NIS2 · GDPR · Essential Entity · Art. 21

Vendor risk management for healthcare: NIS2, GDPR, and patient data in one programme

Your EHR vendor, PACS provider, and cloud infrastructure partner all have direct access to patient data and clinical systems. A compromised supplier does not just create a compliance finding; it halts operations. NIS2 and GDPR now require structured, documented vendor risk programmes for hospitals and healthcare entities above the essential entity threshold. Supplier Shield gives you the register, the assessments, and the audit trail.

€10 M+
NIS2 fines for essential entities
24 / 72 hrs
early warning then full incident notification under NIS2 Art. 23
Annex I
NIS2 classification covering hospitals and most healthcare providers

Trusted by global organisations

UNICCGaviThe Global FundGold StandardRépublique et canton de GenèveAbilene Advisors

§ The challenge

Where healthcare compliance teams are exposed

NIS2 transposition is complete across most EU member states. National supervisors are in active inspection mode. Healthcare entities are a priority enforcement sector, and supervisory questionnaires and on-site inspections are already underway.

Suppliers have deep access, with no formal risk review

NIS2 Article 21(2)(d) requires documented security measures for every supplier that could affect your security posture. For most healthcare teams, this is still done by email. Questionnaires go out. Responses are filed in shared drives. No scoring, no monitoring, no audit trail. When a supplier has a breach, you find out when they call you.

GDPR Article 28 DPAs are outdated or missing

Every vendor processing patient data, staff records, or operational health data must have a current, compliant data processing agreement. Sub-processor changes, new EHR integrations, and cloud migrations create gaps that go undetected for months. A single DPA audit finding can trigger a full supervisory review.

One compliance team, hundreds of vendor relationships

Most healthcare organisations run their vendor risk programme with one to three people covering hundreds of suppliers across clinical, IT, facilities, and procurement. Without a structured system, the team is always catching up, never ahead. Evidence sits across email threads, shared drives, and individual inboxes.

§ How we help

How Supplier Shield maps NIS2 and GDPR to your vendor programme

One structured platform for supply chain security assessments, DPA governance, and continuous monitoring, built for small compliance teams managing large supplier bases.

NIS2 supply chain security controls (Art. 21)

Run formal security assessments for every relevant vendor category.

Structured questionnaires aligned to NIS2 Article 21 requirements: network security, access controls, incident response capability, and physical security. Track contractual security requirements and monitor compliance status continuously. Vendors respond via a secure browser link with no account required.

GDPR vendor processing governance (Art. 28)

Maintain a live register of all data processing agreements and sub-processor chains.

Document every DPA, track review dates, and auto-flag when vendors change sub-processors or expand data processing scope. Integrates with your GDPR compliance programme inside Acuna GRC. No more chasing DPAs by email.

One-click supervisory audit pack

Every assessment, finding, and remediation action: immutable, timestamped, and exportable.

When your national NIS2 supervisor or external auditor asks for evidence of your supply chain security measures, you export a structured pack in one click. No manual assembly, no reconstructing email threads from 18 months ago.

§ Why us

Why healthcare compliance teams choose Supplier Shield

Swiss data hosting · GDPR adequacy decision

Swiss hosting with a GDPR adequacy decision in place

Acuna GRC is hosted in Switzerland, which holds a GDPR adequacy decision. Transfers to Supplier Shield are lawful under GDPR Article 45 without additional safeguards. For healthcare DPOs managing sensitive personal data, this is a simpler legal basis than standard contractual clauses and aligns with most national DPA expectations.

NIS2 + GDPR · one platform

Your NIS2 and GDPR vendor obligations, managed in one record

Most tools cover either security assessments or DPA tracking, but not both. Supplier Shield handles NIS2 Article 21 supply chain security assessments and GDPR Article 28 processing agreement governance in the same vendor record. One entry per supplier, no data duplication, no separate systems to reconcile.

No custom development · no infrastructure project

A structured vendor programme without a long implementation

Healthcare compliance teams cannot afford a 6-month implementation. No custom development, no infrastructure work, no professional services engagement to get started. Import your vendor list, configure supplier tiers by clinical and data risk, and send your first NIS2-aligned assessments. Your team runs the programme; the platform handles the process.

§ Regulatory obligations

NIS2 and GDPR obligations healthcare teams are accountable for

These are the specific articles that national supervisors, certification bodies, and external auditors will verify. Supplier Shield maps your vendor program to each one.

NIS2 Art. 21(2)(d)
Supply chain security

Essential entities must implement security measures addressing risks in the supply chain, including security-related aspects concerning the relationships between each entity and its direct suppliers and service providers.

