Insight
NIS2 for digital suppliers: what changes when your customers are in scope
NIS2 widened EU cybersecurity law from a few thousand operators to a large number of medium and large organisations across many sectors. Even suppliers that are not in scope themselves now receive security questionnaires, contract clauses and incident-reporting expectations from customers that are.
From NIS to NIS2
The original Network and Information Security Directive of 2016 applied to a relatively narrow group of operators of essential services and digital service providers, and member states defined those operators in very different ways. Directive (EU) 2022/2555, known as NIS2, replaced it. Member states had to transpose it into national law by 17 October 2024, with the new rules applying from the following day.
Transposition was uneven. Many member states missed the deadline, and the European Commission opened infringement procedures in late 2024. For companies this means the details still depend on national implementing laws, national registration processes and national authorities, even though the directive sets a common framework.
The direction of travel is nonetheless clear. NIS2 covers more sectors, applies size rules consistently, sets minimum security measures, introduces strict incident reporting timelines and makes management bodies personally accountable for cybersecurity.
Who is in scope
NIS2 lists sectors in two annexes. Sectors of high criticality include energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management provided business to business, public administration and space. Other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing of products such as medical devices, electronics, machinery and vehicles, digital providers such as online marketplaces, search engines and social networks, and research.
Within those sectors, the directive generally applies to medium-sized and large enterprises, meaning organisations with at least 50 employees or annual turnover and balance sheet above 10 million euros. Some entities are covered regardless of size, including providers of public electronic communications networks or services, trust service providers, top-level domain registries and DNS service providers.
Entities are classed as essential or important, largely based on sector and size. The obligations are similar, but supervision differs: essential entities can be supervised proactively, while important entities are mainly supervised after evidence of non-compliance.
- Digital infrastructure
- Cloud computing, data centres, content delivery networks, DNS and top-level domain services, internet exchange points and trust services.
- ICT service management
- Managed service providers and managed security service providers serving business customers.
- Digital providers
- Online marketplaces, online search engines and social networking platforms.
Security measures and management accountability
Article 21 of the directive requires appropriate and proportionate technical, operational and organisational measures, based on an all-hazards approach. The minimum list includes risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition, development and maintenance of systems including vulnerability handling, assessment of the effectiveness of measures, cyber hygiene and training, cryptography and encryption where appropriate, human resources security and access control, and multi-factor or continuous authentication where appropriate.
Management bodies must approve these measures, oversee their implementation and can be held liable for infringements. Members of management bodies are also required to follow training. This matters for suppliers because security questions now reach board level at customer organisations, and procurement teams are expected to show that supplier risk has been considered.
For certain digital infrastructure and ICT service providers, the Commission adopted Implementing Regulation (EU) 2024/2690, which sets out the technical and methodological requirements of these measures in more detail and specifies when incidents are considered significant.
Incident reporting timelines
Entities in scope must notify significant incidents to their national computer security incident response team or competent authority in stages. An early warning is due within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the incident notification. Authorities can request intermediate reports along the way.
Those deadlines are short, and they do not pause because the incident started at a supplier. If a hosting provider, software vendor, managed service provider or agency with administrative access suffers a breach that affects a customer’s services, the customer needs to know quickly and with enough detail to make its own assessment. That is why NIS2-driven contracts increasingly include supplier notification obligations measured in hours rather than days.
What this means for suppliers outside the scope
Many digital agencies, software houses and small hosting or IT providers are not in scope themselves, because of their size or sector. They are still affected through their customers, since supply chain security is one of the required measures. In practice, suppliers see four kinds of request.
- Security questionnaires
- Questions on access control, multi-factor authentication, encryption, vulnerability management, backups, staff training and incident response.
- Contract clauses
- Obligations to notify incidents within a defined number of hours, cooperate with investigations, allow audits and meet specified security controls.
- Access restrictions
- Named accounts, multi-factor authentication, least-privilege access and removal of shared administrator credentials for systems suppliers maintain.
- Evidence
- Policies, certifications such as ISO/IEC 27001 where held, penetration test summaries and records of security updates.
Getting ready as a supplier
A supplier does not need to become a compliance consultancy, but it does need honest, documented answers. Start by listing where you have access to customer systems or data: hosting accounts, content management systems, cloud consoles, CRM administration, analytics, code repositories and email platforms. For each, confirm that access is personal, protected by multi-factor authentication and removed when staff leave or projects end.
Next, write down how you would detect and report an incident affecting a customer, who is responsible and how quickly the customer would be told. A realistic commitment you can meet is more valuable than an ambitious clause you cannot.
Finally, keep software and dependencies you maintain up to date, document backups and recovery tests, and prepare a short security overview that answers the common questionnaire items. Customers in scope are under pressure to show supplier diligence, and suppliers that make this easy become easier to keep.
Penalties and national differences
NIS2 sets maximum administrative fines of at least 10 million euros or 2% of total worldwide annual turnover, whichever is higher, for essential entities, and at least 7 million euros or 1.4% for important entities. Authorities can also issue binding instructions and, for essential entities, take further measures in cases of serious non-compliance.
Because national laws implement the directive, registration deadlines, reporting portals, the authorities involved and some definitions differ between countries. Organisations operating in several member states should check each relevant national law and, for certain digital providers, the rules on main establishment. This article is a general overview and not legal advice.
Questions
When did NIS2 start to apply?
Member states had to transpose it by 17 October 2024 and apply the rules from 18 October 2024, although several national laws came later.
Is a small digital agency in scope of NIS2?
Usually not directly, because of size and sector, unless it provides services such as managed IT or security services at a scale that brings it into scope. It is still affected through customers that are in scope.
How fast must significant incidents be reported?
An early warning within 24 hours of becoming aware, an incident notification within 72 hours and a final report within one month.
Are managed service providers covered?
Yes. Managed service providers and managed security service providers serving business customers are in the ICT service management sector.
Can managers be held responsible?
Yes. Management bodies must approve and oversee cybersecurity measures, can be held liable for infringements and must follow training.
What are the maximum fines?
At least 10 million euros or 2% of worldwide turnover for essential entities, and at least 7 million euros or 1.4% for important entities, whichever is higher in each case.
Does NIS2 apply to financial firms covered by DORA?
For the financial entities it covers, DORA acts as the sector-specific law on digital operational resilience, so its requirements take precedence for those topics.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Complete Digital Transformation — The whole stack, sequenced — brand, web, marketing, CRM, automation, reporting and infrastructure — with benefits measured afterwards rather than projected and forgotten.
- The EU AI Act: what actually applies from 2 August 2026
- Belgium's B2B e-invoicing mandate: the January 2026 big bang
- Passkeys for customer logins: fewer resets, less phishing and the recovery flow you still need
- Password policies that match current guidance: length, breached-password checks and no forced expiry
- All insight articles
Answering NIS2 security questionnaires from customers?
We help digital suppliers tighten access, document incident response and prepare clear security overviews that customers in scope can rely on.
Get in touch