no agent, no credentials, and no participation is required from the supplier. What accrues is a dated record of what was reachable from the public internet on their estate, what changed, when your team was told, and what they did about it. The strongest thing that record carries is not a rating. It is that a control operated, on stated dates, over a stated scope, with a result somebody can reproduce.

The limit is equally plain, and it belongs here rather than at the bottom of the page. Outside-in monitoring sees what is reachable from the public internet. It does not see inside a supplier — not their segmentation, not their screening, not their backups, not the flow-down clauses in their own supplier contracts. The section further down states that boundary as four explicit kinds of statement, because a boundary rendered as a disclaimer is a boundary nobody reads. And for what it is worth on scope: NIS2's annexes name manufacturing sub-sectors directly, which is why this question reaches industrial groups that had never previously thought of themselves as regulated entities — but whether it reaches yours is still not ours to say.

When the record gets asked for

Three occasions, and a file of attestations answers none of them well

The supplier lifecycle — onboarding, continuous review, and the form that still has to be filled in — is set out on third-party risk management, and this page does not restate it. What follows is narrower: three occasions on which somebody puts a question about a supplier to you, and what a monitoring record is and is not able to put in front of them.

01 Flow-down

When a customer sends down their own supplier-security schedule

What is being asked for
Evidence about the parties behind the service you sell, on the terms your customer has agreed with somebody else. The schedule usually arrives written for their programme rather than yours, and the deadline attached to it is commercial rather than statutory.
What a file of attestations can return
The questionnaire responses and certificates your own suppliers have given you. Each is signed, each is accurate as at the date on it, and none of them was produced by anyone independent of the party being described.
What the record adds
A dated, outside-in account of the same suppliers, produced by neither of you and reproducible by either. It does not answer whether the schedule is satisfied — that is between you, your customer and your advisers — but it stops the response consisting entirely of paper the suppliers wrote about themselves.
02 Between cycles

When the question is what has changed since the last review

What a review cycle can date
The days it ran on. A cycle produces an assessment as at the date it was carried out, and between two of them the file has nothing to date — not through negligence, but because a cycle has no instrument that runs while it is not running.
What is observable without asking
Every hostname answering from the public internet across the supplier's apex domains, the administrative interfaces reachable in front of them, and the credential material already attributed to that domain — resolved without the supplier taking part in anything. An acquisition brings inherited infrastructure with it; a migration leaves an old edge answering; an interface opened for a maintenance window stays open. Little of that is something a supplier would think to notify, and some of it is not something the supplier has noticed either.
What the record adds
An entry dated to the week the change became observable, carrying the asset it affects, the owner it was assigned to and the disposition they reached. That is the entry a review cycle structurally cannot produce: one for a month in which nobody was scheduled to look.
03 Incident

When something has already gone wrong

What gets asked first
Which of our suppliers is affected, since when, what was reachable on their estate before this became public, and what did we do about it at the time. Three of those four are questions about a record, not about the incident.
What the record can answer
What was externally observable on the monitored supplier estates, on which dates, which findings were raised, who they were assigned to and what disposition each one reached. What it cannot answer is anything that was never reachable from outside — and the section below sets out exactly where that line falls.
What the record adds
The answer is retrieved from a dated record rather than reconstructed under pressure from inboxes and memory, and the reconstruction is the part that goes wrong.

The honest boundary

Four kinds of statement, and two of them are not evidence about the supplier

The useful question is not whether outside-in monitoring is good evidence. It is which specific statements it supports, and which it does not — because an evidence pack that overstates one row discredits the rest of itself in front of the person reading it.

These are statements about the record as a whole. The vocabulary each individual finding declares itself in — validated, observed but not validated, references you but not attributed, recorded as nothing found — is published once, on third-party risk management, and is not restated here in different words.

What an outside-in supplier monitoring record can and cannot support
Kind of statementWhat the record actually holdsWhat you can do with it
Evidenced directly What was reachable from the public internet on a monitored supplier estate, on stated dates, and what changed between them. An observation with a timestamp on it. Cite it. The date, the scope and the observation travel together.
Evidenced as an operating control That the monitoring ran, over which supplier estates, on what cadence, what each finding was assigned to and what disposition it reached — including the exceptions and the misses against your own service levels. Evidence that the control operated, which is a different thing from evidence that it exists.
Observed, not validated Seen from outside a supplier's estate and nothing further. Authorisation to test another company's systems is not yours to give and we do not assume it, so nothing was probed. One carve-out, and it belongs here rather than in a footnote: where an exposed supplier-staff identity maps to an account on your own systems — a contractor remote-access portal, a shared tenancy, a federated login — that account is your estate, not theirs. Route to the supplier as a confirm-and-fix, with the observation and its date attached. The carve-out is the exception: it is validated under the same audit trail as any first-party finding.
Beyond what outside-in can see A supplier's internal segmentation, its personnel screening, its contractual flow-down to its own suppliers, its backup regime, its incident procedure. None of it is reachable from the public internet and none of it is claimed here. Attestation, audit and contract. This record does not substitute for them, and a page telling you otherwise would be selling you a gap.
Key
  • Direct observation, dated
  • The control operating
  • A lead for the supplier
  • Not ours to evidence

