NIS2 supply chain security: what customers ask their IT suppliers and the evidence that answers it
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- NIS2’s risk-management measures apply to essential and important entities, and Article 21(2)(d) makes supply chain security one of them, so a supplier outside the directive’s scope meets NIS2 as questionnaires, contract clauses and requests for evidence from in-scope customers
- Article 21(3) has customers take into account the vulnerabilities specific to each direct supplier, the overall quality of their suppliers’ products and cybersecurity practices, including secure development procedures, and the results of coordinated risk assessments of critical supply chains under Article 22(1)
- Point 5.1.4 of the Annex to Implementing Regulation (EU) 2024/2690 lists, where appropriate, contract clauses on security requirements, staff skills and background checks, incident notification without undue delay, audit rights, vulnerability handling, subcontracting and exit; it binds the digital infrastructure, ICT service and digital providers listed in its Article 1
- Supplier questionnaires ask about MFA, privileged accounts, access to the customer’s systems, backups and restore tests, incident notification time, patching, subcontractors and certificates, and each answer should point to a dated document such as a configuration export or a test report
- The directive covers entity types listed in its Annexes I and II from medium-sized enterprises upwards under Recommendation 2003/361/EC, plus some types and cases regardless of size; managed service providers, defined in Article 6(39), are among the listed types
Eurokommerz × Vixen.UNO: Cyber Resilience Talk to an expert →
How NIS2 supply chain security reaches IT suppliers outside its scope
Article 21 of NIS2 requires Member States to ensure that essential and important entities take security measures. Point (d) of the article’s paragraph 2 lists among the minimum measures “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. A supplier outside the directive’s scope therefore meets NIS2 through its customers’ third-party risk management. That risk management reaches the supplier as a security questionnaire, a security annex to the contract or a request for evidence such as a restore test report. Under Article 21(3), those customers take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures”. Our guide to NIS2 Article 21 security measures covers all ten measures.
Commission Implementing Regulation (EU) 2024/2690 details this in point 5 of its Annex: a supply chain security policy with selection criteria and contract clauses (point 5.1) and a directory of suppliers (point 5.2). The regulation binds the entities listed in its Article 1, among them cloud computing, data centre and managed service providers. ENISA wrote its technical implementation guidance of June 2025 for those entities. ENISA adds that, beyond them, its indications “may be considered useful by other public or private bodies for improving their cybersecurity”.
Which companies NIS2 covers: sectors and the medium-sized threshold
Article 2(1) applies the directive to entities of a type listed in its Annex I or II. Such an entity must qualify as a medium-sized enterprise under Commission Recommendation 2003/361/EC or exceed the ceilings for medium-sized enterprises. It must also provide services or carry out activities in the Union. The recommendation defines a small enterprise as one that “employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million”. Staff are counted in annual work units. A listed entity that is not small therefore meets the size test. The recommendation’s ceilings for medium-sized enterprises are fewer than 250 persons and an annual turnover not exceeding EUR 50 million and/or an annual balance sheet total not exceeding EUR 43 million. Under Article 6 of the recommendation’s Annex, the data of partner and linked enterprises are added, so a subsidiary is not measured on its own figures alone. Recital 16 of the directive lets Member States take into account an entity’s independence from its partner or linked enterprises, for example in its network and information systems. Article 2(2) to (4) of the directive cover some types and cases regardless of size, among them trust service providers and DNS service providers.
Annex I point 9 lists managed service providers and managed security service providers. Article 6(39) defines a managed service provider as an entity providing services by assistance or active administration on customers’ premises or remotely. The services relate to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or other network and information systems. Both types of provider are also relevant entities under Article 1 of the implementing regulation. An IT service company in scope as one of them therefore applies point 5 of the Annex as binding law. Annex II point 5(b) covers manufacturers of computer, electronic and optical products. Whether a given company is in scope, and as which type of entity, is a legal assessment for its legal department.
Subcontractors and Article 22 coordinated risk assessments
Recital 85 of the directive says entities “should in particular be encouraged to incorporate cybersecurity risk-management measures into contractual arrangements with their direct suppliers and service providers”. It adds that entities “could consider risks stemming from other levels of suppliers and service providers”. Questions about subcontractors follow from the second point: a reseller or service company is the direct supplier, and its manufacturers, data centres and engineering partners sit one level down.
