
It’s 2026. The time for “preparation” is long gone, and the transition periods for EU directives are now history. Non-compliance penalties have stopped being just a theoretical scare tactic on a presentation slide — they have become a real threat to company budgets and reputations.
Yet many CEOs and IT directors live under a dangerous illusion: “We keep our data in the cloud, so our provider surely has it covered.”
Unfortunately, regulators verify this ruthlessly. Under EU law, your company’s security ends where the weakest link in your supply chain begins. If your hosting provider, SaaS vendor, or outsourced IT administrator drops the ball, you bear the liability (and pay the fine).
So how do you stop taking things on faith and start effectively vetting your technology partner? Here’s a proven guide.
Why vetting your IT provider is your responsibility (not an option)
Both the NIS2 directive (covering broad cybersecurity and key economic sectors) and the DORA regulation (focused on digital operational resilience in the financial sector) place enormous emphasis on supply chain security.
You might have flawless procedures in place internally, but if the hosting company running your store or CRM does not meet the standards, your compliance is a fiction. Whether you still need to check whether your company falls under NIS2, or you have long known your legal status, you are responsible for who you entrust with your data and critical processes.
5 key areas for evaluating an IT and hosting services provider
It is best to treat the evaluation of a technology partner like a mini-audit. What exactly should you require of them?
1. Incident management and strict SLAs
NIS2 is unforgiving on timing: you have 24 hours for an early warning and 72 hours for a full incident report.
- What to ask your provider: Does their SLA (Service Level Agreement) guarantee you notification of an incident in their infrastructure fast enough for you to meet your own legal obligation? If a provider informs customers of a breach a week later, you are automatically breaking the law.
2. Operational resilience (business continuity and disaster recovery)
Regulations do not require systems to never go down (that is technically impossible), but they do require you to get back on your feet quickly and smoothly.
- What to ask your provider: How often are recovery plans tested? Where are backups physically stored (the 3-2-1 rule)? Financial institutions in particular need to be extremely rigorous about DORA requirements for ICT providers, where resilience testing is the foundation.
3. Transparency and auditability (right to audit)
You cannot rely solely on nice assurances on a provider’s website.
- What to ask your provider: Does the contract include a “right to audit” clause? A serious provider will let you (or a third-party firm you hire) verify their safeguards. This is often done by sharing the latest results of independent penetration tests or certifications (e.g., ISO 27001, SOC 2 Type II).
4. Your provider’s subcontractors
The supply chain has many links. Your IT services provider probably also relies on someone else’s servers, external databases, or subcontractors (freelancers) to handle support tickets.
- What to ask your provider: Who has access to your data? Does the provider apply the same strict rules to its own subcontractors? If so, ask for evidence. Proper NIS2 implementation in the data center and at the hosting provider must be a process covering the entire data lifecycle.
5. Identity management and Zero Trust architecture
High-privilege accounts (i.e., administrative accounts) at your provider are potentially the fastest route for cybercriminals to take over your infrastructure.
- What to ask your provider: Does the provider enforce hardware U2F security keys (MFA) for its administrators? Are access logs retained and monitored on a 24/7 basis (e.g., through a SOC service)?
Not sure where to start? Run a gap analysis
Keep in mind that, depending on your company’s classification, the regulator will approach you with a different level of scrutiny. The distinction between how an essential entity is treated versus an important entity under NIS2 affects whether you face a preventive (ex-ante) audit or only a review after an incident (ex-post). Regardless of your status, the responsibility for vetting your vendors is the same.
If you want to vet your IT partners, the best place to start is a comprehensive review. A professional NIS2 audit or a dedicated DORA audit are tools that not only expose flaws, but above all give you a roadmap for fixing them.
Who’s going to verify all of this? The role of the vCISO
Vetting SLAs, cloud architecture, and vendor penetration test reports requires deep technical and legal expertise. Hiring a full-time, experienced Chief Information Security Officer (CISO) today is a massive cost and a months-long recruitment process.
That is why, in 2026, relying on an outside expert has become standard practice — vCISO support (Virtual Chief Information Security Officer) gives you access to C-level competence for a fraction of a full-time salary. A vCISO will take on the tough negotiations with IT vendors, analyze their infrastructure, and assure the board that the company operates within the letter of the law.
Summary: a vendor audit is an investment, not a cost
2026 no longer forgives technical debt in compliance. Your customers expect security, and regulators expect hard evidence. Vetting your hosting and IT services providers is the foundation without which no internal security system has any real purpose.
We understand that navigating between IT requirements and legal jargon can be frustrating and stressful. The truth is, though, you do not have to (and should not) do it alone.
Would you like us to schedule you a free, no-obligation consultation, during which our engineers and auditors will check whether your IT vendors pose a risk to your business? If so, get in touch with us!
