Skip to content
NIS2 & Cbw · · 2 min read

NIS2 and your supply chain: why your clients will start asking questions

Even if NIS2 does not apply to you directly, it can reach you through your clients. How to prepare for questions about your security in the chain.

By Limburg Cyber Group

Many business owners think of NIS2: “we’re too small, this doesn’t apply to us.” That may be true for the law’s direct effect. But there is a second route by which NIS2 reaches your business, and it is often overlooked: the supply chain.

Why the chain is part of the law

NIS2 requires organisations that do fall under it to manage the risks in their supply chain too. They must be able to demonstrate that the parties they work with have their security in order. The result: those large clients will pass that requirement down to their suppliers, including the small ones.

Do you supply software, administration, advice, or other services to an organisation that falls under NIS2? Then there is a good chance you will sooner or later receive a questionnaire or contract clause about security.

What clients (will) ask

The questions are usually a variation on:

  • Do you have basics like MFA, backups, and an update policy in order?
  • How do you handle access to their data?
  • What do you do in an incident, and how quickly do you report it to them?
  • Can you demonstrate that you meet your commitments, for example with a policy or certification?

Answer this vaguely and you risk the contract. Have it neatly in order and you win trust.

From threat to opportunity

Here is the crux: having your security in order becomes a commercial argument. In sectors where your clients fall under NIS2, think of suppliers to healthcare, energy, government, or large companies, a demonstrably secure way of working can make the difference between being chosen or not.

What you can do now

  1. Get the basics in order. MFA, backups, updates, access management, an incident plan. See our starter guide.
  2. Write it down. A short security policy you can show is worth its weight in gold for these questions.
  3. Know who your own suppliers are. The chain works both ways; your IT parties are part of your risk too.
  4. Check whether you fall under the law yourself. Take the NIS2 self-scan to know where you stand.

Need help?

We help businesses in Limburg answer supplier questions with confidence, with measures that hold up and documentation you can show. See our NIS2 approach or book a conversation.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.