SteadySec
Your retained security partner

NIS2 · Supplier readiness

NIS2 Supplier Readiness Checklist

For companies that supply software, IT services, or operational services to customers regulated under the EU NIS2 directive. Your customers are legally required to manage the security of their suppliers - so their obligations arrive at your door as questionnaires, contract clauses and audits.

One honest clarification: a supplier cannot "be NIS2 compliant" - the legal duty sits with your regulated customer. What you can be is NIS2-ready: able to prove the controls their contracts require. That is what this checklist covers. Tick an item only if you could show a document, a record, or a screen that proves it.

01Ownership and basics

Customers expect a counterpart who is accountable for security.

02Contracts and questionnaires

This is where supplier obligations actually arrive.

03Access and authentication

The most common questionnaire section - and the easiest to fix.

04Incidents

If you cause or detect an incident, your customer's legal deadlines depend on you.

05Backup and continuity

"When did you last test a restore?" is the question that fails most suppliers.

06Systems and software

Customers must weigh the quality of your practices, including how you build software.

07Your own suppliers

Customer clauses usually require you to pass equivalent obligations down.

08Evidence

The goal: answer any customer questionnaire in under a day, from one folder.

Based on

  1. Directive (EU) 2022/2555 (NIS2), esp. Art. 21(2)(d), Art. 21(3) and Art. 23 - eur-lex.europa.eu
  2. Commission Implementing Regulation (EU) 2024/2690, Annex points 5.1-5.2 (supply chain security) - eur-lex.europa.eu
  3. ENISA, Good Practices for Supply Chain Cybersecurity (2023) and NIS2 Technical Implementation Guidance v1.0 (2025) - enisa.europa.eu
  4. Czech transposition: Act No. 264/2025 Coll., on Cybersecurity (NÚKIB) - portal.nukib.gov.cz

This checklist is general guidance, not legal advice. Your customer's contract and national transposition define the binding requirements.

More gaps than ticks?

That is normal - most suppliers start there. SteadySec helps suppliers to NIS2-regulated companies close the gaps that matter, assemble the evidence pack, and answer customer questionnaires honestly. Because the questionnaires, audits and clause updates keep coming, this work runs best as a retained partnership that keeps your evidence current over time.

hello@steadysec.eu·Book a call