NIS2 · Supply Chain Security

NIS2 supplier questionnaires: What customers actually need to evidence

NIS2 does not require affected companies to send every supplier the same questionnaire. It does require appropriate supply-chain risk management. For vendors, that increasingly means customers want more than Yes: they want an answer with scope, source and accountable approval.

30 July 202610 min readAuf Deutsch lesen
NIS2 supplier security questionnaire mapped to evidence with one visible evidence gap

Why NIS2 creates more supplier questionnaires

Article 21 of the NIS2 Directive requires essential and important entities to take appropriate and proportionate cybersecurity risk-management measures. These expressly include supply-chain security and security-related aspects of relationships with direct suppliers and service providers.

The Directive does not prescribe one universal questionnaire. In practice, Procurement, Security and Compliance translate the duty into due-diligence questions, contract requirements and reassessments. Vendors therefore receive similar questions in very different spreadsheets.

  • Which products, services and subcontractors are critical to the customer?
  • Which vulnerability, incident and escalation processes actually operate?
  • Which business-continuity and recovery evidence is current?
  • How are access, encryption, secure development and supplier risks governed?
  • Which statements are contractual commitments and which are internal targets?

A questionnaire is not NIS2 certification

NIS2 does not create a general product certificate that a supplier can prove with one document. A customer questionnaire is first an instrument in the customer's own risk assessment. Its depth should reflect criticality, dependency and actual risk.

An ISO 27001 certificate can be valuable, but it does not automatically replace product-specific information. Certification scope, controlled environment and requested service still need to align.

Evidence that can support a defensible answer

The strongest response links a precise claim to the right source and, where effectiveness is requested, to a current operational record. A policy proves a rule exists; it does not automatically prove that an activity was completed on time.

  • approved information-security and supplier policies
  • incident-response plan, escalation matrix and exercise records
  • business-continuity and disaster-recovery tests
  • vulnerability-management process, scan or patch evidence
  • access reviews, role models and joiner-mover-leaver records
  • secure-development rules, change records and technical architecture
  • subprocessor list, relevant contracts and responsibilities

A six-step review-ready workflow

  1. 1. Separate question from claim

    Break compound rows into individual assertions. One broad Yes must not hide four different controls.

  2. 2. Establish customer and service scope

    Confirm legal entity, product, region, deployment and subcontractors before mapping a source.

  3. 3. Consider risk and criticality

    Prioritize questions that matter to the service, data access and the customer's dependency.

  4. 4. Map primary source plus record

    Use policies for requirements and operational evidence where execution or effectiveness must be shown.

  5. 5. Keep gaps visible

    Mark unsupported claims as Missing Evidence, assign an owner and never replace the gap with persuasive prose.

  6. 6. Approve and version the statement

    Security, Legal, Privacy or the technical owner approves the external claim; source, version and status remain traceable.

Where AI helps — and where it must not decide

AI can cluster repeated questions, suggest relevant passages, retrieve previously approved answers and draft an initial response. This is especially useful when researching heterogeneous spreadsheets.

It cannot reliably determine a customer's legal status or a supplier's criticality. Nor should it infer concrete technical implementation from a general policy. Scope, evidence quality, exceptions and contractual commitments require accountable human judgment.

Common NIS2 supplier-assessment mistakes

  • answering every question with the same certificate
  • describing planned measures as already implemented
  • leaving product and hosting scope ambiguous
  • reusing old responses without source and version checks
  • answering Yes when only part of a compound question is evidenced
  • hiding missing evidence behind polished wording
  • letting Sales send risky commitments without expert approval

Definition of done for the response pack

  • every material claim has a suitable source or a visible gap
  • service, location and subcontractor scope are clear
  • operational records supplement policies where effectiveness is requested
  • exceptions and partial coverage are explicit
  • owner and approval status are traceable
  • the response is precise, proportionate and reusable

Frequently asked questions

Does NIS2 directly regulate every supplier?

No. Direct scope depends on factors including sector, activity, size and national implementation. Regulated customers may nevertheless pass security requirements to their direct suppliers.

Is there an official NIS2 supplier questionnaire?

The Directive does not prescribe one universal questionnaire. Organizations conduct risk-based due diligence, so formats and depth vary.

Is ISO 27001 certification enough?

It is valuable assurance within its scope, but it does not automatically replace product-, service- or customer-specific detail and operational evidence.

Can TrustRespond confirm NIS2 compliance?

No. TrustRespond supports evidence mapping, drafting and review. Legal conclusions, control effectiveness and external approval remain with qualified accountable people.

Test a NIS2 supplier questionnaire with real evidence

In the pilot, we process up to 50 anonymized questions and show which sources are strong, where evidence is missing and which responses require expert approval.

View the NIS2 solution

Official sources

Editorial note: checked against official EU and ENISA sources on 30 July 2026. This article is practical information, not legal advice.