What we can be precise about is the other half of the problem. A supply-chain security
requirement is answered with evidence about suppliers, and the evidence most programmes hold is
a questionnaire response and a contract clause. Both are attestations. Both were written by the
party being assessed, about a moment that has already passed, and neither one changes when the
supplier's estate does. An attestation carries a
signature and an observation cannot sign anything, so the form does not go away.
ShadowMap contributes the other kind of evidence: continuous outside-in monitoring of the
suppliers you nominate, using the identical methodology applied to your own external estate —
the same discovery, the same categories, the same arithmetic, the same bands. Nothing is
installed, no agent, no credentials, and no participation is required from the supplier. What
accrues is a dated record of what was reachable from the public internet on their estate, what
changed, when your team was told, and what they did about it. The strongest thing that record
carries is not a rating. It is that a control operated, on stated dates, over a stated scope,
with a result somebody can reproduce.
The limit is equally plain. Outside-in monitoring sees what is reachable from the public internet. It does not see inside a supplier:
not their segmentation, not their screening, not their backups, not the flow-down clauses in
their own supplier contracts. The section further down states that boundary as four explicit
kinds of statement. On scope:
NIS2's annexes name manufacturing sub-sectors directly, so this question reaches industrial
groups that had never previously thought of themselves as regulated
entities.