NIS2 guide for suppliers
What the Dutch Cybersecurity Act asks of your customers, and why you feel it as a supplier. Not legal advice, but an explanation in plain language, for anyone who found a questionnaire on their desk.
Do I have to meet NIS2 as a supplier?
Usually you do not fall under it yourself. But your customer does, and passes the requirements on to you through the contract.
ReadMy customer sent a security questionnaire. Now what?
What such a list is, why it landed on your desk, and how to answer it without losing two days to it.
ReadWhen does the Dutch Cybersecurity Act take effect?
The law applies from 15 August 2026. What that means for your customers, and what it means for you through them.
ReadWhich sectors fall under the Dutch Cybersecurity Act?
Eighteen sectors, split into essential and important, with a size threshold. And whoever falls under it questions their suppliers.
ReadThe Dutch Cybersecurity Act is coming. Where do I start as a supplier?
Four steps you can take this month, in order of effect. Most of them cost attention rather than budget.
ReadWhat are the ten NIS2 duty of care measures?
Article 21(2) lists ten topics. Every security questionnaire you receive is a translation of them.
ReadWhat does NIS2 ask for in risk analysis and security policy?
A policy adopted by the board, a risk assessment from the past year, one responsible person, and a view of your critical systems.
ReadHow does the 24-hour report for a cyber incident work?
The law works with a first report within 24 hours. Your customers pass that deadline on to you in their contracts, and you only make it with a prepared procedure.
ReadWhat requirements apply to backups and business continuity?
Automatic backups, at least one copy out of reach of the network, a yearly restore test and a plan to keep working without IT.
ReadDo I have to assess my own suppliers too?
Yes. The same supply chain duty of care your customer puts on you applies a link further down to you as well.
ReadWhat does a customer expect from my patch policy and maintenance?
Updates on a fixed rhythm, an up-to-date inventory, periodic vulnerability scanning, and no more systems without support.
ReadHow do I show that my security actually works?
Not whether measures exist, but whether they do what they are meant to do. Test yearly, record it, and discuss the outcome with the board.
ReadIs security training mandatory for staff and directors?
For organisations under the law, director training is even an explicit obligation. For everyone: most incidents start with a click.
ReadWhat encryption does NIS2 expect from a supplier?
Encrypted laptops and phones, encrypted connections, and encrypted backups. It usually does not have to get more exotic than that.
ReadWhat belongs in access control under NIS2?
Access based on what someone needs, withdrawn the same day when they leave, checked yearly, and knowing which equipment sits with whom.
ReadIs MFA mandatory under NIS2?
The law names multi-factor authentication explicitly. It is the first question on virtually every security questionnaire, and the cheapest one to answer well.
Read