NIS2 supply chain requirements — what suppliers are being asked for, and why

Most companies receiving NIS2 security questionnaires are not in scope themselves. They are suppliers to someone who is — and the obligation is arriving through the contract rather than through the law.

First hour’s on us. No commitment.

What you get

If you are in scope — supplier clauses that actually discharge your obligation, a tiering method so you ask proportionately, and a defensible record of the assessment.

If you are a supplier — a standard answer to the questionnaires, contract terms you can accept without taking on more than you should, and a position that makes you easier to buy from.

How it works

  1. Intake, 45 minutes. Which side of the contract you are on, and what has landed on your desk. Free.
  2. Review, one to three weeks. Scope, terms, and what the requirement actually is.
  3. The output. Clauses, a questionnaire response pack, or both.

Who you’ll work with

Narmin Abbasova, Legal Advisor for EU and business law, leads this work. She specialises in EU business law, cross-border matters and commercial agreements, with experience from international firms and bar associations, and holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

What the law actually requires

The Swedish Cybersecurity Act, implementing NIS2, requires in-scope entities to take appropriate and proportionate technical, operational and organisational measures. One of the listed areas is supply chain security — including security aspects of the relationships between the entity and its direct suppliers and service providers.

Two words carry the weight. Direct: the obligation concerns your immediate suppliers, not the entire chain behind them. Proportionate: it is measured against the vulnerabilities specific to each supplier, the quality of their products and practices, and the criticality of what they provide.

That combination is what most questionnaires get wrong in both directions.

The mistake in-scope entities make

The common approach is to send every supplier the same eighty-question security assessment. It generates enormous work, produces answers nobody reads, and does not discharge the obligation any better than a proportionate approach would.

What holds up under supervision is a documented tiering: which suppliers touch systems that matter, what the exposure actually is, and a depth of enquiry that matches. A cleaning contractor and your core banking platform provider should not receive the same questionnaire, and a supervisor will not be impressed that they did.

The second mistake is asking the questions and not putting anything in the contract. An assessment without contractual consequence is an opinion. What discharges the obligation is terms: security requirements, incident notification with a timeframe that lets you meet your own 24-hour clock, audit or evidence rights, subcontractor control, and termination where the supplier’s security position deteriorates.

The mistake suppliers make

The first is treating each questionnaire as a bespoke project. The questions converge; the answers should be a maintained asset, not a rewrite.

The second is accepting terms drafted for an in-scope entity. Customers frequently pass through obligations that the law places on them, not on you — full NIS2 compliance warranties, unlimited audit rights, incident notification within hours that your operations cannot support. Some of that is negotiable. Agreeing to timelines you cannot meet converts a commercial problem into a breach.

The third is missing that you might be in scope yourself. Digital infrastructure and ICT service management are among the eighteen sectors. A supplier assuming it is merely a supplier is worth checking.

What good looks like on each side

In scope: a tiered supplier register with reasoning; security requirements in contracts proportionate to tier; incident notification timelines that support your own reporting duties; evidence rights that are usable; and a review cycle, since supplier risk is not static.

Supplier: a maintained security response pack; certifications or assurance reports that answer most questions before they are asked; a set of contract terms you have decided in advance you can accept; and a clear internal owner so responses do not take three weeks.

Frequently asked questions

We are a small supplier. Can we refuse to answer?

You can, and you will lose the customer. The better position is a proportionate answer prepared once. Small suppliers who answer well are frequently preferred over larger ones who answer slowly.

Does NIS2 apply to us because our customer is in scope?

Not legally. It reaches you contractually. Whether you are separately in scope depends on your own sector and size — worth establishing, because the answer changes what you should agree to.

How far down the chain does the obligation go?

The requirement concerns direct suppliers. Deeper chains matter where they affect the security of what your direct supplier delivers, and that is usually handled through subcontractor control clauses rather than direct assessment.

Our customer wants notification within 4 hours. Is that required?

Not by the Act. Your customer has a 24-hour early warning obligation to the authority and is building in margin. It is negotiable, and a realistic timeline you meet is worth more to them than an aggressive one you miss.

How does this relate to DORA?

Similar mechanism, different regime. Financial entities follow DORA’s third-party rules instead of the Cybersecurity Act’s. If you supply both financial and non-financial customers, you will meet both.

Where to start

Bring the questionnaire or the clause you were sent. Half the answer is usually visible within the first conversation, and that conversation is free.

Related