CloudSignLab

BlogNIS2 guides

Supplier security under NIS2: what your customers will ask you

NIS2 makes covered companies responsible for the security of their suppliers. Here is what that means for you as a supplier, which questions to expect, and how to answer them once instead of every time.

3 min readBy CloudSignLab

NIS2 does not stop at the companies it covers. It reaches their suppliers too. If you sell software, IT services, components or support to a company that falls under NIS2, you will be asked about your security, often in a long questionnaire and often with a deadline.

This article explains why, what customers typically ask, and how to prepare so that the next questionnaire takes an afternoon instead of two weeks.

Why your customers suddenly care

Article 21 of NIS2 lists the security measures every covered company has to take. One of them, in Article 21(2)(d), is supply chain security: the security of the relationships with direct suppliers and service providers.

Article 21(3) goes further. When covered companies choose and manage suppliers, they have to consider each supplier's specific vulnerabilities, the overall quality of its products and security practices, and its secure development procedures.

In practice this means: your customer has to be able to show an authority that it checked you. The easiest way for them is to ask you.

What customers typically ask

The wording differs from one questionnaire to the next, but the topics repeat:

  • Governance: Who is responsible for security? Do you have written policies, and are they approved and reviewed?
  • Access: Do you use multi-factor authentication? How do you give and remove access, and how often do you review it?
  • Protection: How do you handle updates, malware protection, encryption and secure configuration?
  • Backups and continuity: Do you back up data, have you tested a restore, and do you have a continuity plan?
  • Incidents: How do you detect incidents, and how quickly will you inform the customer?
  • Your own suppliers: Do you check the security of the providers you depend on?
  • People: Do your staff get security training?
  • Evidence: Can you share certificates, policies or reports?

Many customers also add contract clauses: incident notification within a fixed time, the right to audit, and security requirements for subcontractors.

Answer once, reuse many times

The same fifty questions come back in different words. The trick is to stop answering from scratch:

  1. Build an answer library. Write a good, honest answer to each common question once, with the evidence that supports it.
  2. Keep the evidence ready. Policies, backup test results, training records and certificates in one place, with dates.
  3. Publish what you can. A trust page with your security status and documents on request answers many questions before they are asked.
  4. Be honest about gaps. "Planned for Q1, owner named" is a better answer than a vague "yes". Customers check, and a credible plan builds trust.

How CloudSignLab helps

CloudSignLab was built for exactly this. The answer library keeps your approved answers in every language you need. Customer questionnaires can be imported from Excel, matched with your stored answers and written back into the customer's file. Your trust page shows your security status, certificates and policies, and shares documents on request. And the control library with supplier control set shows what customers usually expect from a supplier, so you can close the gaps first.

Start free

This article is a general introduction, not legal advice. Your customer's requirements and your contracts decide what you have to do.

Share this article