Skip to content
NIS2 Recital 91 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this law. Contains: the full text of every article, recital and provision of this law. Everything links back to its source on overview.legal — legal information, not advice.

Recital 91 — coordinated critical supply chain risk assessments

In force — consolidated2022-12-27 · CELEX 02022L2555-20221227 · ELI ↗
Version history 1
  • 2022-12-27in force CELEX 02022L2555-20221227

The coordinated security risk assessments of critical supply chains, in light of the features of the sector concerned, should take into account both technical and, where relevant, non-technical factors including those defined in Recommendation (EU) 2019/534, in the EU coordinated risk assessment of the cybersecurity of 5G networks and in the EU Toolbox on 5G cybersecurity agreed by the Cooperation Group. To identify the supply chains that should be subject to a coordinated security risk assessment, the following criteria should be taken into account: (i) the extent to which essential and important entities use and rely on specific critical ICT services, ICT systems or ICT products; (ii) the relevance of specific critical ICT services, ICT systems or ICT products for performing critical or sensitive functions, including the processing of personal data; (iii) the availability of alternative ICT services, ICT systems or ICT products; (iv) the resilience of the overall supply chain of ICT services, ICT systems or ICT products throughout their lifecycle against disruptive events; and (v) for emerging ICT services, ICT systems or ICT products, their potential future significance for the entities’ activities. Furthermore, particular emphasis should be placed on ICT services, ICT systems or ICT products that are subject to specific requirements stemming from third countries.

Related across sources

Opinion 2/2021 EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries Adopted 1 EDPB - EDPS Joint Opinion 2 /2021 on the European Commission’s Implementing Decision on standard contractual clauses for the transfer of personal data to third countries… Opinion Jan 14, 2021 International Transfer Personal Data Processing Agreement
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
Opinion 9/2025 Worldline Group — processor BCRs EPDB, Opinion 9/2025 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the Worldline Group, 2025. French SA ·Opinion ·EDPB May 21, 2025 International Transfer Processors Codes of Conduct