Why NIS2 creates more supplier questionnaires
Article 21 of the NIS2 Directive requires essential and important entities to take appropriate and proportionate cybersecurity risk-management measures. These expressly include supply-chain security and security-related aspects of relationships with direct suppliers and service providers.
The Directive does not prescribe one universal questionnaire. In practice, Procurement, Security and Compliance translate the duty into due-diligence questions, contract requirements and reassessments. Vendors therefore receive similar questions in very different spreadsheets.
- Which products, services and subcontractors are critical to the customer?
- Which vulnerability, incident and escalation processes actually operate?
- Which business-continuity and recovery evidence is current?
- How are access, encryption, secure development and supplier risks governed?
- Which statements are contractual commitments and which are internal targets?
A questionnaire is not NIS2 certification
NIS2 does not create a general product certificate that a supplier can prove with one document. A customer questionnaire is first an instrument in the customer's own risk assessment. Its depth should reflect criticality, dependency and actual risk.
An ISO 27001 certificate can be valuable, but it does not automatically replace product-specific information. Certification scope, controlled environment and requested service still need to align.
Evidence that can support a defensible answer
The strongest response links a precise claim to the right source and, where effectiveness is requested, to a current operational record. A policy proves a rule exists; it does not automatically prove that an activity was completed on time.
- approved information-security and supplier policies
- incident-response plan, escalation matrix and exercise records
- business-continuity and disaster-recovery tests
- vulnerability-management process, scan or patch evidence
- access reviews, role models and joiner-mover-leaver records
- secure-development rules, change records and technical architecture
- subprocessor list, relevant contracts and responsibilities
A six-step review-ready workflow
1. Separate question from claim
Break compound rows into individual assertions. One broad Yes must not hide four different controls.
2. Establish customer and service scope
Confirm legal entity, product, region, deployment and subcontractors before mapping a source.
3. Consider risk and criticality
Prioritize questions that matter to the service, data access and the customer's dependency.
4. Map primary source plus record
Use policies for requirements and operational evidence where execution or effectiveness must be shown.
5. Keep gaps visible
Mark unsupported claims as Missing Evidence, assign an owner and never replace the gap with persuasive prose.
6. Approve and version the statement
Security, Legal, Privacy or the technical owner approves the external claim; source, version and status remain traceable.
Where AI helps — and where it must not decide
AI can cluster repeated questions, suggest relevant passages, retrieve previously approved answers and draft an initial response. This is especially useful when researching heterogeneous spreadsheets.
It cannot reliably determine a customer's legal status or a supplier's criticality. Nor should it infer concrete technical implementation from a general policy. Scope, evidence quality, exceptions and contractual commitments require accountable human judgment.
Common NIS2 supplier-assessment mistakes
- answering every question with the same certificate
- describing planned measures as already implemented
- leaving product and hosting scope ambiguous
- reusing old responses without source and version checks
- answering Yes when only part of a compound question is evidenced
- hiding missing evidence behind polished wording
- letting Sales send risky commitments without expert approval
Definition of done for the response pack
- every material claim has a suitable source or a visible gap
- service, location and subcontractor scope are clear
- operational records supplement policies where effectiveness is requested
- exceptions and partial coverage are explicit
- owner and approval status are traceable
- the response is precise, proportionate and reusable
Frequently asked questions
Does NIS2 directly regulate every supplier?
No. Direct scope depends on factors including sector, activity, size and national implementation. Regulated customers may nevertheless pass security requirements to their direct suppliers.
Is there an official NIS2 supplier questionnaire?
The Directive does not prescribe one universal questionnaire. Organizations conduct risk-based due diligence, so formats and depth vary.
Is ISO 27001 certification enough?
It is valuable assurance within its scope, but it does not automatically replace product-, service- or customer-specific detail and operational evidence.
Can TrustRespond confirm NIS2 compliance?
No. TrustRespond supports evidence mapping, drafting and review. Legal conclusions, control effectiveness and external approval remain with qualified accountable people.
Test a NIS2 supplier questionnaire with real evidence
In the pilot, we process up to 50 anonymized questions and show which sources are strong, where evidence is missing and which responses require expert approval.
Official sources
- Directive (EU) 2022/2555 — NIS2
- Implementing Regulation (EU) 2024/2690
- ENISA — NIS2 Technical Implementation Guidance
- EU ICT Supply Chain Security Toolbox
Editorial note: checked against official EU and ENISA sources on 30 July 2026. This article is practical information, not legal advice.