Under Article 22, the NIS Cooperation Group, with the Commission and ENISA, may carry out coordinated security risk assessments of critical supply chains. The Group does so “taking into account technical and, where relevant, non-technical risk factors”. Article 21(3) requires entities to take the results into account. Recital 90 refers to the assessment carried out for 5G networks and names non-technical factors such as “undue influence by a third country on suppliers and service providers”. On 13 February 2026 the Commission announced the Cooperation Group’s EU ICT Supply Chain Security Toolbox, with risk assessments of connected and automated vehicles and detection equipment. The Commission did not say whether these assessments fall under Article 22(1). Questions about a supplier’s ownership, where its staff work and its data is stored, and its dependence on one vendor address this non-technical side.
Contract clauses in Implementing Regulation 2024/2690, point 5.1
Point 5.1.1 requires a supply chain security policy in which the customer shall “identify their role in the supply chain and communicate it to their direct suppliers and service providers”. The selection criteria of point 5.1.2 cover the supplier’s cybersecurity practices including secure development and its ability to meet the customer’s cybersecurity specifications. They also cover the quality and resilience of the supplier’s products and services and the customer’s ability to diversify sources and limit vendor lock-in. Point 5.1.4 lists what contracts should specify, “where appropriate through service level agreements”, and qualifies the list with “where appropriate”.
| POINT 5.1.4 | WHAT IT ASKS FOR | CHECK BEFORE SIGNING |
|---|---|---|
| (a) Security requirements | cybersecurity requirements for the supplier, including those of point 6.1 on acquiring ICT products and services | whether it lists requirements or cites a whole standard, and which you meet today |
| (b) Skills and training | awareness, skills, training and, where appropriate, certifications of the supplier’s employees | which roles it covers, how training is recorded |
| (c) Background checks | verification of the background of the supplier’s employees | which staff it covers, what proof is expected |
| (d) Incident notification | notice “without undue delay” of incidents that present a risk to the customer’s systems | the time in hours, the channel, what counts as notifiable |
| (e) Audit | a right to audit or to receive audit reports | notice, scope, frequency, whether a third-party report is accepted |
| (f) Vulnerability handling | handling vulnerabilities that present a risk to the customer’s systems | target times per severity, how advisories reach the customer |
| (g) Subcontracting | rules on subcontracting and security requirements for subcontractors | named subcontractors, clauses passed on, notice before changes |
| (h) Exit | obligations at termination, such as retrieval and disposal of information | return format, deletion confirmed in writing, access removed |
Implementing Regulation (EU) 2024/2690, Annex, point 5.1.4. The right-hand column is our reading.
Point 5.1.6 has customers monitor changes in suppliers’ cybersecurity practices “at planned intervals” and after significant changes or incidents, so the questionnaire is repeated. Point 5.2 requires a registry with “contact points for each direct supplier and service provider” and what each provides. Name a security contact and list what you deliver. For components critical to the customer’s security, point 6.1.2 adds “requirements regarding security updates throughout the entire lifetime of the ICT services or ICT products, or replacement after the end of the support period”. It also adds “information describing the hardware and software components used”. A reseller answers these points from the manufacturer’s support policy and documentation.
NIS2 supplier questionnaire: the questions and the evidence for each
The questions below map to points of the Annex, and the evidence column names the dated documents that support each answer.
| TOPIC | EXAMPLE QUESTION | ANNEX POINT | EVIDENCE |
|---|---|---|---|
| MFA | Is MFA enforced for remote access, email and admin consoles? | 11.6, 11.7 | the policy, a configuration export showing enforcement, exceptions with reasons |
| Privileged access | Are admin accounts personal, separate and reviewed? | 11.3, 11.4 | admin accounts per person, separate admin identities, the last access review |
| Access to our systems | How do your staff connect to our network? | 6.7.2(d), (h), 11.2.2(d) | named accounts, access approved by the customer for a set period, MFA, logs |
| Backups and restore tests | When did you last restore from backup? | 4.2.2, 4.2.6 | the backup plan, job logs, the last restore test report with date and time taken |
| Incident notification | Within how many hours will you notify us? | 5.1.4(d), 3.3 | the incident procedure with its customer notification step, named contacts |
| Vulnerabilities, patches | How fast do you fix critical vulnerabilities? | 5.1.4(f), 6.6, 6.10 | target times per severity, the last scan summary, the advisory channel |
| Subcontractors | Who else handles our data or reaches our systems? | 5.1.4(g) | subcontractors with role and country, clauses passed on, the data processing agreement |
| Certifications | Which certificates do you hold? | 5.1.2, 5.1.4(b) | each certificate with holder, scope and expiry; staff certifications for named roles |
Implementing Regulation (EU) 2024/2690, Annex points named; ENISA Technical Implementation Guidance, version 1.0 (June 2025), examples of evidence for point 4.2.2. The questions and the other evidence are our reading.
