Protect//guide // NIS2
Supplier to an NIS2-regulated company? What you will be asked for
Companies covered by NIS2 must check the security of their suppliers. What this means for software, IT, maintenance and equipment companies that work with them.
Updated: 02.10.2026 · ~6 min read
Among the minimum measures NIS2 imposes on essential and important entities is supply chain security (art. 21(2)(d) of the NIS2 Directive, transposed in Romania by GEO 155/2024). Entities must take into account the vulnerabilities of each direct supplier, the quality of its products and security practices, and the way it develops its products. In practice, the law's requirements reach suppliers through contracts, even when the suppliers are not covered directly.
Who it concerns
Any company with access to the systems, data or equipment of an NIS2 entity, or that delivers something critical to its operations:
- software development companies and integrators;
- IT service, administration and helpdesk providers;
- maintenance companies for industrial equipment with remote access;
- suppliers of network equipment, video cameras or access control;
- accounting, payroll or archiving firms that work inside the client's systems.
If your company is itself a medium-sized or large managed ICT service provider (MSP or MSSP), the situation is different: you are covered by NIS2 directly. You can check with the NIS2 simulator.
What clients will send you
Security questionnaires
Lists of questions about your practices: how you manage passwords and access, whether you use multi-factor authentication, how you back up, how you train staff, what you do in an incident. Some run to dozens of questions and ask for attached evidence.
New contract clauses
- a duty to notify the client of incidents that may affect it, within a short deadline compatible with the client's own reporting deadlines to DNSC;
- rules for access to the client's systems: named accounts, access only when needed, logging;
- prior approval of subcontractors;
- the client's right to verify security measures;
- where data is stored and how it is returned or deleted when the contract ends.
Requests for evidence
The security policy, the result of the last restore test, the list of people with access to the client's systems, training records. Some large clients may ask for certifications such as ISO/IEC 27001, especially for critical services.
What you can prepare now
- a short, realistic security policy that you actually apply;
- multi-factor authentication on email, internal systems and any access to client systems;
- named accounts, no shared accounts, and a procedure for disabling access when someone leaves;
- a tested backup with an off-site copy;
- an incident procedure that includes notifying affected clients;
- for software companies: separate development and production environments, dependency checks, code review and handling of reported vulnerabilities;
- a file with all of the above, easy to send when the first questionnaire arrives.
A supplier that answers the questionnaire within a few days, with concrete documents, gains time and the client's trust.
We help you prepare the policies, the technical measures and the questionnaire answers; details on the NIS2 page. If you are not sure whether your company is covered directly, the guide Essential or important entity? explains the classification rules.
Received a security questionnaire from a client?
We help you answer it correctly and put the missing measures in place, without paperwork made only for the file.