The NIS 2 Implementation Act (NIS2UmsuCG) requires companies with important and essential entities to implement various cybersecurity risk-management measures. This includes securing the supply chain, i.e. the proper obligation of service providers and suppliers to ensure IT security that pays into the client's statutory IT security. The presentation shows which requirements there are and how they are to be prioritized and implemented.