DORA, NIS2, GLBA, HIPAA: The Regulatory Case for Vendor Risk Assessments
Third-party oversight is now a legal requirement across finance, healthcare, and critical infrastructure. What each regime actually expects from your vendor risk program. For years, third party risk management was a best practice. Increasingly, it is the law. Regulators on both sides of the Atlantic have concluded that an organization's security is only as strong as its supply chain — and they now expect documented, ongoing vendor oversight, not a one time checkbox. DORA: resilience with teeth The EU's Digital Operational Resilience Act, applicable since January 2025, is the most prescriptive third party regime yet for financial entities. It requires a register of information covering all ICT service providers, contractual provisions for audit and access rights, documented exit strategies for critical providers, and board level accountability for ICT risk. If your vendor inventory lives in a spreadsheet, DORA is the regulation that ends that era. NIS2: supply chain security goes mainstream The NIS2 Directive extends cybersecurity obligations far beyond banks — energy, transport, health, digital infrastructure, manufacturing, and more. Article 21 explicitly names supply chain security, including "security related aspects concerning the relationships between each entity and its direct suppliers." Translation: regulators expect you to assess your vendo