NIS2
Not in scope of NIS2, but your customers are: what suppliers are asked for
Updated September 26, 2026
Many small software companies, IT providers and consultancies are below the NIS2 size threshold. Their customers often are not. Article 21(2)(d) requires organisations in scope to address security in their relationships with direct suppliers, and Article 21(3) tells them to consider each supplier's vulnerabilities, product quality and security practices, including secure development.
What customers typically ask
- Do you have an information security policy approved by management?
- Is multi-factor authentication enforced for all staff with access to our systems or data?
- How quickly will you notify us of an incident, and through which channel?
- How do you handle vulnerabilities in your products and patch your infrastructure?
- Do you test backups? What recovery times can you commit to?
- Do you hold ISO/IEC 27001 or an equivalent, or can we audit you?
- Which subcontractors process our data, and where?
Contract clauses to expect
Implementing Regulation (EU) 2024/2690 lists what contracts with suppliers should cover where appropriate: security requirements, staff training and background checks, incident notification without undue delay, the right to audit or to receive audit reports, vulnerability handling, subcontracting rules, and data return and deletion at exit. In Estonia, customers must also make sure providers who host or operate their systems notify them of incidents within 24 hours.
How to answer well
Honest, specific answers beat long policies. Say what is in place today and what is planned with a date. Overstating controls creates contractual liability when something goes wrong.
Our NIS2 assessment detects when you are a supplier rather than an in-scope entity, and produces a customer security statement that lists only the controls your answers confirm, with the rest shown as improvements in progress.
Where does your company stand on NIS2?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.