Legislation

NIS2 questionnaire for suppliers: view an example before yours arrives

Information Security
Vendor Management
Supply Chain
Required

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Haven't received a questionnaire from a NIS2-regulated client regarding the Cyber Security Act yet? You still have time to prepare. Your client hasn't started the conversation with you yet, and you can use that time to get ready at your own pace for when they do. You're going to need that time.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
25.08.2026
Written by
Kilian
Houthuijzen
Commercieel Manager & Partner

Do you have to be NIS2-compliant as a supplier?

Not automatically. The Cyber Security Act, the Dutch implementation of the European NIS2 directive, applies directly to approximately 8,000 organizations across 18 sectors, based on their specific sector and size. Many SME suppliers do not fall under this based on their own situation. However, if you supply to an organization that is subject to the law, you will still be affected through your client. You will often receive a questionnaire from a major client like ASML or Philips, which has a massive impact on your growth and continuity as an SME. This is entirely due to supply chain responsibility.

{{LINKCARD}}

So why is your client sending a cybersecurity questionnaire?

Organizations subject to the law are required to map and manage the security of their supply chain. In other words, supply chain responsibility. This usually starts with a risk analysis of their suppliers, and a questionnaire is often the method they use to conduct this with you. Among other things, they want to know how you handle their data, who has access to it, and how quickly and systematically you respond if something goes wrong. The latter is not an unnecessary question for your client: they themselves have strict reporting deadlines for cyber incidents (24 hours for an initial warning, 72 hours for an initial assessment, and one month for the final report, all to the CSIRT and the regulator).

Are you required to complete the questionnaire?

There is no law that directly obligates you as a supplier to respond. What is changing, however, is that clients are increasingly including these types of requirements in contracts or purchasing terms. A supplier that does not provide a clear answer risks losing the contract to a competitor who can. In practice, this makes the questionnaire feel primarily like a condition for retaining the business.

What is in the sample questionnaire?

The questionnaire you can download here is a self-assessment based on what we have encountered in practice with clients. It consists of nearly 100 questions based on the control measures from ISO 27001:2022 (Annex A). One section stands out in particular: as a supplier, you will also receive questions about your own suppliers, such as how you include security requirements in their contracts and how you map risks in that secondary chain. Supply chain responsibility, therefore, does not stop with you.

 

For each question, provide an explanation, refer to evidence such as policies or tooling where possible, and assign yourself a maturity level: not present, present, defined, or best practice. This gives your client a complete and substantiated overview at once, rather than just isolated yes/no answers.

NIS2 questionnaire for suppliers: What can you do today?

 

  1. Go through the 93 questions and give yourself an honest, preliminary score for each measure: not present, present, defined, or best practice.
  2. For the items where you score "present" or higher, start collecting the evidence, such as a policy document, a screenshot of a setting, or a process description.
  3. Keep that overview in a single document so you can reuse it as soon as your own client's questionnaire arrives

 

This way, you don't have to start from scratch the moment that questionnaire lands in your inbox. You can get a head start on that process now, at your own pace. Want to handle this structurally? Then an ISO 27001 certification or a NIS2 Supply Chain label is a rock-solid option.

 

Are you unsure if this applies to your organization, or do you want to know which certification best suits your company? Schedule a no-obligation call below, and we can explore your options together.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Legislation

NIS2 implementation at Fendix: from gap analysis to compliance

by
Jurre
Kennisartikel
NIS2

Cybersecurity Act (NIS2) registration obligation: how to register with the NCSC

by
Kilian
Kennisartikel
Legislation

When does NIS2 take effect? Deadlines & legislation explained

by
Mathijs
Kennisartikel