NIS2 supplier questionnaires for SMEs — an evidence-first checklist
Large customers send long NIS2 / supply-chain security questionnaires even when the supplier is not itself an essential or important entity. Directive (EU) 2022/2555 (NIS2) requires in-scope entities to manage supply-chain risk (Art. 21(2)(d)) — that is why the forms land in your inbox. This page is a practical first pass. It is educational only: not legal advice, not a certification, and not a NIS2 audit.
Who this guide is for
- SME suppliers answering enterprise security schedules
- Founders and ops leads who need scope → questions → evidence in that order
- Teams that refuse to invent fake ISO certificates just to “pass” a portal
Official dates & scope context (EUR-Lex / Commission)
- 17 October 2024 — Member States must adopt and publish measures necessary to comply (Art. 41(1)).
- 18 October 2024 — Those measures apply from this date; NIS1 repealed as from this date (Art. 41(1)).
- Size-cap — As a rule, Annex I/II entities that are medium-sized under Recommendation 2003/361/EC, or larger, and active in the Union, fall within scope (Art. 2(1)).
- Essential / important — Classification by size + annex sector; some types regardless of size (Art. 3).
- Incident reporting (context) — For essential/important entities: early warning within 24 hours; incident notification within 72 hours; final report not later than one month after the notification (Art. 23(4)). Not automatic duties if you are out of scope.
Supplier angle: Many small suppliers are out of direct scope under the size-cap but still face questionnaires. Answering honestly with evidence is not the same as becoming a notified entity. National transposition varies — we do not invent a country table.
Three-step questionnaire method
- Scope yourself: Are you Annex I/II + medium/large, or a smaller supplier-only firm? Write the answer before you fill cells.
- Map questions to themes: access control, logging, backups, vulnerability process, vendor list, incident contact, encryption, remote work, data location.
- Attach evidence: Prefer real policies, screenshots of MFA, backup schedules, and named contacts over marketing claims.
Evidence index (typical asks)
- Information security / acceptable-use policy (version + date)
- Access control: MFA on admin and email; joiner/mover/leaver notes
- Backup and restore test notes (even if lightweight)
- List of critical subprocessors / cloud vendors
- Incident contact email/phone and escalation path
- Patch or vulnerability cadence you actually follow
What this does not mean
Completing a customer form does not make you “NIS2 certified.” There is no single EU NIS2 certificate in a download pack. Use counsel when regulatory status or contract liability is on the line.
Official sources (verify live)
- EUR-Lex Directive (EU) 2022/2555
- ELI / OJ
- European Commission — NIS2 Directive
- NIS2 transposition in EU countries
Want a printable supplier file? NIS2 Supplier Starter includes scope sheet, questionnaire map, and evidence index — $29.90 one-time via Polar. Educational only. Not an audit.
Educational materials only. Not legal advice. Not a certification. Not a NIS2 audit. Operator: Ismail Kanto.