Duty of care
A key element of the legislation is the duty of care for 'appropriate and proportionate technical, operational and organizational measures'. In addition to your own measures, you must also ensure that the cybersecurity of your direct suppliers is taken care of.