Suppliers and supply chain security

What does NIS2 mean for suppliers and the supply chain?

Even outside the direct statutory scope, you may face NIS2 requirements through your customers.

Read how NIS2 affects suppliers, which questions customers may ask and how to manage supply chain risks with evidence.

Why customers request more information

A customer must understand the dependencies of a critical service and what happens during a disruption or security incident. Suppliers are therefore classified, with more attention given to critical suppliers.

A generic questionnaire is not enough. The level of detail should reflect access, data, substitutability, continuity and the potential impact of incidents.

  • security policies and responsibilities
  • access management and technical security
  • incident reporting and cooperation
  • continuity, recovery and exit arrangements
  • sub-suppliers and processing locations
  • assurance, audits and periodic reassessment

What can you prepare as a supplier?

Create a reusable information pack containing current, verifiable information. Ensure commercial answers reflect actual operations; do not promise controls that do not exist.

Set appropriate requirements rather than passing everything down

The aim is not to impose exactly the same requirements on every supplier. A supplier with administrative access to a core system needs a different assessment from one providing public information.

Record the risk category and reasoning. This makes discussions between procurement, security and the supplier more concrete.

Keep monitoring the supply chain

An assessment at the start of a contract is not enough. Plan reassessment according to risk and record relevant changes. Combine contract management, security monitoring and continuity planning so that warning signs do not remain isolated within separate teams.

Frequently asked questions

Does NIS2 apply to every supplier?+

No. Direct applicability depends on the supplier’s own services, sector, size and any exceptions. Customers may also agree appropriate supply chain requirements in contracts.

Can a customer request an ISO 27001 certificate?+

A certificate may be a contractual requirement; NIS2 does not require every supplier to obtain ISO 27001 certification. Check the relevance and scope of the requested evidence. A certificate does not replace assessment of the specific service and its risks.

How often should you assess suppliers?+

Base the frequency on risk, changes and incidents; critical suppliers generally require more frequent attention.

Sources and further reading

We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.

Related articles

NIS2 and the Dutch Cybersecurity ActDoes the Dutch Cybersecurity Act apply to my organisation?Read article →NIS2 and the Dutch Cybersecurity ActNIS2 controls: what do you need to put in place?Read article →ISO 27001What is ISO 27001 and what does it mean for your organisation?Read article →

This is general guidance and does not replace a legal assessment or the official standard.