NIS2 and your supply chain: why the questionnaire lands on your desk too
Many organisations only check whether they themselves fall under the Dutch Cybersecurity Act. That is half the question. The law obliges the organisations that do fall under it to assess the security of their suppliers, and that requirement travels down the chain. If you deliver software, hosting or managed services to a hospital, a municipality or an energy company, the questionnaire is coming your way, whether or not you fall under the law yourself.
The Dutch Cybersecurity Act (the national implementation of NIS2) passed on 7 July 2026 and takes effect on 15 August 2026, with no transition period. Supply-chain security is one of the explicit elements of the duty of care. For the broader explainer of who falls under it and what the law requires, see Dutch Cybersecurity Act (NIS2): do you fall under it and what changes?
The law does not stop at your customer
The duty of care in the Dutch Cybersecurity Act lists a number of areas that an organisation must cover in any case. One of them is the security of the supply chain. That is not a footnote. It means that an organisation under the law must not only have its own systems in order, but must also demonstrably assess whether its suppliers do.
The reasoning is practical. Many major incidents of recent years started with a supplier: a managed-service party with too much access, a software package with a vulnerability, a connection nobody was watching any more. An organisation that locks its own door but hands the supplier a key is still exposed. That is why the law places responsibility with the buying party as well.
Why you get the questionnaire, even if you don't fall under it
This is where the surprise lies for many smaller suppliers. You can stay well under the size thresholds and sit in a sector that isn't designated. You then don't fall under the law directly. But your customer may well fall under it, and that customer is now obliged to secure the security of its suppliers.
Your customer solves that in the only way that suits them: by passing the requirement on to you. In practice this happens in three ways, often at once.
- A supplier questionnaire. A survey of your security, from access control to incident process, that you must complete and return.
- Tightened contract terms. New or renewed contracts get clauses on security measures, incident reporting deadlines and the right to audit.
- Evidence requirements. Increasingly, concrete proof is requested, such as a recent penetration test report or a certification, rather than just a completed questionnaire.
The result is that the law reaches you through the chain. You won't feel a fine from the regulator, but you will feel the customer who, without a satisfactory answer, doesn't renew or doesn't award. For a SaaS vendor or an IT service provider, that is just as hard commercially.
Getting the supplier questionnaire from a customer under NIS2? A pentest report is the most widely accepted proof that your technical measures work, and answers the hardest questions in one go.
Book a free intake →What such a questionnaire asks
Questionnaires differ from customer to customer, but they all draw on the same duty-of-care topics. The table below shows the most common blocks, and what each block is really about.
| Topic | What the customer wants to see |
|---|---|
| Policy & governance | An information security policy that is actually lived, with a named responsible person |
| Access & authentication | Role-based access, multi-factor authentication, deprovisioning of accounts that leave |
| Incident & reporting | A process to detect and report incidents, with timelines that align with the customer's own reporting obligation |
| Backup & continuity | Demonstrably tested backups and a recovery plan, not just a backup schedule on paper |
| Proof that it works | A recent, independent penetration test report and a retest statement of the critical systems |
You answer the first four blocks with policy and procedures. The last block is where a completed questionnaire falls short. "We take security seriously" is not proof. An external party that tried to get in and recorded the result is.
"We're too small for NIS2" is no longer the answer
Until recently, "we don't fall under it ourselves" was an adequate response to a customer's security question. Under the Dutch Cybersecurity Act that argument works against you. Your customer cannot accept it, because their duty of care obliges them to look at you precisely. The more critical you are in their process, the heavier the enquiry.
That is not bad news if you turn it around. A supplier who answers the questionnaire quickly, completely and with proof lowers the barrier to doing business with them. In a market where more and more clients run the same enquiry, a well-substantiated security story helps you stand out.
NIS2 obliges not only the organisations that fall under it, but through them their suppliers too. If you deliver something critical to such a customer, the questionnaire will come. And you answer it more convincingly with a test report than with a reassurance.
Where the penetration test covers the questionnaire
The Dutch Cybersecurity Act never mentions the word "penetration test" literally, no more than the NIS2 directive does. Yet a pentest keeps coming back in the chain, and that makes sense. A good pentest report answers the question a customer can least verify for themselves: does this supplier's security really work? It shows in black and white:
- Which vulnerabilities actually existed at the time of testing
- Which of those were genuinely exploitable, not just theoretical
- Which measures demonstrably held up
- Which findings were resolved after remediation, via the retest
That makes a pentest report the strongest answer to the evidence block of the questionnaire. It does not replace the organisational arrangements, such as the reporting chain and processing agreements, but it covers the part you can't convincingly close with a form. Want to understand the basics first? Read what a penetration test actually is. For the cadence there is how often you should have a penetration test done, and for the price what a penetration test costs.
Then the supply-chain requirement runs alongside existing frameworks. Healthcare institutions often assess suppliers against NEN 7510, municipalities against ENSIA and the BIO, which we covered in NIS2 and municipalities: what does the regulator expect?. The underlying question is the same in all cases: can you demonstrate that your measures work?
What you can do now as a supplier
You don't have to wait until the first questionnaire arrives. In fact, whoever gets ahead of the enquiry negotiates from a stronger position. A workable first step:
- Map which customers fall under NIS2. Healthcare, government, energy, transport, digital infrastructure and their suppliers are the first to start asking.
- Determine how critical you are to them. The deeper you sit in a primary process, the sooner and heavier the enquiry comes.
- Get your own basics on record. Policy, access control with multi-factor authentication, an incident process and tested backups. That is the bulk of every questionnaire.
- Arrange the proof for the technical side. Plan a penetration test on your most critical application or service and keep the report and the retest statement, so you have them ready the moment a customer asks.
- Turn it into a sales argument. A supplier who answers the questionnaire completely in one go wins time and trust with the buyer.
If you fall under the law yourself too, this is only one side of your obligations. The full order of steps is in the Dutch Cybersecurity Act has passed: your action list to 15 August.
Conclusion
The question "do we fall under NIS2?" is not the only one that matters. The Dutch Cybersecurity Act works through the entire chain, and so it also reaches suppliers who thought themselves out of range. Whoever delivers to an organisation that does fall under the law gets the questionnaire, the contract clauses and the request for proof.
That proof is the hardest thing to close with a form. An independent penetration test, with a report and retest statement, gives the answer that actually convinces a customer. That turns the questionnaire into a chance to win the work. Not sure where to start? A free 30-minute intake gives clarity on your situation, with no obligation.
Proof that convinces the chain.
A manual penetration test on your critical service, with a report and retest statement you can send straight back as your answer to the supplier questionnaire. Fixed price, retest included.
Book free intake →