Blog

Indirectly in scope: when your customer sends the NIS2 questionnaire

· 2 min read · NIS2 · Supply chain · SMEs

You are not covered by NIS2, but your largest customer is. Then a questionnaire arrives. How to answer it without bending the truth.

Many mid-sized companies followed the NIS2 debate with relief: too small, wrong sector, not in scope. Then an email arrives from their most important customer with an information security questionnaire, 40 questions, due in two weeks.

Why the questionnaire arrives

NIS2 requires entities in scope to address the security of their supply chain as well (Art. 21(2)(d) of the directive). Your customers therefore need to know how resilient their suppliers and service providers are. The questionnaire is how they show it. It is not a vote of no confidence but a duty your customer passes on to you.

The typical questions

Most questionnaires circle around the same topics:

  • Is there a continuity plan, and when was it last tested?
  • How quickly can you deliver again after an outage?
  • How are security incidents reported, and to whom?
  • Who has access to the customer's systems and data?
  • How are backups organised, and are they separated from production?

Three mistakes I often see

Answering everything with yes. It looks good at first, but becomes a problem at your customer's next audit when evidence is requested.

Answering every request from scratch. With several customers you get several questionnaires with similar questions worded differently. Without a central collection of answers and evidence, that costs days every time.

Hiding gaps. An honest answer with an action plan convinces more than a polished one. "A recovery test is planned for the second quarter" is a good answer.

What to prepare

Build an answer library: short, verifiable statements on continuity planning, backup, access and reporting, each with the evidence behind it. That turns every new questionnaire into a task of hours instead of days.

And if a question makes you hesitate, that is a good pointer to where your own resilience still has gaps. Whether or not a law forces you to look.

← Back to overview

More articles

· 2 min read

Tabletop exercise: half a day in the crisis team

No technology, no script to memorise. A table, a scenario and the people who decide in a real incident. This is how a tabletop exercise works.

Exercises · Crisis team · Tabletop

· 2 min read

NIS2: What management needs to know personally

NIS2 makes cyber security a board matter, quite literally. What management must approve, oversee and learn, and why delegating alone is not enough.

NIS2 · Management · Liability