Last updated: July 2026
Most conversations about the EU’s NIS2 Directive start with the same question: “Are we in scope?” It’s the wrong place to begin. Because even if NIS2 never names your business directly, there’s a good chance it’s already changing what your customers expect from you — and what your own suppliers can get away with.
This is the section of NIS2 that really surprises companies. It doesn’t only focus on the major players in critical sectors; it extends down the supply chain, making every regulated company responsible for enforcing security standards among their partners. So, if you sell to, buy from, or are even close to a regulated organization, you’ll want to pay attention to this article.
The provision that changes everything
Buried in NIS2’s risk-management requirements is a deceptively short instruction: in-scope organizations must manage the security risks in their supply chains and their relationships with direct suppliers and service providers.
That single requirement has an enormous ripple effect. A regulated company can no longer treat its own perimeter as the boundary of its responsibility. Its security is only as strong as the vendors plugged into it—the cloud host, the managed IT provider, the software supplier, the logistics platform, the payroll system. So the law forces regulated entities to look hard at who they depend on, assess those dependencies, and hold them to a standard.
And here’s the mechanism that matters: regulated companies don’t have legal authority to fine their suppliers, so they pass the obligations down the only way they can — through contracts, security questionnaires, audits, and certification demands. The duty starts at the top with the regulated entity, but it cascades outward to everyone they do business with.
Why this pulls in companies that “aren’t in scope”
NIS2 generally applies directly to medium and large organizations—roughly 50 or more employees, or over €10 million in turnover—operating in one of its covered sectors. By that measure, a great many small and mid-sized businesses are technically outside the law.
But “outside the law” and “outside the impact” are two very different things.
Imagine a small software vendor with just 25 employees, specializing in a unique tool designed for hospitals. While this vendor isn’t big enough to face direct regulations, the hospitals they serve definitely are. Now, these hospitals have a legal obligation to keep an eye on their supplier risks. So, they send over a security questionnaire, asking for details on encryption methods and access controls, looking for proof of an incident-response plan, and seeking contractual guarantees about breach notifications. Although the vendor wasn’t specifically mentioned in NIS2, it’s clear that they are now operating under its influence in a very real way.
Multiply that across every critical sector—energy, transport, water, healthcare, banking, manufacturing, and digital infrastructure—and you get a picture of how NIS2 quietly raises the security bar for hundreds of thousands of businesses that never appear in the legal text. The directive regulates the few; the market enforces it on the many.
What regulated buyers will start asking you for
If you supply an in-scope organization, expect the requests to land in some combination of these forms:
- Security questionnaires covering your controls — access management, encryption, patching, backups, multi-factor authentication, and more.
- Evidence, not assurances. Increasingly, buyers want proof: policies, certifications, audit reports, penetration-test summaries. “Trust us” no longer clears the bar.
- Contractual security clauses, including commitments on how fast you’ll notify them of an incident that affects their data or services.
- The right to audit, or at least to require independent certification such as ISO 27001 or an equivalent recognized standard.
- Subcontractor transparency, because your suppliers are now part of their extended supply chain too.
For a business that’s ready, this is a routine procurement step. For one that isn’t, it can mean lost contracts—quietly, without ever being told that a failed security review was the reason.
The flip side: your suppliers are now your problem
The cascade flows in both directions. For regulated entities, ensuring supply chain security isn’t just about checking off a list—it’s a real concern that carries risks and liabilities. In fact, some of the most significant breaches we’ve seen lately didn’t happen through the main entrance; they slipped in through a trusted vendor, whose access turned into an attacker’s gateway.
Under NIS2, you’re expected to understand and manage that exposure. In practice, that means knowing which suppliers are critical to your operations, what access they have to your systems and data, how secure they actually are, and what happens if one of them is compromised or goes offline. A supplier’s breach can become your incident—and your reporting obligation, your regulator’s attention, and potentially your penalty.
Turning the obligation into an advantage
The businesses that handle this well don’t treat it as a compliance burden—they treat it as a competitive edge. Being demonstrably secure becomes a reason to win contracts rather than a hurdle to clear. Here’s how to get there, whichever side of the relationship you’re on.
If you sell to regulated organizations:
- Get ahead of the questionnaire. Get ready for what’s ahead by gathering your evidence now—think security policies, access controls, a solid incident-response plan, and, if possible, a well-regarded certification like ISO 27001.
- Tighten the basics first. Multi-factor authentication, tested backups, patching, and clear access management answer most of what buyers ask about, and they’re the highest-value security investments anyway.
- Be ready to commit to incident notification. Buyers will want to know how quickly you’ll tell them if something goes wrong. Have a clear, realistic answer.
- Make security part of your sales story. When a customer’s procurement team is comparing you against a competitor who can’t pass the review, your readiness wins the deal.
If you’re a regulated buyer (or expect to be):
- Map your suppliers and rank them by criticality. You can’t secure what you haven’t identified. Focus first on the vendors with deep access or single points of failure.
- Assess before you onboard, and reassess regularly. Security isn’t a one-time checkbox at contract signing.
- Write security into your contracts. Notification timelines, minimum standards, audit rights, and subcontractor disclosure all belong in the agreement, not in a hopeful conversation later.
- Plan for a supplier incident. Decide in advance how you’d detect, contain, and report a breach that originates with a vendor.
The bottom line
NIS2’s supply-chain provisions quietly rewrote the rules of doing business in the EU. Regulated companies are now obliged to police the security of everyone they depend on — and the only practical way they can is by pushing those expectations outward through every contract they sign.
The result is a market where cybersecurity has become a condition of trade, regardless of whether the law names you. The businesses that recognize this early will find doors opening: contracts won, customers reassured, and partnerships strengthened. The ones that wait will discover the cost of inaction the hard way — in deals that slip away without explanation.
You don’t have to be in scope to be affected. You just have to be in someone’s supply chain. And almost everyone is.
This article is general information, not legal advice. NIS2 obligations depend on your specific sector, size, and the national law of each country you operate in—and those national rules are still evolving. Verify your position against the relevant national authority or a qualified advisor before acting.
