NIS2 supplier questionnaires for SMEs — an evidence-first checklist

Large customers send long NIS2 / supply-chain security questionnaires even when the supplier is not itself an essential or important entity. Directive (EU) 2022/2555 (NIS2) requires in-scope entities to manage supply-chain risk (Art. 21(2)(d)) — that is why the forms land in your inbox. This page is a practical first pass. It is educational only: not legal advice, not a certification, and not a NIS2 audit.

Who this guide is for

  • SME suppliers answering enterprise security schedules
  • Founders and ops leads who need scope → questions → evidence in that order
  • Teams that refuse to invent fake ISO certificates just to “pass” a portal

Official dates & scope context (EUR-Lex / Commission)

  • 17 October 2024 — Member States must adopt and publish measures necessary to comply (Art. 41(1)).
  • 18 October 2024 — Those measures apply from this date; NIS1 repealed as from this date (Art. 41(1)).
  • Size-cap — As a rule, Annex I/II entities that are medium-sized under Recommendation 2003/361/EC, or larger, and active in the Union, fall within scope (Art. 2(1)).
  • Essential / important — Classification by size + annex sector; some types regardless of size (Art. 3).
  • Incident reporting (context) — For essential/important entities: early warning within 24 hours; incident notification within 72 hours; final report not later than one month after the notification (Art. 23(4)). Not automatic duties if you are out of scope.

Supplier angle: Many small suppliers are out of direct scope under the size-cap but still face questionnaires. Answering honestly with evidence is not the same as becoming a notified entity. National transposition varies — we do not invent a country table.

Three-step questionnaire method

  1. Scope yourself: Are you Annex I/II + medium/large, or a smaller supplier-only firm? Write the answer before you fill cells.
  2. Map questions to themes: access control, logging, backups, vulnerability process, vendor list, incident contact, encryption, remote work, data location.
  3. Attach evidence: Prefer real policies, screenshots of MFA, backup schedules, and named contacts over marketing claims.

Evidence index (typical asks)

  • Information security / acceptable-use policy (version + date)
  • Access control: MFA on admin and email; joiner/mover/leaver notes
  • Backup and restore test notes (even if lightweight)
  • List of critical subprocessors / cloud vendors
  • Incident contact email/phone and escalation path
  • Patch or vulnerability cadence you actually follow

What this does not mean

Completing a customer form does not make you “NIS2 certified.” There is no single EU NIS2 certificate in a download pack. Use counsel when regulatory status or contract liability is on the line.

Official sources (verify live)

Want a printable supplier file? NIS2 Supplier Starter includes scope sheet, questionnaire map, and evidence index — $29.90 one-time via Polar. Educational only. Not an audit.

Get NIS2 Supplier — $29.90 Product page

Educational materials only. Not legal advice. Not a certification. Not a NIS2 audit. Operator: Ismail Kanto.

← EN home