NIS2 and your supply chain: why your clients will start asking questions
Even if NIS2 does not apply to you directly, it can reach you through your clients. How to prepare for questions about your security in the chain.
By Limburg Cyber Group
Many business owners think of NIS2: “we’re too small, this doesn’t apply to us.” That may be true for the law’s direct effect. But there is a second route by which NIS2 reaches your business, and it is often overlooked: the supply chain.
Why the chain is part of the law
NIS2 requires organisations that do fall under it to manage the risks in their supply chain too. They must be able to demonstrate that the parties they work with have their security in order. The result: those large clients will pass that requirement down to their suppliers, including the small ones.
Do you supply software, administration, advice, or other services to an organisation that falls under NIS2? Then there is a good chance you will sooner or later receive a questionnaire or contract clause about security.
What clients (will) ask
The questions are usually a variation on:
- Do you have basics like MFA, backups, and an update policy in order?
- How do you handle access to their data?
- What do you do in an incident, and how quickly do you report it to them?
- Can you demonstrate that you meet your commitments, for example with a policy or certification?
Answer this vaguely and you risk the contract. Have it neatly in order and you win trust.
From threat to opportunity
Here is the crux: having your security in order becomes a commercial argument. In sectors where your clients fall under NIS2, think of suppliers to healthcare, energy, government, or large companies, a demonstrably secure way of working can make the difference between being chosen or not.
What you can do now
- Get the basics in order. MFA, backups, updates, access management, an incident plan. See our starter guide.
- Write it down. A short security policy you can show is worth its weight in gold for these questions.
- Know who your own suppliers are. The chain works both ways; your IT parties are part of your risk too.
- Check whether you fall under the law yourself. Take the NIS2 self-scan to know where you stand.
Need help?
We help businesses in Limburg answer supplier questions with confidence, with measures that hold up and documentation you can show. See our NIS2 approach or book a conversation.
Read more
GDPR and NIS2: where they overlap and where they differ
GDPR and NIS2 look alike, but protect different things. Here is how to understand the overlap, the differences, and why you may face both at once.
ISO 27001 vs NIS2: what is the difference and do you need both?
ISO 27001 and NIS2 are often mentioned in one breath, but they are not the same. The difference explained clearly, and how they actually reinforce each other.
NIS2 and director liability: why this is a boardroom topic
Under NIS2, directors are personally responsible for cybersecurity. What that means concretely and how the board can demonstrably take up its role.