Skip to main content
Regulator guide · Supply-chain security

A supplier attestation is written by the supplier. The monitoring record is not.

NIS2 carries supply-chain security requirements. This page describes something narrower and checkable: the dated, outside-in monitoring record ShadowMap holds on the suppliers you nominate, produced with the identical methodology applied to your own estate.

What this page covers

A description of the monitoring evidence, its cadence and its limits: the material that sits underneath a supply-chain determination somebody else makes.

Out of scope

A reading of NIS2, an applicability assessment, or EU regulatory counsel. We do not issue those.

Scope of this page

A monitoring record, not a reading of the directive

Whether NIS2 binds your entity, which of its requirements attach, and what discharges them, are questions for your compliance function and its advisers.

A supply-chain security requirement is answered with evidence about suppliers, and the evidence most programmes hold is a questionnaire response and a contract clause. Both are attestations. Both were written by the party being assessed, about a moment that has already passed, and neither one changes when the supplier's estate does. An attestation carries a signature and an observation cannot sign anything, so the form does not go away.

ShadowMap contributes the other kind of evidence: continuous outside-in monitoring of the suppliers you nominate. Nothing is installed, no agent, no credentials, and no participation is required from the supplier. What accrues is a dated record of what was reachable from the public internet on their estate, what changed, when your team was told, and what they did about it. The strongest thing that record carries is that a control operated, on stated dates, over a stated scope, with a result somebody can reproduce.

The limit is equally plain. Outside-in monitoring sees what is reachable from the public internet. It does not see inside a supplier. The section further down states that boundary as four explicit kinds of statement. On scope: NIS2's annexes name manufacturing sub-sectors directly, so this question reaches industrial groups that had never previously thought of themselves as regulated entities.

When the record gets asked for

Three occasions, and a file of attestations answers none of them well

The supplier lifecycle (onboarding, continuous review, and the form that still has to be filled in) is set out on third-party risk management, and what follows is narrower: three occasions on which somebody puts a question about a supplier to you, and what a monitoring record is and is not able to put in front of them.

01 Flow-down

When a customer sends down their own supplier-security schedule

What is being asked for
Evidence about the parties behind the service you sell, on the terms your customer has agreed with somebody else. The schedule usually arrives written for their programme, and the deadline attached to it is commercial, not statutory.
What a file of attestations can return
The questionnaire responses and certificates your own suppliers have given you. Each is signed, each is accurate as at the date on it, and none of them was produced by anyone independent of the party being described.
What the record adds
A dated, outside-in account of the same suppliers, produced by neither of you and reproducible by either. It does not answer whether the schedule is satisfied. But it stops the response consisting entirely of paper the suppliers wrote about themselves.
02 Between cycles

When the question is what has changed since the last review

What a review cycle can date
The days it ran on.
What is observable without asking
Every hostname answering from the public internet across the supplier's apex domains, the administrative interfaces reachable in front of them, and the credential material already attributed to that domain. An acquisition brings inherited infrastructure with it; a migration leaves an old edge answering; an interface opened for a maintenance window stays open. Little of that is something a supplier would think to notify, and some of it is not something the supplier has noticed either.
What the record adds
An entry dated to the week the change became observable. That is the entry a review cycle structurally cannot produce: one for a month in which nobody was scheduled to look.
03 Incident

When something has already gone wrong

What gets asked first
Which of our suppliers is affected, since when, what was reachable on their estate before this became public, and what did we do about it at the time. Three of those four are questions about a record.
What the record can answer
What was externally observable on the monitored supplier estates, on which dates, which findings were raised, who they were assigned to and what disposition each one reached. What it cannot answer is anything that was never reachable from outside.
What the record adds
The answer is retrieved from a dated record instead of being reconstructed under pressure from inboxes and memory, and the reconstruction is the part that goes wrong.

The honest boundary

Four kinds of statement, and two of them are not evidence about the supplier

An evidence pack that overstates one row discredits the rest of itself in front of the person reading it.

These are statements about the record as a whole. The vocabulary each individual finding declares itself in is published once, on third-party risk management, where each state is defined.

