[Important Security Notice] Fake Qfinder Pro Websites Detected. Learn more >

Choose QNAP solutions to achieve EU NIS2 network security and supply chain risk management

Latest Articles 2026-09-21 clock 9 mins read

Choose QNAP solutions to achieve EU NIS2 network security and supply chain risk management

Choose QNAP solutions to achieve EU NIS2 network security and supply chain risk management

Key takeaway: QNAP is ISO/IEC 27001 certified, helping enterprises quickly pass NIS2 supply chain audits

NIS2 (Network and Information Security Directive 2, official name Directive (EU) 2022/2555) is a mandatory cybersecurity regulation issued by the EU for critical infrastructure and essential entities, aiming to comprehensively enhance corporate cybersecurity defense and digital resilience. Many companies, when evaluating NIS2, tend to overlook one thing: Article 21(2)(d) lists “supply chain security” as one of the ten risk management measures, explicitly requiring companies to assess “security risks related to direct suppliers and service providers.” Whether the storageunit manufacturer selected by the company itself has third-party certification qualifications is therefore already part of the audit scope.

QNAP can provide unit and software implementation among the ten measures in Article 21(2); at the same time, QNAP holds multiple third-party certifications (such as ISO/IEC 27001, 27017, 27018, Japan JC-STAR, etc.), meeting the requirements of enterprise audits for supply chain security under Article 21(2)(d). Other NIS2 requirements such as risk assessment, incident response planning, and executive management training are all part of internal corporate governance and legal affairs, which cannot be fulfilled by any product alone.

View all QNAP certifications >>

image

Read more: European Commission — NIS2 Directive official page

Implementation status: Germany, the Netherlands, and France have already started implementation. Enterprises should seize the time to prepare.

NIS2 came into effect in 2023, and October 17, 2024 is the deadline for all member states to transpose the directive into national law. As of April 2026, 22 out of 27 member states have completed the transposition, and Germany, the Netherlands, and France have already launched practical implementation actions. NIS2 has moved from the 'still time to prepare' phase to the 'audits and penalties are happening' stage. The scope of application is estimated to cover more than 100,000 enterprises across the EU, divided into 'essential entities' (energy, transport, finance, healthcare, water, digital infrastructure) and newly included 'important entities' (manufacturing, postal and courier services, digital service providers, etc.).

The upper limit of penalties for violations depends on the type of entity: for essential entities, the maximum is 100 million euros or 2% of global turnover; for important entities, the maximum is 70 million euros or 1.4% of turnover, whichever is higher. Furthermore, Article 20's personal liability provision means this is no longer just a financial risk—regulators can hold individual management members accountable for serious misconduct, including temporarily banning them from performing management duties. Therefore, QNAP recommends that enterprises do not wait until an audit is imminent to scramble for remediation, but instead proactively prepare technical safeguards and evidence-ready records in advance. This is not only a compliant and robust practice, but also enables enterprises to provide reassuring proof to customers and business partners at any time.

NIS2 Article 21(2) Risk Management Measures and QNAP Solution Comparison Table

Article 21(2) Measures QNAP
(d) Supply chain security organizations and supplier evaluation QNAP itself holds third-party certifications such as ISO/IEC 27001, 27017, 27018, and Japan JC-STAR Level 1 Enterprise evaluation When QNAP acts as a supplier, it has concrete third-party certifications that can serve as audit evidence for Article 21(2)(d)
(b) Event handling technicality ADRA NDR X (detecting lateral movement, automatic isolation of infected devices), Security Center and Malware Remover attacks are detected and blocked before spreading, reducing the scope of event impact
(c) Business continuity and risk management technical aspects HDP for Business (3-2-1-1-0 principle, Immutable Backup, Airgap+ isolation node), Video Verification for recovery boot video verification; HBS 3 offsite/cloud backup; dual controller HA, High Availability Manager “Backup verification” with video and drill records to prove the backup is complete and restorable; no service interruption during single point of failure
(e) System acquisition, development, and maintenance security (including vulnerability handling) technical aspects Security Advisory subscription, Live Update Known vulnerabilities have subscription notifications and update mechanisms for tracking
(h) Cryptography and encryption policy technology SED self-encryptionhard disk drives (TCG-OPAL, TCG-Enterprise), AES-256 encryption When a hard drive is lost, stolen, or replaced and leaked externally, static data remains in an unidentifiable state
(i) Human resource security, access control, and asset management technology RBAC role permissions, AD/LDAP integration, Delegated Administration Access permissions correspond to real identity, and permissions are synchronized and invalidated after resignation or transfer
(j) Multi-factor authentication and secure communication technology QNAP Authenticator Multi-factor authentication (MFA); QVPN Service (WireGuard, OpenVPN and other encrypted tunnels) Login and remote access are both protected by dual authentication and encrypted tunnels

Supply Chain Security: Third-party certifications are evidence that can be directly referenced during enterprise audits

Among the ten risk management measures, Article 21(2)(d) Supply Chain Security is the only measure that enterprises cannot complete solely through their own efforts. The regulation clearly requires enterprises to assess the “security risks related to direct suppliers and service providers.” Therefore, the scope of audits is no longer limited to the enterprise’s own systems, but also extends to the information security capabilities and sufficiency of supporting evidence from upstream suppliers.

