NIS2 makes your security evidence a condition of the customer's contract
Published September 30, 2026·4 min read
The first sign that NIS2 has reached your organisation will rarely be a notice from your own regulator. It will be a supplier questionnaire attached to a customer renewal, a security schedule added to a draft contract, or a procurement email asking whether you are NIS2 compliant before the deal can close. Gerard Brophy, chief revenue officer of Climb Channel Solutions, put it directly in IT Pro on 24 September 2026: if a customer falls under NIS2, "part of that compliance burden now lands on you."
The article is aimed at channel partners and MSPs, but the mechanism it describes is wider than distribution. Article 21 of NIS2 requires a covered organisation to manage the security of its direct suppliers and service providers. That obligation was written into the directive in 2022, but it became operational as each member state turned the text into national law. The decisive variable is the customer's classification. A 200-person software firm is out of scope by headcount, yet if it sells to a hospital group in Germany or an energy company in France, it inherits the same demand for provable controls as a regulated entity.
The timing is already uneven. Brophy notes that NIS2 is in force in Germany since 6 December 2025 and Greece since November 2024, with France close behind and Ireland not far. A supplier that trades with a customer in those markets is no longer waiting for the directive to arrive. It is waiting for a contract clause.
The same duty reaches the UK and the Middle East. It travels through the contract rather than through EU membership. A UK provider—or any supplier outside the EU—that works for EU customers, for the UK arm of an EU-regulated group, or for sectors that cross the border still lands in the supply chain that a covered customer is required to assess and document. Brophy makes the point for the UK; the logic extends to any supplier whose customer is regulated in a member state.
The evidence that used to be assumed is now requested
For an organisation with one security person covering the whole estate, the requirement is manageable. The lead time is not. A customer's procurement team rarely needs a bespoke assessment. It needs evidence you can produce in days, not months. Most companies at this size can describe their controls in a meeting but cannot produce them as artefacts: a named risk owner, an incident response procedure, a supplier vetting record, an access policy. Those are the artefacts Article 21 pushes downstream.
The organisations that pass first assemble the evidence pack before the questionnaire exists. It does not need to be a full audit file. A one-page brief is enough to answer most first-round requests:
- who owns information security and what authority they hold
- which framework or certification the organisation is assessed against
- how incidents are handled, including notification thresholds
- how suppliers are vetted and what evidence is retained
With that in hand, a supplier can turn a 40-question spreadsheet into a short submission and a follow-up call. The customer's assessor can mark the control as evidenced and move on. That is what being the easy supplier looks like.
For organisations that have not yet mapped their existing controls to NIS2, the NIS2 and DORA framework mapping shows where gaps sit before a customer finds them. A scored security self-assessment will show which evidence already exists and which has to be created.
The same duty runs the other way
Run this logic forward and it covers the other side of your supplier list. When your organisation falls in scope, or when its own customer demands it, you become the party asking the evidence questions. At that point, a spreadsheet cycle of questionnaires stops being enough. The duty is to manage supplier risk continuously, which means checking answers and remediating gaps, rather than collecting a signature once. A managed third-party risk programme that checks supplier claims against live monitoring data, validates findings before they reach your team, and drives remediation directly with the vendor makes the assessment continuous enough to survive a regulator's question. Most important, it prevents the situation where a supplier's signed questionnaire says one thing and its public exposure says another.
Ask procurement which customers are already asking
Article 20 also changes the conversation at the buyer's end. It puts senior management of an in-scope organisation on the hook for approving and overseeing security measures, including the supply chain. For the procurement manager on the other side of the table, accepting an unevidenced supplier is no longer an administrative shortcut. It is a personal exposure. That is why the questionnaire will come early, and why it will not go away.
Ask your account and sales teams this before the next forecast review: which of our ten largest customers is already asking for security evidence as part of the contract? If nobody can answer, you have found the gap before a lost deal does.
- nis2
- third-party risk
- supply chain security
- supplier assurance
- procurement