Skip to content
CONFIGLANE

Regulation · Smaller companies

NIS2 may not apply to you — but it does to your largest customer

The letter does not come from a regulator but from your largest customer's procurement department. It contains an information security questionnaire, a deadline, and a note that the answers become part of the framework agreement.

By ConfiglanePublished 5 min readSmall Business

The short version

  • Companies below the thresholds are usually not directly in scope. Customers who are, however, must address supply chain security under § 30 BSIG — and pass that on contractually.
  • What is typically required: a committed security level, incident reporting within an agreed window, evidence of implemented measures, and regular verification.
  • The questionnaires cover six areas: access protection, backup, updates, incident planning, training and documentation.
  • None of it is exotic — it is the basic equipment of properly run IT. What is demanded, however, is evidence rather than assurance.

The most common question smaller companies ask about NIS2 is “does this apply to us?” The most common answer is: probably not directly. And the most common surprise follows three months later, when a large customer's procurement department sends a questionnaire.

How it reaches you

NIS2 obliges entities in scope to address the security of their supply chain, which in Germany sits in § 30 BSIG. Your customer cannot delegate that duty to you — but they can and must secure it contractually. Four instruments are common:

  • A committed security level you contractually undertake to maintain.
  • Reporting duties: security incidents must be reported within an agreed window — often considerably shorter than you are used to.
  • Evidence of implemented measures, sometimes in the form of certifications.
  • Verification: compliance with the agreed level is checked regularly, occasionally via an audit clause.

The scope is risk-based and proportionate. An office supplies vendor gets different questions from a service provider with remote access to production systems. If you hold technical access or process data, you land in the more demanding group.

The six areas that get asked about

The questionnaires vary in length but barely in subject. Anyone who can answer these six points cleanly gets through almost all of them:

  1. Access protection

    Is multi-factor authentication in place? How are administrator accounts protected? This is where most questionnaires stall — and the point with the best effort-to-effect ratio.

  2. Backup

    Are there separate, tested backups with documented restore tests? The decisive word is tested: a backup without an evidenced restore increasingly counts as no backup.

  3. Updates and patches

    How quickly are security updates deployed? What is wanted is not a number off the cuff but a described procedure with an owner.

  4. Incident plan

    Is there a plan, defined reporting paths and named responsibilities? Two pages are enough — but they have to exist and be findable in an emergency.

  5. Training

    Are staff regularly made aware? Evidenced means with a date and an attendance list, not as a good intention.

  6. Documentation

    Are the measures documented, do policies exist? This point often decides the rating, because it makes everything else provable.

Which parts sit in the network

Four of the six areas have a technical side that lives in the network and cannot be settled with a policy document:

  • Remote access. Everyone reaching your network from outside — staff at home, your IT provider, the machine builder's maintenance link — needs a named, protected path. An open remote access without a second factor is the most common reason a questionnaire comes back.
  • Separation inside the network. Guests, production, office and servers on one flat network are hard to defend once somebody asks.
  • Traceability. Who changed what, and when? Without a log, the question about the incident plan is hard to answer.
  • Currency of the devices. Routers, firewalls and switches are software. A device without updates is an open finding, even when it runs reliably.

The link to the wider regulation — and what segmentation has to achieve in detail — is in our article on NIS2 and segmentation. How we build and support smaller networks is described on the page for smaller companies.

Prepare rather than react

The best time to answer these questions is before the first questionnaire. Not because the answers would be better, but because they are not written under deadline pressure and can be reused for every further customer.

A completed questionnaire is also a sales argument. A supplier who can show the fundamentals are in place becomes the easier choice for a customer in scope — and that increasingly decides framework agreements.

Sources

Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.

FAQ

Frequently asked questions about the NIS2 supply chain

We have 20 staff. Do we have to register?

Very probably not. The thresholds sit considerably higher, and a registration duty only arises from direct scope. The classification is nevertheless a legal question with sector-specific exceptions — settle it cleanly once and you also have a dependable answer for the questionnaire.

Can we ignore the questionnaire?

Rarely in practice. It usually comes with a deadline and is tied to the framework agreement. An unanswered security enquiry is a risk your customer has to document — and the simplest way to resolve that risk is a different supplier.

Do we need ISO 27001 certification?

In most cases no. Certifications are one possible form of evidence, not the only one. For smaller suppliers, traceable evidence is usually enough: a description of the measures, records of backup tests and training, current network documentation. If a customer explicitly demands a certificate, that becomes a commercial judgement.

What does preparation cost?

It depends on the starting point. With multi-factor authentication, tested backups and clean separation in the network already in place, it is largely documentation work. If one of those is missing, the questionnaire is not the problem but the occasion — and the measure would have been due anyway.

Next step

Does this hold for your network?

An assessment answers the question against your infrastructure rather than an example — ending in a first dependable change.

Request an assessment

Assessment → first dependable change