The sequence

How a supplier gets into the record

The order matters, because each stage bounds what the next one is ever allowed to look at. Nothing is assessed that was not first attributed, and nothing is attributed that you did not first nominate.

The claim, unpacked

"The same methodology" is a checkable statement

It is the sentence this whole page rests on, so it should not have to be taken on trust. Here is what it means in each place it bites — and, at equal weight, what it deliberately leaves out.

One outside-in engine, applied to a supplier estate As of August 2026
  • The same discovery runs against a supplier’s apex domains as against your own: hostnames answering from the public internet, resolved without the assessed party taking part in the process.
  • The same categories, the same arithmetic and the same bands produce a supplier’s rating and your own. That is what makes an internal target and a supplier threshold directly comparable, rather than two scales that happen to share a letter.
  • The same finding record. A supplier finding carries a dated observation, an owner, a disposition and a change history — it is not a thinner object than a first-party one, and it is not held in a separate product.
  • The same sub-processor view: the hosting, DNS, mail, certificate and authentication providers each supplier actually resolves to, compared across the whole monitored portfolio, so a shared upstream becomes a counted fact with a date on it.
  • Cadence is continuous rather than cyclical, so the interval between a supplier-side change becoming externally observable and your team holding it as a finding is not bounded by a review calendar.

Deliberately excluded

  • No legal reading. Nothing here establishes whether NIS2 binds your entity, which of its requirements attach, or what would discharge them.
  • No testing of a supplier’s systems. Authorisation over a third party’s estate is not yours to give and we do not assume it — supplier findings arrive observed and untested, with the one narrow exception set out in the ledger above.
  • Nothing inside the supplier. Segmentation, personnel screening, contractual flow-down, backup regime and incident process are invisible from outside and are not claimed.
  • No register of onward suppliers. Showing which providers a supplier resolves to is not the same as the list of sub-suppliers your contract may oblige them to maintain, and the two should not be presented as though they were.
  • No filing, notification or regulatory-reporting workflow. ShadowMap produces the record; it lodges nothing with any authority on your behalf.

Questions this page gets asked

Before you take this to your advisers

Does this make us NIS2 compliant?

No, and no monitoring product can. Compliance is a determination about your entity, your obligations and your controls, and it belongs to your compliance function and its advisers. What ShadowMap produces is one input to that determination: a dated, independent record of what was externally observable about the suppliers you nominate, and of the monitoring that observed it. Whether that record discharges any particular obligation is a judgement we are not in a position to make and do not make anywhere on this page.

Do you test our suppliers' systems?

No — not without authorisation from the party that owns the estate, which in a supply-chain relationship is not yours to give. Supplier findings arrive observed and untested, with the observation and its date attached so the supplier can act on it. The exception is narrow and it is on the ledger above: where an exposed supplier-staff identity maps to an account on your own systems, a contractor remote-access portal or a shared tenancy, that account is your estate and is in scope for validation under the same audit trail as any first-party finding. Continuous Automated Red-Teaming runs only where it is safe and authorised, and every finding states which mode it is in.

Most of our suppliers will not cooperate with an assessment. Does that stop this?

No, and that is the property that makes outside-in usable across a real supply chain. Discovery and assessment require no participation from the assessed party — no agent, no credentials, no questionnaire returned, and nothing touched that is not already reachable from the public internet. You will have contractual leverage over some suppliers and none at all over others, and the monitoring record does not distinguish between the two. What it will not do is see inside any of them, cooperative or otherwise.

We are not established in the EU, but our customers are. Does any of this reach us?

That is exactly the question this page cannot answer for you, and the honest response is to send it to your advisers rather than guess at it. What we can describe is the mechanism our customers report: regulated buyers pass their own supplier-security obligations down the chain as contractual requirements, so the practical trigger is often a clause in a customer contract rather than direct application of the instrument itself. If that is where you are, the useful preparation is the same either way — hold a dated record of your own external estate and of the suppliers behind the service you sell, well before somebody asks to see it.

The record starts on the day you nominate the first supplier

Nominate up to three suppliers and one of your own apex domains. A written snapshot comes back in two business days — no supplier cooperation required, and no call needed to get it.