What the directive puts on the buyer
Article 21(2)(d) of Directive (EU) 2022/2555 lists supply chain security among the risk management measures, including the security-related aspects of the relationship between an entity and its direct suppliers. Article 21(3) tells the entity to take account of the vulnerabilities specific to each supplier, the overall quality of that supplier's products and its secure development practices. Article 23 sets the clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Read them together and the position is plain. The obligation sits with the entity. The information needed to discharge it sits with suppliers, and nothing in the directive gives the entity a right to demand it. That right has to be bought, in a contract, before the incident.
Where the national texts diverge
The transposition deadline was 17 October 2024. Several member states missed it and the Commission opened infringement proceedings the following month, so anyone drafting supplier language now is drafting against a set of national texts that are still moving. Three differences matter to a clause.
- Germany's implementation act rewrites the BSI-Gesetz rather than standing alone. The risk management measures land in Section 30 and the three-stage reporting in Section 32, which means a buyer can pass the reporting obligation through to a supplier by reference to a section number that the supplier's own counsel can look up.
- Belgium transposed early and attached a conformity assessment route to its framework, so a Belgian buyer can ask a supplier for an assessed level instead of a self-declaration, and can say in the contract which level.
- Italy runs registration through fixed annual windows with the national cybersecurity agency, which fixes the date by which a buyer must know whether a supplier's failure takes an in-scope service down. That is a drafting deadline, not an administrative one.
We do not read all of these in the original language. Where our reading rests on a translation we say so in the deliverable, and where the national instrument is still a bill rather than an act we say that too. It is the kind of caveat that gets dropped in a summary and then relied on in a negotiation.
The gaps that show up in ordinary commercial terms
Our sample was the published standard terms of software and hosting providers — the documents a buyer signs unchanged when it is too small to negotiate. They are public, and they are representative for exactly that reason. The same five gaps recur.
- Notification triggers copied out of data protection templates, so they fire on personal data and nothing else. A three-day outage of an operational technology (OT) monitoring platform holding no personal data trips none of them.
- The notification clock running from the supplier's internal escalation rather than from its own detection, which lets a supplier hold an incident inside its process and start the clock late without breaching anything.
- An audit right limited to an annual questionnaire: no test results, no subcontractor list, no right to the outcome of a post-incident review.
- Subcontractor and hosting-region changes notified after the event, or not at all.
- Certification evidence collected once at onboarding and filed. Certificates carry a scope statement, and a scope statement that excludes the service you buy is worth nothing. Nobody reads them.
The clause we withdrew
Our first model clause put a 24-hour notification obligation on every supplier in scope, worded to mirror the reporting article so a buyer could pass the obligation straight through. We put it to our own suppliers first, because our own supplier list is the only one we control. It runs to 11 companies. Two of them are large enough that their standard form is the contract and no drafting of ours will change it. One asked a fair question we could not answer from the clause: what counts as its detection. We had used the word without defining it. The clause was withdrawn and rewritten to tier the supplier base — a supplier whose failure stops an in-scope service notifies within 24 hours, everyone else within 72 hours, with the tier set by the buyer and reviewed annually. Tiering was the right structure and we should have started there instead of arriving at it through a refusal.
A clause the supplier will not sign is not a control. It is a negotiation lost in advance
What survived into the model language
- Incident defined by reference to the availability, integrity and confidentiality of the service supplied, never by reference to personal data.
- Notification in writing to a named security contact, with the clock running from the supplier's own detection, and detection defined in the definitions clause rather than assumed.
- A right to the written outcome of the supplier's post-incident review within 30 days, and a right to attend where the supplier holds one.
- Any change of subcontractor or hosting region notified 30 days in advance, with a right to object.
- Annual evidence: a current certificate with its scope statement read and recorded, or a completed assessment against the same controls.
What we cannot answer yet
Proportionality, and it is not a small gap. A specialist supplier of a dozen people with one product and no security staff cannot carry the clause a hosting provider with thousands of customers can carry, and pretending otherwise produces a signed contract and no change in behaviour. The workaround is to hold the risk on the buyer's side with segmentation, time-limited supplier accounts and a documented manual fallback. That is containment, not compliance. The second open question is how a supervisory authority will treat a buyer that tiered its suppliers honestly and got a tier wrong. Nobody knows, because no decision has been published. We have no view worth reading before there is one.