Many companies first meet NIS2 not through a regulator but through a customer: a security questionnaire in a tender, a new clause in a framework agreement, a request for "your NIS2 policies". This happens even to companies that are far too small, or in the wrong sector, to be covered by Directive (EU) 2022/2555 themselves. The reason is the supply chain duty in Article 21. This guide explains the rule, why it travels down the chain, what customers typically ask for, and how a supplier can prepare.
The guide is general information, not legal advice.
The rule: Article 21(2)(d) and (3)
Every essential and important entity must take cybersecurity risk-management measures that include, at a minimum, "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers" (Article 21(2)(d)).
Article 21(3) says how: when deciding which supply chain measures are appropriate, the entity must take into account
- the vulnerabilities specific to each direct supplier and service provider;
- the overall quality of products and cybersecurity practices of its suppliers and service providers, including their secure development procedures; and
- the results of the coordinated security risk assessments of critical supply chains carried out at EU level under Article 22(1).
Two further rules push in the same direction. Article 21(2)(e) requires security in the acquisition, development and maintenance of network and information systems — which covers what the entity buys. And Article 20 makes the management body responsible for approving and overseeing all of these measures, so the board of the customer is personally interested in its suppliers' answers.
Why the duty travels down the chain
A covered entity cannot secure its suppliers by internal policy alone. It has only one instrument: the contract. So it assesses suppliers before contracting, writes security requirements into the agreement, and asks for evidence during the relationship. From the supplier's point of view, the result is a commercial requirement rather than a legal one — but a hard one: a supplier that cannot answer may be scored down in a tender or replaced at renewal. In practice, large customers push compliance evidence down to their suppliers, and those suppliers increasingly pass the same questions on to their own subcontractors.
Suppliers that provide ICT services are most exposed: software vendors, hosting and cloud providers, IT maintenance companies, managed service providers (who are often in scope themselves), and any supplier with remote access to the customer's systems. But logistics companies, component manufacturers, cleaning and facility companies with access to premises, and consultants handling customer data receive such questions as well.
What customers typically ask for
- A security questionnaire mapped to the ten areas of Article 21(2): policies, incident handling, backups and continuity, access control, multi-factor authentication, encryption, vulnerability handling, staff training.
- Documented policies — an information security or cybersecurity risk management policy, an incident response plan, a business continuity plan and a supplier security policy of the supplier's own.
- Contract clauses — minimum security measures, notification of security incidents within a short deadline (so that the customer can meet its own 24-hour early warning under Article 23), cooperation in incident handling, audit and information rights, subcontracting restrictions, and termination rights.
- Technical evidence — results of an external check of the supplier's public infrastructure (domain, e-mail authentication, TLS, open ports), penetration test summaries, or certifications where the supplier holds them.
- Periodic re-confirmation — the customer's own effectiveness assessment under Article 21(2)(f) often turns into an annual re-questionnaire of key suppliers.
How a supplier can prepare
- Check your own status first. If your company is itself in scope — see Who does NIS2 apply to? — the full obligations apply, not only the customer's questions.
- Prepare one set of answers. A written policy set and a short evidence file answer most questionnaires and save repeating the work for each customer.
- Read the clauses before signing. An incident notification deadline, unlimited audit rights or an uncapped indemnity are negotiable; accept only what the company can actually deliver.
- Keep it current. Evidence that describes last year's systems does not help in this year's tender.
- Apply the same logic downstream. Your own subcontractors with access to customer systems will be part of your answer.
Documentation for suppliers on nis2europe.eu
nis2europe.eu, operated by AIPOS OÜ, offers a Supply Chain Security Attestation intended for a supplier that is not itself subject to NIS2 but whose NIS2-regulated customer asks for evidence of supply chain security measures. According to nis2europe.eu, it combines a baseline technical check of the supplier's public infrastructure, a map of the supplier's position against the customer's Article 21(2)(d) requirements, and an attestation document the supplier can hand to the customer. At the time of writing, nis2europe.eu listed it at 299 EUR net; the current price is on nis2europe.eu/pricing. Suppliers that are themselves in scope will usually need the full documentation package instead.
An attestation is evidence for the customer's assessment. It does not bind the customer, which decides for itself whether the supplier's measures are sufficient, and it is not a certification by any authority. The overview of the whole directive is on the page NIS2 compliance documentation; the country pages of nis2europe.eu start at nis2europe.eu.
Ready to start? See the supply chain rules and the documentation available on nis2europe.eu. NIS2 compliance documentation.
Frequently asked questions
Does NIS2 apply to suppliers?
Not directly, unless the supplier is itself in scope. But its NIS2-regulated customers must address the security of their direct suppliers and service providers (Article 21(2)(d)), so they impose requirements on the supplier by contract.
What do customers usually ask suppliers for?
Security questionnaires, evidence of policies and technical controls, incident notification clauses, audit rights and sometimes certifications. Article 21(3) tells the customer to assess each supplier's vulnerabilities, product quality and secure development practices.
Is there NIS2 evidence designed for suppliers?
nis2europe.eu offers a Supply Chain Security Attestation for suppliers that are not themselves subject to NIS2 but are asked for evidence by an NIS2-regulated customer. It is sold by AIPOS OÜ; the current price is on nis2europe.eu.
Related guides
- What is NIS2? The EU cybersecurity directive explained
- Who does NIS2 apply to?
- What happens without NIS2 compliance
More on this topic: NIS2 compliance documentation.