QNAP's own third-party certifications have become even more significant under NIS2: ISO/IEC 27001 (Information Security Management System), ISO/IEC 27017 (Cloud Service Security Controls), ISO/IEC 27018 (Cloud Privacy Protection), as well as the JC-STAR Level 1 (IoT Product Security Mark) obtained in July 2026 in Japan. All of these can be directly referenced and included as third-party evidence in supplier risk assessments under Article 21(2)(d). If a supplier cannot provide the required third-party certifications, the enterprise will bear sole responsibility for this audit gap.

Event handling and 24-hour alert: The timer starts counting down from the moment it is detected, not after it is restored.

The reporting deadlines under Article 23 are even more urgent than those of the GDPR or HIPAA, and are divided into three stages: a “preliminary warning” must be submitted within 24 hours of becoming aware of a major incident; a formal “incident notification” (including an initial impact assessment and severity rating) must be submitted within 72 hours; and a final report must be submitted within one month. The biggest difference from the previous two regulations is that the clock starts ticking from the moment of “awareness” (not from “recovery completion” or “decision to report”). In other words, passing the NIS2 test is not about how fast you can recover from a backup, but how quickly you can grasp the situation, clarify the facts, and provide an initial explanation.

Traditional antivirus and perimeter firewalls cannot stop attackers who have already infiltrated the internal network and are moving laterally. QNAP ADRA NDR X (Network Detection and Response) uses existing NAS and compatible switches to monitor internal network traffic, detect lateral movement, and automatically isolate infected devices during medium to high-risk situations, stopping attackers before they spread; once containment is successful, it can work with NAS snapshots to restore affected systems restore to their pre-infection state. NAS on the device also provides Security Center baseline checks, firewall (QuFirewall), and Malware Remover scans. When managing multiple unit devices, QuLog Center centrally aggregates logs and supports tagging and advanced search—when the 24-hour clock starts counting down, these detections and log records provide the first early warning report with concrete facts, not just blind guesses. When the 24-hour clock starts counting down, these detections and log records provide the first early warning report with concrete facts, not just blind guesses.

Business continuity and risk management: Backup and fault tolerance are both essential

Article 21(2)(c) lists “business continuity and risk management” as one of the measures, with clear content including backup management and disaster recovery. QNAP supports this from two levels: server and VM workloads are centrally protected by HDP for Business for Windows®, VMware®, Hyper-V®, Proxmox® VE, and Microsoft 365®, designed according to the 3-2-1-1-0 backup principle, combined with Immutable Backup and Airgap+ physical isolation backup nodes; Video Verification automatically records the boot process of backed-up VMs as integrity evidence. Files data on NAS are backed up offsite/cloud via HBS 3, with version management and data integrity checks.

"Business Continuity" and "Disaster Recovery" are two different issues. Recovery means "getting it back" after the original data is damaged, while high availability is about solving single-point failures so that "services are not interrupted" at the moment. QNAP offers three types of high availability architectures for different scales:

Encryption, multi-factor authentication, and access control

Article 21(2)(h) requires cryptography and encryption policies. QNAP provides AES-256 encryption for shared data folder / LUN, and supports self-encrypting hard disk drives (SED), covering TCG-OPAL and TCG-Enterprise, with encryption and decryption handled directly by the hard disk drives controller. Article 21(2)(j) requires multi-factor authentication and secure communication. QNAP Authenticator provides multi-factor authentication (MFA), and QVPN Service (WireGuard, OpenVPN, etc.) establishes encrypted channels for remote storage access. Article 21(2)(i) covers human resource security and access control, which is implemented by RBAC role-based permissions integrated with AD, Azure AD, or LDAP. Permission changes are centrally managed within the existing domain account system, and access rights are synchronized and revoked upon resignation or changes.

Next step: Implement NIS2 compliance, check whether your own technical requirements and suppliers are certified

Internal policy governance (such as risk assessment processes, incident response drills, and management-level information security training) requires proactive promotion by enterprises. However, when it comes to on-site audits for infrastructure and supply chain security (Article 21(2)(d)), choosing the right partners can make compliance efforts much more effective. Selecting QNAP storage and backup solutions with ISO/IEC 27001 international certification and CNA (CVE Numbering Authority) credentials can help enterprises directly meet the EU NIS2 Directive Article 21(2)(d) mandatory audit requirements for “supply chain security.”

If you are evaluating storageunit options that comply with NIS2 regulations, offsite backup plans, or Proxmox VE backup architectures, please consult with QNAP sales or technical support to plan the most suitable product combination according to your actual needs.

AI Disclosure: Some images and text in this article were created or refined with the assistance of Artificial Intelligence (AI) and reviewed by human editors.

Sunnine

Sunnine

QNAP Makreting Memeber

Was this article helpful?

Thank you for your feedback.

For further assistance, ask other users and QNAP experts in the community. Go to QNAP Community

Please tell us how this article can be improved:

If you want to provide additional feedback, please include it below.

Table of Contents

Choose specification

      Show more Less
      Choose Your Country or Region
      open menu
      back to top