Skip to main content
NIS2

NIS2: how supply chain rules reach you anyway

Your firm is below the NIS2 size thresholds, but your regulated clients still ask you for evidence. Here is why, and what they expect.

L'équipe Vigicap5 min read

One of your regulated clients sends you a twelve-page supplier security questionnaire about your password policy, your continuity plan and your own subcontractors. You never thought NIS2 could apply to a firm your size, and a quick calculation confirms you are nowhere near its thresholds. The questionnaire arrives anyway, and the contract renewal depends on it.

The client has not made a mistake. This is the mechanism by which NIS2 reaches companies it does not regulate directly — and it will happen again with other clients over the coming months.

Why does a regulated client care about your security?#

Because the directive obliges it to. Article 21 of Directive (EU) 2022/2555 — NIS2 — lists the areas of risk-management measures a regulated entity has to implement, and supply chain security is one of them. In practice, the regulated entity must take into account the vulnerabilities specific to each of its direct suppliers and the quality of their cybersecurity practices — not only its own.

Before going further, the three-question test — sector, size, exceptions — is set out in Am I in scope of NIS2?.

An IT provider is not a supplier like any other in that calculation. It holds administrator access to the client's infrastructure, often with long-lived credentials and visibility across several systems at once. The most frequently cited example remains the 2021 attack on the software vendor Kaseya: its remote monitoring product, used by managed service providers to administer their own clients, became the way in for a cascading ransomware campaign — hitting companies that had no direct relationship with Kaseya at all. That is precisely the scenario Article 21 asks a regulated entity to anticipate among its suppliers.

Who is actually subject to NIS2?#

Two cumulative criteria: sector of activity, and size. Annexes I and II of the directive set out a closed list of sectors — energy, health, transport, banking, digital infrastructure, waste management, manufacturing, and a dozen others. A company outside those sectors is out of scope, whatever its size.

For those inside a listed sector, Article 2 adds a second filter: the entity must at least reach the size of a medium-sized enterprise within the meaning of European Recommendation 2003/361/EC — in practice, at least 50 employees, or more than EUR 10 million in both turnover and annual balance sheet total. Below that, the company stays out of scope, apart from the targeted exceptions the text provides for (sole provider of a service in a Member State, public network operator, and so on).

Managed service providers are not a blind spot in the text: in the category covering business-to-business ICT service management, Annex I explicitly names managed service providers (MSPs) and managed security service providers (MSSPs) as entities in scope.

So why is a fifteen-person firm concerned anyway?#

It is not, within the meaning of Article 2 — and that has to be said plainly, because a firm that goes and checks the text and finds itself below the thresholds will, rightly, distrust everything else it is told if it was first told the opposite.

MSPs fall within NIS2's scope as a category — Annex I names them explicitly, alongside managed security service providers. But the size thresholds in Article 2 — at least 50 employees, or more than EUR 10 million in both turnover and balance sheet total — leave most small provider firms outside the directive's direct scope. They are affected by another route: the supply chain diligence obligations the directive places on their regulated clients (Article 21), not by the directive itself.

That distinction explains the questionnaire at the top of this article. The client is not asking you to comply with NIS2 — the directive is not addressed to you. It is asking you for evidence that you will not be the weak link its own compliance depends on.

France shows how far along the client side already is: ANSSI, France's national cybersecurity agency, is already inviting future essential and important entities to come forward on its MonEspaceNIS2 portal, without waiting for transposition to be complete. Regulated clients are not discovering the directive; they have been inside it for a while, and they are working through their own obligations, including the one that involves you. NIS2 is an EU directive, but each Member State transposes and supervises it in its own way — so the exact registration mechanism your clients face depends on the country they operate in.

What will a regulated client actually ask you for?#

Three things, almost always in that order. A supplier security questionnaire, when the relationship starts and then at each renewal — passwords, MFA, backups, incident handling, the subcontractors you use yourself. A contractual clause committing you to security obligations and to notification if an incident on your side affects the client's data. And, for the clients furthest along in their own compliance work, an audit right or the ability to request evidence at any point.

None of this is optional for the client: it is the client who has to document, for its own regulator, that it has assessed the security of its critical suppliers. If it cannot answer for you, it cannot answer for itself.

How do you answer once for your whole client base, rather than client by client?#

By building a single reusable evidence file instead of filling in each questionnaire from scratch. The questions overlap from one regulated client to the next — nearly all of them ask the same thing about MFA, backups and incident handling, in different words. The right answer is not to treat each questionnaire as a fresh investigation, but to keep the real state of your own practices, and of the ones you run for your clients, up to date continuously — so you never start from a blank page when the next one lands.

It is also the moment to treat your own firm the way you treat your SME clients: an assessment of your maturity, an action plan on the gaps, and a file that holds up in front of a client asking precise questions.

Vigicap offers that assessment — the same objectives from ReCyF, the cyber framework published by ANSSI, that you already run your clients through, applied this time to your own organisation, during the free trial.

TopicsNIS2MSPsubcontractingsupply chain
NIS27 min

NIS2: a guide for IT service providers

Who NIS2 covers, what it concretely requires, the incident notification deadlines — and how an IT service provider turns all of it into an offer.