Source: OJ L 333, 27.12.2022, p. 80–152

Current language: EN

Article 22 Union level coordinated security risk assessments of critical supply chains


Summary What does Article 22 of the NIS 2 directive say?

This article establishes a mechanism for coordinated, Union-level security risk assessments of critical ICT supply chains.

It connects directly to Article 21, which requires entities to consider supply chain security as part of their risk-management measures — Article 22 is the upstream process that informs those considerations at a collective, cross-border level.

The Cooperation Group leads these assessments in cooperation with the Commission and ENISA, and both technical and non-technical risk factors are within scope.

Important points:

  • The Cooperation Group, together with the Commission and ENISA, may carry out coordinated security risk assessments of specific critical ICT services, systems, or product supply chains.
  • The Commission is responsible for identifying which specific critical ICT services, systems, or products are subject to these assessments, after consulting the Cooperation Group, ENISA, and where necessary, relevant stakeholders.
  • These assessments feed directly into the supply chain security obligations placed on entities under Article 21.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The Cooperation Group, in cooperation with the Commission and ENISA, may carry out coordinated security risk assessments of specific critical ICT services, ICT systems or ICT products supply chains, taking into account technical and, where relevant, non-technical risk factors.

    1. The Commission, after consulting the Cooperation Group and ENISA, and, where necessary, relevant stakeholders, shall identify the specific critical ICT services, ICT systems or ICT products that may be subject to the coordinated security risk assessment referred to in paragraph 1.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod