For companies that supply software, IT services, or operational services to customers regulated under the EU NIS2 directive. Your customers are legally required to manage the security of their suppliers - so their obligations arrive at your door as questionnaires, contract clauses and audits.
One honest clarification: a supplier cannot "be NIS2 compliant" - the legal duty
sits with your regulated customer. What you can be is NIS2-ready: able to prove the
controls their contracts require. That is what this checklist covers. Tick an item only
if you could show a document, a record, or a screen that proves it.
01Ownership and basics
Customers expect a counterpart who is accountable for security.
A named person owns securityOne accountable owner, known to staff, with a deputy.
A short, approved security policy set existsInformation security, access, incidents, backup, acceptable use - concise beats long.
You have assessed the risks of the services you deliverWhat you touch at the customer, what data flows, what happens if you are compromised.
Staff get security awareness training at least annuallyWith dated records - customer contracts increasingly require proof.
02Contracts and questionnaires
This is where supplier obligations actually arrive.
Security clauses are reviewed before you signFlag anything you cannot honour today: notification deadlines, audit rights, subcontractor duties.
Questionnaires are answered from evidence, not memoryState gaps honestly with a dated plan. A wrong "yes" is a contract problem later.
You know each customer's incident notification deadline and contactTheir own regulatory clock is 24 hours for early warning - your window will be short.
No "NIS2 compliant" claims in your sales materialClaim specific, provable controls instead.
Contract exit duties are definedData return, deletion and handover per customer.
03Access and authentication
The most common questionnaire section - and the easiest to fix.
MFA on all remote access, email and admin interfacesIncluding any access into customer systems.
Unique named accounts, no shared credentialsEspecially for access to customer environments and data.
Admin access is limited, separate and logged
Leavers lose access within a defined timeCustomer-side accounts included in the offboarding checklist.
Access rights are reviewed at least annuallyWith a dated record of the review.
04Incidents
If you cause or detect an incident, your customer's legal deadlines depend on you.
A written incident procedure exists and staff know how to raise one
The procedure includes notifying affected customers without undue delayNamed contacts, agreed channels, contractual deadlines.
Key events are logged on systems that touch customer servicesLogins, admin actions, backups.
Incidents and near misses are recorded and reviewed
05Backup and continuity
"When did you last test a restore?" is the question that fails most suppliers.
Systems supporting customer services are backed up on a defined schedule
A restore was tested and documented in the last 12 months
Backups would survive ransomwareOffline, immutable, or separated credentials.
A continuity plan covers loss of key people, premises or primary ITFor the services your customers depend on.
06Systems and software
Customers must weigh the quality of your practices, including how you build software.
You keep an inventory of hardware, software and cloud servicesAt least for what delivers customer services.
Security patches are applied on a defined cadenceWith a fast lane for actively exploited flaws.
Data is encrypted in transit; sensitive data at rest where risk requires
Software suppliers: a defined secure development practiceCode review, dependency updates, tested releases; SBOM on request is a growing ask.
07Your own suppliers
Customer clauses usually require you to pass equivalent obligations down.
You keep a list of subcontractors involved in delivering to regulated customers
Security and incident notification duties are flowed down in their contracts
You know your critical dependenciesThe one sub-supplier or cloud service you cannot deliver without.
08Evidence
The goal: answer any customer questionnaire in under a day, from one folder.
One versioned evidence pack with a named ownerPolicies, MFA proof, restore tests, training records, incident procedure, subcontractor list.
Expiring evidence has refresh datesRestore tests, access reviews and training records age out - questionnaires repeat.
Answers to different customers are consistentOne source of truth, no contradictions between questionnaires.
This checklist is general guidance, not legal advice. Your customer's contract and national transposition define the binding requirements.
More gaps than ticks?
That is normal - most suppliers start there. SteadySec helps suppliers to NIS2-regulated companies close the gaps that matter, assemble the evidence pack, and answer customer questionnaires honestly. Because the questionnaires, audits and clause updates keep coming, this work runs best as a retained partnership that keeps your evidence current over time.