Compliance Cascade
Compliance Cascade
The mechanism by which a regulation applying to a single enterprise obligates every supplier in its supply chain, whether or not those suppliers are themselves in scope. The regulator writes the rule for the top-tier company; the top-tier company writes the same requirements into its procurement questionnaires and contract clauses; suppliers do the same to their suppliers; and the obligation propagates down to organizations several tiers removed from any regulator.
The 2026 anchor case is NIS2: an EU mid-size vendor not in NIS2 scope received a 40-question security assessment from its largest customer (in scope) with the terms of doing further business attached. That supplier must now extract pen-test summaries and ISO certs from ~20 small suppliers with no security function.
What the cascade actually asks
The reframing that landed as the top comment (↑141) in the r/sysadmin thread:
"So, they're not 'are your vendors certified compliant', they're 'how do YOU handle the responsibility for when they aren't?'" — u/Ssakaa
Corollary — the question no supplier could answer:
"Demonstrate the technical process you use to track zero-day vulnerabilities within their code or dependencies. When a critical flaw is announced in a component they use, what cryptographic or automated evidence do they provide to prove your specific deployment is secure or patched within 5 business days?"
The real, current answer — per the top comment — "is... you don't." Which is exactly what the cascade is designed to change; the transmission mechanism is producing capability that didn't exist before, however unevenly.
The operational playbook — tier before you ask
The highest-value practical comment in the corpus [↑42]:
*"Tier them before you send anything. Only the suppliers touching customer data or holding network access need the full 40 questions; the rest get five of them plus a contract clause. For the small ones with no security function, ask what they actually do instead of demanding evidence they cannot produce — a written answer with a breach-notification deadline attached is defensible, and losing a good supplier over a missing ISO cert is not. Monitoring 20 vendors with no tool is a spreadsheet with review dates and a calendar reminder. Your customer is really asking whether you have a process, so tell them the tiering is the process."* — u/AddendumWorking9756
Four tiers is the pragmatic shape practitioners describe:
| Tier | Access / data | Ask |
|---|---|---|
| 1 | Customer data + network access | Full assessment (SIG/CAIQ, evidence, cert copies) |
| 2 | Customer data OR network access | Short assessment + breach-notification clause |
| 3 | Neither, business-critical | Contract clause only |
| 4 | Small suppliers, no security function | Written attestation + breach-notification deadline |
The live disagreement — security or paperwork?
The corpus does not resolve this and neither does this page:
For (u/Steerable-Octopus [↑162], u/jimicus [↑43]):
"It sounds like the NIS2 directive is working exactly as intended." "It turns security best practices — which the organisations affected should have been doing anyway — into legal requirements."
Against (u/PersonalEconomist220 [↑58], pressed with case citations — In re Home Depot, Firemen's Retirement System v. Sorenson, Palkon v. Holmes, Construction Industry Laborers Pension Fund v. Bingle):
*"What it does is increase bureaucracy and sink endless money into useless paper trails produced by useless jobs instead of actually enforcing proper security. The only way you can make companies do actual things is to get them on the hook, no matter what paper trail they produce."*
The decisive rebuttal [↑45]:
*"How do you propose an accountability trail for this stuff if not by some kind of certification or request for documentation… exactly the thing you're filling out?"* — u/IwishIhadntKilledHim
And a practical note [↑7]:
"In reality, people will form LLCs, do the bare minimum, get compromised, move any assets to a new LLC, and start all over again." — u/MrD3a7h
Cross-links
- Security Obligation Propagates Via Revenue and Contract — this is the mechanism seen from the supplier seat. The whole synthesis links commerce to security-work propagation.
- Security Questionnaire Fatigue — what the receiving end (the top-tier vendor's SaaS suppliers) sees when the cascade lands on them at scale.
- Security Budget in Tiers — the CISO's response to the cascade internally: tier 1 in the budget is "what keeps you legal and contractually compliant" — this concept is what makes that tier real and non-optional.
Follow-ups
- Watch for the first regulator-published guidance clarifying which sub-tier questions are in scope vs. private-contract additions.
- Watch for cyber-insurance underwriters to price on tier-1-clear evidence rather than SIG/CAIQ-completed evidence.
- Watch for a US federal equivalent to NIS2 that triggers the same cascade on US suppliers.
- Watch for a documented case of a top-tier vendor losing a good supplier because the tiering wasn't in place — the failure-mode this concept was designed to prevent.