Back to Publications
Regulatory Brief · NIS2

NIS2 Reaches You Through Procurement, Not a Regulator

31 July 2026By NexCyber Editorial NIS2

Most companies meet NIS2 as a customer questionnaire, not a legal notice. Article 21(2)(d) puts it in your contracts even when you are out of scope.

The short answer

Most companies that end up doing NIS2 work were never in NIS2 scope.

Directive (EU) 2022/2555 obliges in-scope entities to manage the security risks of their supply chain, including the security of their direct suppliers — Article 21(2)(d).

That clause does not put suppliers in scope. It puts NIS2 into their contracts.

the law reaches your CUSTOMER
your customer must answer for its suppliers
-> the questionnaire reaches YOU

A hospital group, an energy utility, a bank, a logistics operator, a cloud provider — each is answerable for the security of what it buys. The cheapest way for them to discharge that duty is to ask you.

And they will ask before any authority does. The commercial deadline arrives first, and it is the one that costs revenue.

---

Who is genuinely in scope

Scope is sector, then size.

Annex I — high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, space.

Annex II — other critical sectors: postal and courier, waste management, chemicals, food, manufacturing (including medical devices, computers and electronics, machinery, motor vehicles), digital providers, research.

essential   large entities in an Annex I sector
important   medium entities in Annex I · large and medium in Annex II

Certain entities are in scope regardless of size — DNS providers, TLD registries, trust service providers, providers of public electronic communications.

And NIS2 is a Directive, not a Regulation. It does not bind you directly: the national transposition of each Member State where you operate binds you, and those texts differ in registration procedure, supervisory authority and penalty ceiling. Anyone quoting "the NIS2 requirement" without naming a country is quoting the floor, not the rule.

---

What the questionnaire will actually ask

Your customer has to evidence that it manages supplier risk. In practice it asks you to demonstrate the same ten measures it owes under Article 21(2):

  1. 1policies on risk analysis and information system security
  2. 2incident handling
  3. 3business continuity — backup, disaster recovery, crisis management
  4. 4supply chain security, including your own direct suppliers
  5. 5security in acquisition, development and maintenance, including vulnerability handling and disclosure
  6. 6policies to assess the effectiveness of the measures themselves
  7. 7basic cyber hygiene and cybersecurity training
  8. 8cryptography and, where appropriate, encryption
  9. 9HR security, access control, asset management
  10. 10multi-factor or continuous authentication, secured voice/video/text, secured emergency communications

Measure 4 propagates. Your customer asks you; you must be able to answer for your own suppliers. The chain does not stop at the first link.

Measure 6 is the one almost every programme omits, and the one a serious buyer probes. It requires you to assess whether your measures work — a review with a date, a scope and a result. An annual assertion that the policy exists is not an assessment.

---

The incident clause that lands in your contract

Your customer owes Article 23: early warning within 24 hours, incident notification within 72 hours, final report within one month.

It cannot meet a 24-hour clock if a supplier takes three days to confirm an incident. So the clock is pushed into supplier contracts — typically as a duty to notify within hours, not days.

This is the clause that changes your operations rather than your paperwork. It requires someone reachable, with the authority to tell a customer that something happened, before the full picture exists.

---

Why answering well is a commercial advantage, not a cost

The questionnaire is a purchase condition. Every supplier receives it; most answer late, partially, or with a policy document that does not address the question.

Three things a buyer notices immediately:

an SBOM you can regenerate      -> answers "what is in your product" in minutes
a published vulnerability       -> proves the process exists outside your slide deck
  disclosure policy and contact
a dated effectiveness review    -> answers measure 6, which most suppliers cannot

None of the three requires certification. All three are verifiable from outside, which is exactly why they carry weight.

And the same artefacts answer the CRA, DORA and the AI Act. The SBOM required under CRA Annex I Part II is the SBOM your NIS2 customer asks for. Building it once and mapping it to several regimes is the difference between a compliance cost and a sales asset.

---

What to do before the next questionnaire arrives

  1. 1Determine whether you are genuinely in scope — sector, then size, then the national transposition. Being out of scope does not exempt you from the questionnaire; it changes what you owe.
  2. 2Prepare the three verifiable artefacts above. They answer most of what is asked.
  3. 3Name who can notify a customer of an incident, and give that person the authority to do it without convening a committee.
  4. 4Write your effectiveness review, with a date. Measure 6 is where a thin programme shows.
  5. 5Map your answers across regulations before writing them. Answering NIS2 alone means answering the CRA again in six months.

---

Check where you stand — free, no account, no sales call

  • [Free applicability assessment](/assess) — determine NIS2 scope and entity class, and see the same evidence mapped across CRA, DORA, the AI Act and RED.
  • [Compliance responsibility mapper](/resources/responsibility-mapper) — a RACI by role, so the notification duty lands on a named person.
  • [Penalty calculator](/resources/penalty-calculator) — exposure on your own turnover.

---

Further reading

What is NIS2Essential versus important entitiesNIS2 incident reporting timelinesNIS2 implementation guide — eight stepsHow to build an SBOMOne evidence set across five EU regulationsNIS2 regulation overview

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. NIS2 is a Directive: the binding text is the national transposition in each Member State where you operate, and those texts differ. Verify against the applicable national law and consult your competent authority or a qualified adviser.*