NIS2 Supplier Starter — educational questionnaire & evidence pack for SME suppliers
NIS2 Supplier Starter is a downloadable readiness pack for SME suppliers who receive long NIS2 / supply-chain security questionnaires from large customers. It is built around Directive (EU) 2022/2555 (NIS2). It is not legal advice, not a certification, and not a NIS2 audit.
Price: $39.90 USD one-time. Checkout is via Polar (card in USD). After payment, Polar emails the receipt and file download to the email you use at checkout. This site does not store card data.
Who it is for
- SMEs that are not themselves essential/important entities but must still answer customer security questionnaires
- Founders and ops leads who need a structured first pass: scope check → question map → evidence checklist
- Teams preparing a thin, honest “supplier file” before signing a customer security schedule
Official dates & scope used in this pack (EUR-Lex / Commission)
| Date / fact | What (summary) | Article |
|---|---|---|
| 17 October 2024 | Member States must adopt and publish measures necessary to comply with the Directive. | Art. 41(1) |
| 18 October 2024 | Those measures apply from this date (NIS1 repealed as from this date). | Art. 41(1) |
| Size-cap | As a rule, Annex I/II entities that are medium-sized under Recommendation 2003/361/EC, or larger, and active in the Union, fall within scope. | Art. 2(1) |
| Essential / important | Entities are classified as essential or important (size + annex sector; some types regardless of size). | Art. 3 |
| Supply chain | In-scope entities’ risk-management measures must include supply chain security, including relationships with direct suppliers or service providers — a common driver of vendor questionnaires. | Art. 21(2)(d) |
| Incident reporting | For essential/important entities: early warning within 24 hours of awareness; incident notification within 72 hours; final report not later than one month after the notification. Context for suppliers — not automatic duties if you are out of scope. | Art. 23(4) |
Supplier angle: Many small suppliers are not directly in scope under the size-cap but still face questionnaires because customers must manage supply-chain risk. This pack helps you answer with real evidence. It does not turn you into a notified entity.
National law varies. Art. 41 set 17 October 2024 as the transposition deadline. Check your Member State — this page does not invent a country-by-country table.
Sources (verify live): EUR-Lex Directive (EU) 2022/2555, ELI / OJ, European Commission — NIS2 Directive, NIS2 transposition in EU countries.
What is in the pack (v1)
- START-HERE — orientation, official dates, how to use the pack
- Who is in scope — Annex/size: SME itself vs supplier-only
- Customer questionnaire map — typical NIS2/supply-chain questions → evidence themes
- Evidence index — policies, access control, backup, vendor list, incident contact (checklist of artifacts, not fake certs)
What this does not mean
Checking boxes does not make you “NIS2 compliant” or “certified.” There is no single EU NIS2 certificate in this pack. National transposition and your facts matter. Use official sources and qualified counsel for decisions that affect regulatory status or customer contracts. This pack does not perform a NIS2 audit.
Educational materials only. Not legal advice. Not a certification. Not a NIS2 audit. NIS2 Supplier Starter does not guarantee legal or compliance outcomes. Operator: Ismail Kanto.