NIS2: What It Requires From Your Customer, and Why You Got the Questionnaire
NIS2 is by far the regulation driving the most security questionnaires across Europe right now.
NIS2 (EU Directive 2022/2555) raises the common level of cybersecurity across the EU, replacing the original 2016 NIS Directive and expanding coverage to eighteen sectors. Obligated companies are classified as "essential" or "important" entities and must implement ten risk-management measures (Article 21.2) plus incident notification obligations with strict deadlines: 24-hour early warning, 72-hour notification, and a final report within one month (Article 23).
The reason you received a questionnaire is almost always Article 21.2(d): supply chain security. Large companies cannot audit hundreds of suppliers individually, so they push the obligation down via a questionnaire and a contract clause.
Transposition timelines vary by country — the EU deadline was 17 October 2024, and many states are still finalizing their laws. Germany already has its national law in force: NIS2UmsuCG took effect on 6 December 2025, with no transition period, affecting around 29,500 companies, enforced by the BSI.
Who does this apply to?
Directly: essential and important entities in the listed sectors, generally companies above certain size thresholds. Indirectly — likely your case: any supplier to one of those entities, regardless of your own company’s size, via Article 21.2(d) and your contract.
Typical questions
Do you perform periodic information security risk analysis?
art. 21.2.a
Do you have a documented incident response plan?
art. 21.2.b
Do you assess your suppliers’ security before engaging them?
art. 21.2.d
Is MFA enforced for remote access?
art. 21.2.j
Evidence you’d need
- Up-to-date risk register
- Incident response plan
- Supplier evaluation procedure
- MFA configuration screenshot
Does your questionnaire cite NIS2 articles?
Upload it and we’ll show you, article by article, what you cover and where the gaps are.
Analyze my questionnaire for freeFAQ
Does NIS2 apply directly to my SME?
Maybe not — but it doesn’t matter for the questionnaire. It reaches you by contract, because your customer is obligated and passes that obligation down the supply chain.
