Legislation

NIS2 questionnaire for suppliers: view an example before yours arrives

Information Security
Vendor Management
Supply Chain
Required
Haven't received a questionnaire from a NIS2-regulated client regarding the Cyber Security Act yet? You still have time to prepare. Your client hasn't started the conversation with you yet, and you can use that time to get ready at your own pace for when they do. You're going to need that time.
This article was last updated on
25.08.2026
Written by
Kilian
Houthuijzen
Commercieel Manager & Partner

Do you have to be NIS2-compliant as a supplier?

Not automatically. The Cyber Security Act, the Dutch implementation of the European NIS2 directive, applies directly to approximately 8,000 organizations across 18 sectors, based on their specific sector and size. Many SME suppliers do not fall under this based on their own situation. However, if you supply to an organization that is subject to the law, you will still be affected through your client. You will often receive a questionnaire from a major client like ASML or Philips, which has a massive impact on your growth and continuity as an SME. This is entirely due to supply chain responsibility.

‍

{{LINKCARD}}

So why is your client sending a cybersecurity questionnaire?

Organizations subject to the law are required to map and manage the security of their supply chain. In other words, supply chain responsibility. This usually starts with a risk analysis of their suppliers, and a questionnaire is often the method they use to conduct this with you. Among other things, they want to know how you handle their data, who has access to it, and how quickly and systematically you respond if something goes wrong. The latter is not an unnecessary question for your client: they themselves have strict reporting deadlines for cyber incidents (24 hours for an initial warning, 72 hours for an initial assessment, and one month for the final report, all to the CSIRT and the regulator).

Are you required to complete the questionnaire?

There is no law that directly obligates you as a supplier to respond. What is changing, however, is that clients are increasingly including these types of requirements in contracts or purchasing terms. A supplier that does not provide a clear answer risks losing the contract to a competitor who can. In practice, this makes the questionnaire feel primarily like a condition for retaining the business.

What is in the sample questionnaire?

The questionnaire you can download here is a self-assessment based on what we have encountered in practice with clients. It consists of nearly 100 questions based on the control measures from ISO 27001:2022 (Annex A). One section stands out in particular: as a supplier, you will also receive questions about your own suppliers, such as how you include security requirements in their contracts and how you map risks in that secondary chain. Supply chain responsibility, therefore, does not stop with you.

 

For each question, provide an explanation, refer to evidence such as policies or tooling where possible, and assign yourself a maturity level: not present, present, defined, or best practice. This gives your client a complete and substantiated overview at once, rather than just isolated yes/no answers.

NIS2 questionnaire for suppliers: What can you do today?

 

  1. Go through the 93 questions and give yourself an honest, preliminary score for each measure: not present, present, defined, or best practice.
  2. For the items where you score "present" or higher, start collecting the evidence, such as a policy document, a screenshot of a setting, or a process description.
  3. Keep that overview in a single document so you can reuse it as soon as your own client's questionnaire arrives

 

This way, you don't have to start from scratch the moment that questionnaire lands in your inbox. You can get a head start on that process now, at your own pace. Want to handle this structurally? Then an ISO 27001 certification or a NIS2 Supply Chain label is a rock-solid option.

 

Are you unsure if this applies to your organization, or do you want to know which certification best suits your company? Schedule a no-obligation call below, and we can explore your options together.

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Partnership Fendix x InventIT
Partners

New partnership: Fendix x InventIT for NIS2

by
Ruben
Blog
Five frequently asked questions about NIS2 and the Dutch Cybersecurity Act
Legislation

NIS2 and the Dutch Cybersecurity Act: 5 FAQs

by
Mathijs
Blog
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

by
Mathijs
Download