A supply-chain security
requirement is answered with evidence about suppliers, and the evidence most programmes hold is
a questionnaire response and a contract clause. Both are attestations. Both were written by the
party being assessed, about a moment that has already passed, and neither one changes when the
supplier's estate does. An attestation carries a
signature and an observation cannot sign anything, so the form does not go away.
ShadowMap contributes the other kind of evidence: continuous outside-in monitoring of the
suppliers you nominate. Nothing is
installed, no agent, no credentials, and no participation is required from the supplier. What
accrues is a dated record of what was reachable from the public internet on their estate, what
changed, when your team was told, and what they did about it. The strongest thing that record
carries is that a control operated, on stated dates, over a stated scope,
with a result somebody can reproduce.
The limit is equally plain. Outside-in monitoring sees what is reachable from the public internet. It does not see inside a supplier. The section further down states that boundary as four explicit
kinds of statement. On scope:
NIS2's annexes name manufacturing sub-sectors directly, so this question reaches industrial
groups that had never previously thought of themselves as regulated
entities.