What an outside-in supplier monitoring record can and cannot support
Kind of statementWhat the record actually holdsWhat you can do with it
Evidenced directly What was reachable from the public internet on a monitored supplier estate, on stated dates, and what changed between them. Cite it. The date, the scope and the observation travel together.
Evidenced as an operating control That the monitoring ran, over which supplier estates, on what cadence, what each finding was assigned to and what disposition it reached, including the exceptions and the misses against your own service levels. Evidence that the control operated, not only that it exists.
Observed Seen from outside a supplier's estate and nothing further. Authorisation to test another company's systems is not yours to give and we do not assume it, so nothing was probed. One carve-out: where an exposed supplier-staff identity maps to an account on your own systems (a contractor remote-access portal, a shared tenancy, a federated login), that account is your estate, not theirs. Route to the supplier as a confirm-and-fix, with the observation and its date attached. The carve-out is validated under the same audit trail as any first-party finding.
Beyond what outside-in can see A supplier's internal segmentation, its personnel screening, its contractual flow-down to its own suppliers, its backup regime, its incident procedure. None of it is reachable from the public internet and none of it is claimed here. Attestation, audit and contract. This record does not substitute for them.
Key
  • Direct observation, dated
  • The control operating
  • A lead for the supplier
  • Not ours to evidence

The sequence

How a supplier gets into the record

The order matters, because each stage bounds what the next one is ever allowed to look at. Nothing is assessed that was not first attributed, and nothing is attributed that you did not first nominate.

The claim, unpacked

"The same methodology" is a checkable statement

It is the sentence this whole page rests on, so it should not have to be taken on trust. Here is what it means in each place it bites, and what it deliberately leaves out.

One outside-in engine, applied to a supplier estate As of August 2026
  • The same discovery runs against a supplier’s apex domains as against your own.
  • The same categories, the same arithmetic and the same bands produce a supplier’s rating and your own. That is what makes an internal target and a supplier threshold directly comparable.
  • The same finding record. A supplier finding carries a dated observation, an owner, a disposition and a change history, the same as a first-party finding, and it lives in the same product.
  • The same sub-processor view: the hosting, DNS, mail, certificate and authentication providers each supplier actually resolves to, compared across the whole monitored portfolio, so a shared upstream becomes a counted fact with a date on it.
  • Cadence is continuous, so the interval between a supplier-side change becoming externally observable and your team holding it as a finding is not bounded by a review calendar.

Deliberately excluded

  • No legal reading. Nothing here establishes whether NIS2 binds your entity, which of its requirements attach, or what would discharge them.
  • No testing of a supplier’s systems. Supplier findings arrive observed and untested, with the one narrow exception set out in the ledger above.
  • No register of onward suppliers. Showing which providers a supplier resolves to is not the same as the list of sub-suppliers your contract may oblige them to maintain.
  • No filing, notification or regulatory-reporting workflow.

Questions this page gets asked

Before you take this to your advisers

Does this make us NIS2 compliant?

No, and no monitoring product can. What ShadowMap produces is a dated, independent record of what was externally observable about the suppliers you nominate, and of the monitoring that observed it. Whether that record discharges any particular obligation is a judgement we are not in a position to make.

Do you test our suppliers' systems?

No. Not without authorisation from the party that owns the estate, and in a supply-chain relationship that authorisation is not yours to give. Supplier findings arrive observed and untested, with the observation and its date attached so the supplier can act on it. The exception is narrow: where an exposed supplier-staff identity maps to an account on your own systems, a contractor remote-access portal or a shared tenancy, that account is your estate and is in scope for validation under the same audit trail as any first-party finding. Continuous Automated Red-Teaming runs only where it is safe and authorised, and every finding states which mode it is in.

Most of our suppliers will not cooperate with an assessment. Does that stop this?

No, and that is the property that makes outside-in usable across a real supply chain. Discovery and assessment require no participation from the assessed party — no agent, no credentials, no questionnaire returned, and nothing touched that is not already reachable from the public internet. You will have contractual leverage over some suppliers and none at all over others, and the monitoring record does not distinguish between the two.

We are not established in the EU, but our customers are. Does any of this reach us?

That is a question for your advisers. What we can describe is the mechanism our customers report: regulated buyers pass their own supplier-security obligations down the chain as contractual requirements, so the practical trigger is often a clause in a customer contract rather than direct application of the instrument itself. If that is where you are, the useful preparation is the same either way: hold a dated record of your own external estate and of the suppliers behind the service you sell, well before somebody asks to see it.

The record starts on the day you nominate the first supplier

Nominate one supplier apex domain. A written snapshot comes back in two business days. No supplier cooperation required, and no call needed to get it. The rest of the register is scoped on a call, from the list you already keep.