NIS2 and the supply chain: what to actually ask your suppliers
Article 21 explicitly includes supply-chain security. A questionnaire alone doesn’t demonstrate it.

NIS2 treats the supply chain as part of a company’s own risk perimeter, not someone else’s problem. Article 21 explicitly requires measures covering the security of relationships with direct suppliers, and the responsibility for managing them stays with the company that chose them — even when the supplier itself falls outside the directive’s scope.
A questionnaire is not a verification
Most companies manage supplier risk with an annual questionnaire: closed questions, self-declared answers, no follow-up. That is a record of intentions, not a control. NIS2 does not ban the questionnaire, but anyone using it as the only tool will discover the difference only after an incident, when they have to explain to their management body — and potentially to the regulator — what the trust placed in that supplier was actually based on.
A more solid programme sorts suppliers by real criticality (system access, data handled, how replaceable they are) before deciding the level of verification: for the small number of genuinely critical suppliers, a paper review is not enough — an independent check, built into the contract, with audit rights and cascading incident-notification duties, is needed.
What belongs in the contract, not just the questionnaire
The security requirements that matter end up in the contract, not in an appendix nobody rereads after signing: notification timelines for incidents touching your systems or data, audit rights, minimum security obligations proportionate to the access granted, and clear consequences for non-compliance. Without this, the initial due diligence is a formality — reassuring at signing, but not protective over the following three years.
The takeaway
Supply-chain security is not demonstrated by a filing cabinet of completed questionnaires. It is demonstrated by contracts that impose verifiable obligations, and by a short list of genuinely critical suppliers where verification goes beyond self-attestation.



