EUComply

NIS2 / DORA Vendor Clause Set

Answer regulated clients' vendor-chain questionnaires before they ask.

$49 one-time · Markdown + PDF

Pro launches when checkout is live; the free scanner is complete.

What's inside

  • Service description & scope lock — a fixed reference against scope creep (NIS2 supply-chain security)
  • Security measures clause (TOMs) — least-privilege access, AES-256 credential storage, MFA, vulnerability scanning
  • Audit / evidence right — satisfies NIS2 Art. 21(2) and DORA Art. 30(1) audit obligations
  • 24-hour incident notification — the Client's regulatory reporting clock starts with your clause, not your apology
  • Subcontractor governance — equivalent-obligations flow-down plus 30-day change notice
  • Purpose notes on every clause — why it exists and when the client will invoke it

Paste into any supplier contract or sign standalone. Delivered as Markdown + PDF.

Note: Professional template with guidance comments — not legal advice.

Free preview — two full clauses

# NIS2 / DORA VENDOR CLAUSE SET **ComplianceDocs** · v1.0 · Not legal advice — have counsel review before use. Regulated clients treat the company that runs their website as part of their supply chain. Under **NIS2**, essential and important entities must manage supply-chain security; under **DORA Art. 28–30**, financial entities must contractually govern ICT third-party providers. ### 1.3 Audit / evidence right > The Client may request, at reasonable notice (not less than 10 business > days), documentation of performed work including Change Log extracts, > backup test records, and access reviews. The Vendor shall provide such > documentation within 5 business days of the request. **Purpose:** NIS2 Art. 21(2) and DORA Art. 30(1) both require the ability to audit third-party providers. This clause satisfies that contractual obligation. ### 1.4 Incident notification > The Vendor shall notify the Client of any Security Incident affecting a > Site within 24 hours of confirmation … The notification shall include: > time of detection, nature and scope of the incident, affected systems, > measures taken, and an estimated timeline for resolution. ── Clauses continue in the full set ── Service description · TOMs register · Subcontracting · Liability · Annexes A–B

You've read two of the five core clauses. The full set adds TOMs language, subcontractor flow-down and annex structure.

Buy with confidence

14-day money-back guarantee. If the document doesn't fit your workflow, reply to your receipt within 14 days and you get a full refund. No forms, no questions.

How do I receive the document?
Instantly after checkout — download link on screen and by email.
Who handles the payment?
Lemon Squeezy acts as merchant of record and handles cards, PayPal, Apple Pay, VAT and sales tax worldwide.
What's the license?
Use the documents for yourself and for your own clients, as many times as you like. Reselling or republishing the template itself isn't allowed.
Is this legal advice?
No. These are professionally structured templates to adapt to your situation. For specific advice, consult a lawyer.