A client forwarded us a security questionnaire last month with a blunt note attached: “answer this or we cannot renew the contract”. They employ nine people. NIS2 does not apply to them directly, yet it reached them anyway — through their customer. That is the part most owners miss, so let’s look at how the rules actually travel down the supply chain.

What NIS2 asks for, in plain terms

NIS2 is the European directive on network and information security, and each member state writes it into national law. It covers essential and important entities across sectors such as energy, transport, health, banking, water, public administration, digital infrastructure and certain digital providers. In general it targets medium and large organisations, so a nine-person firm is usually out of direct scope. The Commission’s overview lists the sectors if you want to check yours.

Three obligations matter most. First, risk management measures: policies, access control, patching, backups, encryption and staff training. Second, incident reporting on a tight clock — an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a month. Third, management accountability, because senior leadership now carries personal responsibility for oversight.

Why it lands on small suppliers anyway

Here is the mechanism. Covered organisations must manage supply-chain risk, which means assessing every vendor with access to their systems or data. Therefore your hosting provider, your web agency, your ERP consultant and your marketing tool all get audited by proxy. As a result, small firms receive questionnaires, contract clauses and evidence requests they never planned for. Meanwhile the same questions arrive from insurers and from public-sector tenders.

Frustrating? Slightly. However, it is also an opening. A supplier who answers quickly and credibly wins work from competitors who stall for three weeks.

What to prepare before the questionnaire arrives

  • An asset and access list. Which systems hold customer data, and who can reach them.
  • Multi-factor authentication everywhere. Email and admin first, no exceptions for the founder.
  • Backups you have restored. An untested backup is a hope, not a control — see our guide to backing up WordPress properly.
  • A patching routine with dates, so you can show updates happen on a schedule.
  • An incident contact and a one-page plan. Who calls whom, and within how long.
  • A short security policy — two pages beat a template nobody reads.

Most of that list is basic hygiene you should want regardless. Our WordPress security checklist covers the website half, and our piece on AI-powered phishing covers the human half, which is where incidents usually start.

One caveat worth stating plainly: national implementations differ in timing and detail, and enforcement is still bedding in. So confirm your own obligations with a lawyer rather than a blog post — including ours. What you can do today is prepare the evidence. Because when NIS2 reaches you through a customer’s contract, the businesses with their documents in order simply keep the account. If you want help getting the technical side ready, talk to us.