How do you answer a NIS2 supplier questionnaire? A practical guide for SMEs
Published on June 12, 2026 · Updated on August 4, 2026
This article is general information about laws and regulations, not legal advice.
It often starts with an email from the procurement department of a large customer. Subject: "Vendor Security Assessment" or "Supplier information security review". Attached: an extensive questionnaire about your cybersecurity, with the friendly but urgent request to return it completed, with a deadline of a few weeks.
That questionnaire has a concrete reason. Your customer falls under NIS2 and has to assess the risks in its supply chain: the supply-chain duty of care we described earlier. In the Netherlands that obligation becomes enforceable on 15 August 2026 through the Cyberbeveiligingswet (Dutch government news release, 7 July 2026); large organisations are expected to set up their supplier assessments accordingly. Your answers partly determine whether your customer can demonstrate its own compliance. And so, very practically: whether you keep that customer. Unsure what NIS2 really requires of you, and what is merely a myth? First read what the NIS2 supply-chain duty of care really requires.
This guide covers four themes that follow directly from the NIS2 measures of Article 21(2) (patch management and vulnerability management, access security with MFA, incident handling and the supply chain) and (more importantly) how to give an answer that the assessor at your customer (procurement, security or an auditor) takes seriously.
Why your large customers (have to) ask these questions
NIS2 requires essential and important entities to assess the security risks of their direct suppliers and to set appropriate requirements for them: that follows from Article 21(2)(d), the provision on supply-chain security that supplier questionnaires often refer to, read together with Article 21(3), which requires entities to take into account the vulnerabilities of each direct supplier. The reasoning is simple: an attacker who cannot get through the front door of the hospital or the grid operator tries it via a supplier. The regulator therefore looks not only at the organisation itself, but also at how it manages its chain. What that duty of care entails exactly is explained on NIS2 supply-chain duty of care.
For you as a supplier that means two things. First: expect a recurring cycle (often yearly) and with new contracts the questionnaire may be part of the arrangements from the start; the frequency differs per customer. Second: your answers become part of your customer's compliance file. A vague answer ("we take security seriously") is useless to your customer's auditor and invites follow-up questions. A concrete, substantiated answer makes you exactly the kind of supplier procurement is happy to renew with.
On the procurement side the message is now explicit: a completed questionnaire alone is paper, a snapshot. The Dutch NCSC accordingly advises procuring organisations to question the answers and verify them with their own investigation. A supplier who includes an external measurement of their own accord gives the auditor more than the questionnaire itself: an independent observation instead of a self-declaration.
Do you have to answer, and what if you don't?
Strictly legally, no: NIS2 (in the Netherlands the Cyberbeveiligingswet) places the obligation of Article 21(2)(d) on your customer, not directly on you. Your duty to answer arises through the contract and the procurement policy of that customer.
In practice it is different. A customer who receives no answers, or only vague ones, can hardly do anything but classify you as an elevated risk, with possible consequences at contract renewal and in new tenders.
Tactically there is room: asking for a delay or for clarification is fine. A well-substantiated answer two weeks later is worth more than an empty form on time.
The 4 themes in a Vendor Security Assessment that follow directly from the NIS2 requirements
1. How is your patch management and vulnerability management organised?
What they are really asking: do you know which systems you have exposed to the internet, how quickly do you close known vulnerabilities, and can you prove it?
Weak answer: "Updates are installed regularly."
Strong answer: describe your process in three sentences and attach evidence. For example: "Our external systems are scanned for vulnerabilities monthly. We remediate critical findings within 14 days, others within 30 days. Attached: last month's scan report with remediation status." (deadlines for illustration) A dated report from an independent scan says more than a page of prose. Start by understanding what an attacker sees of your domain: that is exactly the same outside view your customer's auditor assesses.
2. Do you use Multi-Factor Authentication (MFA) on all systems?
What they are really asking: can a stolen or leaked password of one of your employees lead to access to systems, and thereby possibly to our data?
