NIS2 evidence with Preloop
Supply-chain and vulnerability-handling evidence for agent runtimes
The instrument is Directive (EU) 2022/2555 (NIS2). National transposition is ongoing. The cybersecurity risk-management measures sit in NIS2 Art. 21(2), including supply-chain security and security in acquiring, developing, and maintaining networks and information systems, with vulnerability handling and disclosure.
Preloop does not decide whether you are an essential or important entity. It does not replace a NIS2 programme or an incident-notification process.
Not legal advice
Preloop is not a law firm. Nothing on this site is legal advice. Every regulation reference names the instrument and the article or date so you can check it against EUR-Lex yourself.
Where NIS2 Art. 21(2) talks about supply chain
The following is what the text says, not a claim that Preloop satisfies it.
- Supply-chain security (NIS2 Art. 21(2)). Essential and important entities must manage supply-chain security, including the security of relationships with suppliers and service providers. If AI agents pull packages, call MCP servers, or deploy from CI, those paths are part of how software enters production. Preloop can require approval on those tool calls and keep a trail.
- Vulnerability handling. The CRA exploit-check preset (
preloop.cra.vulnscan/v1) maps an SBOM you already have to OSV.dev and CISA KEV. That can feed a vulnerability-handling process. It is not disclosure, and it is not a complete vulnerability management system.
What Preloop can collect
- Runtime session logs: tool, arguments (as retained), matched policy, decision, approver, outcome.
- Flow evidence packs when you run the Apache security-audit presets against a release SBOM.
- Human oversight on high-impact agent actions (deploy, production data, billing).
That is operational evidence for teams who already have a NIS2 workstream. It is not a transposition opinion, and it is not a certification.
Related EU pages
- EU AI Act (Reg. (EU) 2024/1689)
- Cyber Resilience Act (Reg. (EU) 2024/2847)
- DORA (Reg. (EU) 2022/2554)