Skip to main content
Shaping Europe’s digital future
  • REPORT / STUDY
  • Publication 13 February 2026

Toolbox to improve ICT supply chain security

The NIS Cooperation Group composed of EU Member States representatives, the European Commission and the EU Agency for cybersecurity (ENISA), has adopted an EU ICT Supply Chain Security Toolbox.

Illustration for the reports cover, with the mention of the NIS2 Cooperation Group.

This toolbox provides a common approach on how to identify, assess and mitigate cybersecurity risks of ICT supply chains. It also outlines risk scenarios and recommends mitigation measures, including overcoming the dependencies on high-risk suppliers.  

The toolbox will help Member States and public and private actors to bolster the security of ICT supply chains in the EU as set out in the revised Cybersecurity Act presented on 20 January 2026. 

This toolbox is accompanied by two risks assessments on connected and automated vehicles and detection equipment. These two reports provide a comprehensive overview of the cybersecurity risks identified, their potential consequences, and the mitigating measures considered necessary to address them. 

You can download the toolbox and the risks assessments below.

Downloads

1. EU ICT Supply Chain Security Toolbox
Download 
2. Risk assessment - Connected and automated vehicles (CAV)
Download 
3. Risk assessment - Detection equipment
Download