Strong answer: be specific about where MFA is and is not enabled. "MFA is mandatory on email, VPN, our administration system and all management interfaces. For [system X] MFA is not yet available; this system is only reachable from office IP addresses." Honesty about an exception, with a compensating measure, comes across as more credible than an unqualified "yes, everywhere". An experienced auditor will ask follow-up questions.
3. What is your procedure in the event of a data breach or ransomware attack?
What they are really asking: if you get hit, how quickly will we know? NIS2 organisations themselves have tight reporting deadlines: an early warning within 24 hours and an incident notification within 72 hours (Article 23 of the NIS2 directive). When an incident hits the chain, they can only meet them if their suppliers report quickly.
Strong answer: mention your internal response plan, but above all the commitment towards the customer: "In the event of an incident that may affect your data or services, we inform your designated contact within 24 hours via [channel]. Our incident response plan is available for review on request; we rehearse it annually." If you do not have a response plan yet: the Dutch NCSC (which the Digital Trust Center merged into in early 2026) publishes a free step-by-step guide for an incident response plan that works well for SMEs.
4. How do you verify the security of your own (sub)suppliers?
What they are really asking: the chain does not stop with you. Your hosting provider, your software vendors and your IT administrator are just as relevant to our risk analysis.
Strong answer: make a simple list of your critical suppliers (hosting, email, accounting software, IT management) and describe per supplier how you safeguard security: certifications (ISO 27001, SOC 2), data processing agreements, or your own periodic checks. You do not have to audit Microsoft: referring to their certifications is, in practice, a common approach.
Beyond these four themes, expect questions about backups and recovery, encryption, access management and offboarding, security awareness, certifications, cyber insurance and business continuity. So build a reusable base file with your standard answers and supporting evidence, so the next questionnaire is not a new project. If you are ISO 27001-certified yourself, your certificate is the starting point and the above serves as additional, current evidence.
How do you give an answer your customer's assessor takes seriously?
Three principles make the difference between a questionnaire that bounces between departments and one that is accepted in one go:
| Principle | What it means | Example |
|---|---|---|
| Claim nothing you cannot show | Every "yes" needs a document, report or setting behind it. | Scan report, MFA policy, response plan, supplier list. |
| Be honest about what is not (yet) in order | A planned improvement with a date is acceptable; an exposed overclaim is not. | "MFA on system X follows in Q3; until then IP restriction applies." |
| Provide dated, repeatable evidence | A snapshot ages; the auditor wants to see you do it structurally. | Recent, repeated reports instead of one report from 2024. A pentest and a continuous scan complement each other. |
Please note: your answers may be attached to the contract as an annex and thereby acquire contractual effect. So only commit to deadlines you can demonstrably meet internally, and not the example deadlines from this article if they do not fit your organisation.
The pattern behind all four questions is always the same: demonstrate, don't assert. And that is exactly why it pays to build the evidence up structurally, instead of scraping it together per questionnaire. Whoever receives a dated, independent report of their external attack surface every month answers question 1 with a single attachment from now on, and for question 2 has supporting evidence that no management interfaces were found exposed to the internet on the scan date. The MFA policy itself remains your own documentation.
Conclusion
A NIS2 supplier questionnaire is above all an opportunity to stand out. Whoever describes concrete processes and includes dated evidence stands out positively with their customer.
Exposentry delivers that evidence as a service: monthly, independent scan reports of your domain and infrastructure that you attach directly to the questionnaire. Those reports form defensible evidence of your basic hygiene; the compliance judgment itself remains with your customer and their auditor. The reports are built on OpenKAT, the open-source security scanner that originates from the Dutch government and that Edward Hasekamp contributes to. So your customer's auditor can verify how the measurement is produced. See the plans and pricing or start today with a first scan, so you have the report ready before the next questionnaire arrives.
Are you a large organisation receiving questionnaires back from suppliers that you want to verify? Then have a look at supplier monitoring.
Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.