The question at hand
NIS2 compliance teams face a resource allocation problem. Article 21 lists ten security requirements, from supply chain due diligence to incident response protocols. All carry the same legal weight. Essential entities face fines up to €10 million or 2% of global turnover for non-compliance; important entities face up to €7 million or 1.4%. Management bodies face personal liability, including temporary bans from executive roles.
You can't implement everything simultaneously. The practical question: where do you start?
One camp argues for tackling supply chain risk management first. It's Article 21(2)(d), it's board-visible, and it addresses third-party exposure. The other camp pushes credential and access management as the faster path to demonstrable compliance. The implementation timelines differ dramatically: supply chain risk programs take 6-12 months to operationalize, while access control enforcement can be operational in 2-4 weeks.
Both positions have merit. Both have real costs if you choose wrong.
The case for supply chain first
Supply chain risk management addresses systemic exposure. Your vendors, contractors, and service providers touch your network and information systems. A breach at a third party becomes your breach under NIS2's accountability framework. Article 21(2)(d) requires documented security requirements in supplier contracts, ongoing monitoring, and evidence of due diligence.
This work takes time because it requires cross-functional coordination. Legal needs to revise contract templates. Procurement needs new vendor assessment workflows. IT needs visibility into which suppliers have what access. Building that infrastructure can't be rushed, so starting early makes sense.
The board understands supply chain risk. They've read the headlines about third-party breaches. When you brief them on NIS2 compliance status, supply chain risk management is a program they can conceptualize and fund. It fits the narrative of modern enterprise risk management.
From an audit perspective, supply chain controls demonstrate strategic thinking. You're not just securing your own perimeter; you're managing ecosystem risk. That resonates with competent authorities evaluating whether your organization takes security seriously at a governance level.
The case for IAM first
Credential abuse appears in 39% of all breaches across the full attack chain, according to the Verizon Data Breach Investigations Report. Credentials aren't just an initial access vector; they're how attackers move laterally after they're inside. Article 21(2)(i) requires access control policies covering all accounts with access to network and information systems. "All accounts" includes service accounts, API keys, and non-human identities that most organizations can't currently enumerate.
The implementation timeline is the strongest argument. A competent team can enforce fine-grained password policies across Active Directory, migrate shared credentials into a managed vault, and enable phishing-resistant MFA for privileged accounts in 2-4 weeks. That's not a multi-quarter program; it's a sprint.
IAM work generates immediate auditable evidence. Article 32 gives competent authorities the right to request documentation of implemented security measures. When you deploy a centralized credential vault with RBAC, AD/LDAP integration, and audit logging, you create exportable evidence automatically. Every access review, every credential rotation, every MFA enrollment produces a timestamped record. That evidence artifact is what auditors need to verify compliance.
The operational benefit compounds. Once you have credential visibility, you can identify dormant accounts, over-privileged roles, and unmanaged service accounts. These are direct audit failure points. A typical mid-size organization has more service accounts than human accounts, and most have never been rotated or assigned a documented owner. Fixing this closes the credential chokepoint faster than any other single control.
Where practitioners actually land
Most compliance teams don't choose one or the other. They run both workstreams in parallel but sequence the milestones differently.
The pattern that works: start IAM implementation immediately while supply chain risk management goes through its design phase. By the time you've drafted new supplier contract language and built your vendor assessment framework, you've already closed the credential gaps and generated your first compliance evidence package.
This sequencing solves the morale problem. Compliance teams burn out when they spend months on policy work with nothing to show. IAM gives you visible progress in weeks. You can walk into a status meeting and demonstrate that privileged access is now under MFA, service accounts are inventoried and rotated, and the audit log is running. That momentum matters when you're asking the same team to tackle a 12-month supply chain program.
Practitioners also recognize that IAM controls support supply chain security. When you enforce access control policies internally, you can extend those requirements to vendor access. The credential vault that manages your service accounts can also manage third-party API keys. The MFA policy you enforce for employees becomes the baseline for contractor access. IAM isn't separate from supply chain risk; it's the technical foundation.
Our take
Fix IAM first, but don't stop there.
The argument for starting with credential and access management isn't that supply chain risk doesn't matter. It's that you need early wins to sustain a multi-year compliance program, and IAM delivers those wins faster than any other Article 21 requirement.
The practical path: deploy a centralized credential vault within 30 days. Get service accounts under management, close the dormant account backlog, and enforce phishing-resistant MFA on privileged and remote access. Configure audit logging and export your first compliance report. That's your baseline evidence artifact.
Use that momentum to fund the longer work. Supply chain risk management, incident response protocols, and board-level governance reporting all need to happen. But when you walk into those planning meetings with documented IAM controls already operational, you're negotiating from a position of demonstrated capability, not theoretical commitment.
The organizations that will fail NIS2 audits aren't the ones with imperfect security. They're the ones with no evidence. Start where you can generate evidence fastest, then build outward.