An export from the identity system shows what is enforced today, which a policy alone does not; our guides to phishing-resistant MFA and privileged access management cover those controls. For backups, ENISA’s examples of evidence under point 4.2.2 include “Backup plans” and “Logs from backup software that show regular backups are being performed”. Point 4.2.6 asks for regular recovery tests with documented results, as our NIS2 backup guide explains.
Under Article 23(4), an in-scope customer’s early warning to its CSIRT or competent authority is due within 24 hours of becoming aware of a significant incident. A supplier’s notice may be how the customer becomes aware, so a contract may set the notice in hours instead of “without undue delay”. Point 3.3.2 has customers communicate their event reporting mechanism to suppliers, and that channel belongs in your incident procedure; our article on NIS2 incident reporting covers the customer’s deadlines.
Our security and compliance assessment audits infrastructure, access, backups and compliance with NIS2 requirements, and ends with a risk map and a prioritised action plan. Send us the questionnaire you received and the answers you cannot yet support with evidence.
How a mid-size supplier prepares one evidence pack
A supplier with several in-scope customers gets the same questions in different templates, and one evidence pack, kept current, answers them all.
- Map each question in the questionnaires and security annexes received so far to an Annex point.
- Write a company sheet with the legal entity, a security contact, the incident notification channel and an exact list of what you supply.
- Describe how your staff reach customer systems: named accounts, MFA, approval by the customer for a set period, logging, removal of access when the work ends.
- File the evidence for each topic in the table above with its date: policy excerpt, configuration export, last test report, last review record.
- List subcontractors with role and country, and certificates with the entity that holds each, its scope and its expiry date.
- Mark each gap as planned, with a date, instead of answering yes for a control that is not in place.
- Update the pack after significant changes and before each planned re-assessment under point 5.1.6.
Network diagrams and penetration test reports can be shown under an NDA or in a review meeting rather than uploaded to a supplier portal. Answers attached to a contract can become commitments, so describe your systems as they are on the day you answer.
Certificates in a supplier assessment: holder and scope
Neither Article 21 nor point 5 of the implementing regulation’s Annex requires a supplier to hold an ISO/IEC 27001 certificate. Under point 5.1.2, each customer sets its own selection criteria. ENISA’s June 2023 report on supply chain cybersecurity draws on a 2022 survey of 1,081 organisations across the EU. In it, 61 % of the organisations said they “require security certification from suppliers”.
A certificate covers the legal entity and the scope written on it. A data centre operator’s ISO/IEC 27001 certificate therefore does not extend to a reseller or service company hosting systems there. An answer should name the entity that holds each certificate. Point 5.1.4(b) concerns certifications of the supplier’s employees, “where appropriate”, such as the vendor certifications of the engineers on a contract.
When Eurokommerz is the supplier on your list, we fill in your form and state precisely which entity holds which certificate. We hold no ISO certificate of our own and do not borrow our partner’s. Send us your supplier questionnaire through the form below.
General information on EU law as of October 2026, not legal advice for an individual case.
What we do
Under Cyber Resilience, our engineering partner Vixen.UNO audits infrastructure, access, backups and compliance with NIS2 requirements. You receive a NIS2 compliance map with the gaps listed and a plan to close them. The compliance map is a technical assessment. Implementation covers network segmentation, zero-trust access with multi-factor authentication and privileged access management, regular test restores and an incident response plan. The implementation is rolled out step by step in agreed maintenance windows with a rollback plan. The price of the technical assessment is fixed before work begins, and we do not issue compliance certificates. As a supplier, we sign an NDA before technical detail, provide a data processing agreement on request and name subprocessors in the contract, as our security and compliance page sets out.
FAQ
Does NIS2 apply to suppliers?
What does NIS2 require for supply chain security and third-party risk?
What is in a NIS2 supplier questionnaire?
Which contract clauses does NIS2 require with suppliers?
How quickly must a supplier notify a customer of an incident under NIS2?
Does a supplier need ISO 27001 certification for NIS2?
Send us the questionnaire or security annex your customer sent, with a short note on how your company handles MFA, admin accounts, backups and incidents today. We reply within one business day with a date for a first call, on which we work through your situation and infrastructure, and you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day