NIS2 Art. 23
Incident reporting

Incidents caused by third-party suppliers must be reported to national CSIRTs within 24 hours of awareness. Supplier Shield tracks supplier-related incidents and maintains the evidence chain for notifications.

GDPR Art. 28
Processor contracts

All vendors processing personal data on your behalf must have a current DPA with mandatory clauses including sub-processor disclosure, data subject rights facilitation, and deletion obligations.

MDR / IVDR (where applicable)
Medical device software vendors

For healthcare entities using medical device software, supplier qualification requirements under MDR/IVDR may apply. Supplier Shield documents the applicable QMS and certification evidence per vendor.

§ Acuna GRC

GDPR, NIS2, and clinical compliance, all managed together

Supplier Shield is the TPRM module inside Acuna GRC. Your vendor assessments connect directly to your GDPR record of processing activities, NIS2 risk register, and internal audit workflows, all on one Swiss-hosted platform.

§ Platform capabilities

What Acuna GRC + Supplier Shield does for healthcare compliance teams

Supplier Shield is the TPRM module inside Acuna GRC. Here is what the full platform means in practice for a healthcare organisation managing both NIS2 and GDPR vendor obligations.

Data Protection module
GDPR Art. 28 · DPA register · sub-processors

The Acuna Data Protection module maintains your record of processing activities and tracks every data processing agreement, linked directly to the same vendor record used for NIS2 security assessments. When a medical imaging vendor changes their cloud sub-processor, both the security and the DPA record update in one place.

Multi-framework control mapping
NIS2 + GDPR + ISO 27001 in one control

A supplier security assessment satisfies NIS2 Art. 21, ISO 27001 A.15, and generates the evidence for your GDPR Art. 28 DPA review simultaneously. In Acuna, one control maps to all applicable frameworks, with no duplicate assessments and no inconsistent conclusions across your compliance programs.

OSINT automated risk scoring
A–F grades · live breach exposure

Your medical device vendors, EHR providers, and cloud suppliers are continuously scanned for breach exposure, DNS hygiene, TLS configuration, and threat intelligence signals. Composite A–F grades update automatically. You see a supplier's posture change the moment it does, without waiting for the next annual questionnaire.

Aiko: AI inside your GRC data
Natural language · instant answers

Ask Aiko: "Which of our vendors are processing patient data without a current DPA?" or "Show me all suppliers with a security grade below C that have access to our EHR." Answers from your live data in seconds. NIS2 supervisory preparation that used to take a day takes minutes.

Assessment Campaigns at scale
Guided wizard · automated reminders

Launch a full NIS2 supply chain security assessment across all your medical device vendors in one session. Select the template, choose the supplier group, personalise the outreach, and track completion from one dashboard. Automated reminders follow up without any manual chasing from your team.

Full platform overview: Acuna GRC cloud platform

§ FAQ

Common questions from healthcare compliance teams

We have not started our NIS2 vendor programme yet. Is it too late?

It is not too late, but the window is narrowing. Most national supervisors are now in active inspection mode, not a grace period. The good news is that Supplier Shield is designed to get you from zero to a structured programme quickly. Most healthcare teams complete their initial vendor register, send their first NIS2-aligned assessments, and have a defensible evidence base in place within 30 days.

Is our healthcare organisation an essential entity under NIS2?

Healthcare providers are explicitly listed as essential entities under NIS2 Annex I. This includes hospitals, private clinics, reference laboratories, medical device manufacturers where they also provide digital services, and pharmaceutical manufacturers. If you are unsure about your classification, our advisory team can assist.

What counts as a "supplier" for NIS2 supply chain security purposes?

Any organisation providing ICT services, software, or hardware that supports your healthcare operations: cloud providers, EHR vendors, PACS systems, diagnostic software suppliers, medical device integrators, IT managed service providers. NIS2 is broad. If a compromise of the supplier could affect your security posture, they are in scope.

How does Supplier Shield handle GDPR Article 28 DPAs?

The platform maintains a structured register of all your data processing agreements, vendor by vendor. Each entry tracks DPA version, review date, sub-processor disclosures, and compliance status. When a vendor notifies you of a sub-processor change, you log it, review the impact, and update the DPA record, all with an immutable audit trail.

Can Supplier Shield integrate with our existing ISMS or QMS?

Yes. Supplier Shield operates as the TPRM module within Acuna GRC, which supports integration with existing ISMS documentation (ISO 27001) and can align with QMS structures. Our advisory team handles implementation and scope mapping.

A defensible NIS2 vendor programme in 30 days.

Talk to our team about your current supplier base. We will map your NIS2 and GDPR obligations to Supplier Shield and show you which vendor categories need immediate attention before your next supervisory review.