The short version
- Companies below the thresholds are usually not directly in scope. Customers who are, however, must address supply chain security under § 30 BSIG — and pass that on contractually.
- What is typically required: a committed security level, incident reporting within an agreed window, evidence of implemented measures, and regular verification.
- The questionnaires cover six areas: access protection, backup, updates, incident planning, training and documentation.
- None of it is exotic — it is the basic equipment of properly run IT. What is demanded, however, is evidence rather than assurance.
The most common question smaller companies ask about NIS2 is “does this apply to us?” The most common answer is: probably not directly. And the most common surprise follows three months later, when a large customer's procurement department sends a questionnaire.
How it reaches you
NIS2 obliges entities in scope to address the security of their supply chain, which in Germany sits in § 30 BSIG. Your customer cannot delegate that duty to you — but they can and must secure it contractually. Four instruments are common:
- A committed security level you contractually undertake to maintain.
- Reporting duties: security incidents must be reported within an agreed window — often considerably shorter than you are used to.
- Evidence of implemented measures, sometimes in the form of certifications.
- Verification: compliance with the agreed level is checked regularly, occasionally via an audit clause.
The scope is risk-based and proportionate. An office supplies vendor gets different questions from a service provider with remote access to production systems. If you hold technical access or process data, you land in the more demanding group.
The six areas that get asked about
The questionnaires vary in length but barely in subject. Anyone who can answer these six points cleanly gets through almost all of them:
Access protection
Is multi-factor authentication in place? How are administrator accounts protected? This is where most questionnaires stall — and the point with the best effort-to-effect ratio.
Backup
Are there separate, tested backups with documented restore tests? The decisive word is tested: a backup without an evidenced restore increasingly counts as no backup.
Updates and patches
How quickly are security updates deployed? What is wanted is not a number off the cuff but a described procedure with an owner.
Incident plan
Is there a plan, defined reporting paths and named responsibilities? Two pages are enough — but they have to exist and be findable in an emergency.
Training
Are staff regularly made aware? Evidenced means with a date and an attendance list, not as a good intention.
Documentation
Are the measures documented, do policies exist? This point often decides the rating, because it makes everything else provable.
Which parts sit in the network
Four of the six areas have a technical side that lives in the network and cannot be settled with a policy document:
- Remote access. Everyone reaching your network from outside — staff at home, your IT provider, the machine builder's maintenance link — needs a named, protected path. An open remote access without a second factor is the most common reason a questionnaire comes back.
- Separation inside the network. Guests, production, office and servers on one flat network are hard to defend once somebody asks.
- Traceability. Who changed what, and when? Without a log, the question about the incident plan is hard to answer.
- Currency of the devices. Routers, firewalls and switches are software. A device without updates is an open finding, even when it runs reliably.
The link to the wider regulation — and what segmentation has to achieve in detail — is in our article on NIS2 and segmentation. How we build and support smaller networks is described on the page for smaller companies.
Prepare rather than react
The best time to answer these questions is before the first questionnaire. Not because the answers would be better, but because they are not written under deadline pressure and can be reused for every further customer.
A completed questionnaire is also a sales argument. A supplier who can show the fundamentals are in place becomes the easier choice for a customer in scope — and that increasingly decides framework agreements.
Sources
Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.
- NIS-2: indirect scope via the supply chainopens in a new tab
ComConsult · retrieved 2 August 2026
- NIS2 reaches mid-sized companies through the supply chain: your major customer's questionnaireopens in a new tab
H5M · retrieved 2 August 2026
- Implementing the NIS2 directive: risk management duties under the new BSIGopens in a new tab
Menold Bezler · retrieved 2 August 2026

