A tool by nisd2.eu

Supplier portal by nisd2.eu

Answer one security questionnaire. Share with every customer.

One canonical supplier questionnaire, structured by ENISA NIS 2 Technical Implementation Guidance v1.0. Every question cites CIR 2024/2690, BSIG §30 or BSI IT-Grundschutz. Free. Open source. Your data stays portable.
Structured by ENISA NIS 2 TIG v1.0 §5

How it works.

Three steps, from first sign-in to first customer invite.

1. Create a profile
Sign in with Google. Enter company name and primary domain. Two minutes.
2. Answer the questionnaire
Three sub-pages in the portal: profile and service description, universal cybersecurity measures per NIS 2 Art. 21(2), technical sections per service type. 59 questions, at your own pace, draft auto-saves.
3. Invite customers
Each invited customer gets a private magic link. No public profile, no search-engine indexing.

What is in the questionnaire.

Ten sections, each citing the underlying paragraph of ENISA TIG, CIR 2024/2690 or BSI IT-Grundschutz.

  • Identity (CIR §5.2 / ENISA TIG §5.2 supplier register)
  • Incident contact (customer-facing)
  • Service type
  • Mandatory contract clauses (CIR / ENISA TIG §5.1.4)
  • Cybersecurity measures (NIS 2 Art. 21(2) / ENISA TIG §5.1.2)
  • Additional contract clauses (ENISA TIG §5.1.4 TIPS)
  • SaaS technical
  • On-prem software technical
  • Professional services, details
  • Managed services, details

The full schema is public on GitHub and exportable as JSON.

Four technical sections per service type.

The Service type page in the portal surfaces four additional sections. Fill in only the ones that match what you offer.

SaaS

Hosting region, encryption at rest and in transit, MFA for admin accounts, recovery time objective.

On-prem software

Software Bill of Materials (SBOM), cryptographically signed releases, published vulnerability disclosure policy, patch SLA for critical CVEs.

Professional services

Background check scope, NDA with all consultants, documented customer-premises behaviour policy.

Managed services

Privileged access management, admin session recording, 24/7 on-call for security incidents.

Sample questions.

Six questions from different sections, with the help text suppliers see while filling them in. Identity, security practices, contract clauses, AI declarations, technical details.

Legal name

Your company's registered name, as it appears in the commercial register. Example: Müller GmbH or Acme Software Ltd.

ENISA TIG §5.2

Documented Information Security Management System (ISMS)

Tick yes if you have a written information security policy with assigned roles, regular reviews, and documented incident handling. ISO 27001 or BSI Grundschutz certification implies yes.

CIR 2024/2690 §5.1.2(a)

Accept customer right to audit (or provide audit reports)

Tick yes if you either grant customers an on-site audit right or provide substitute audit reports (for example SOC 2, ISAE 3402).

CIR 2024/2690 §5.1.4(e)

Provide incident assistance to customers at no / ex-ante cost

Tick yes if you commit to helping customers at no extra cost when an incident is caused by your product or service. If you agree a pre-defined day rate up front instead, also tick yes.

ENISA TIG §5.1.4 TIPS

We use, integrate or provide AI systems

Do your products or services process customer data through an AI or ML model? Includes external models you call through an API, for example OpenAI or Anthropic.

NIS2 Art. 21(2)(d)

Hosting region

The cloud region where customer data is hosted. Example: AWS eu-central-1, Azure West Europe. Name the primary region; secondary or backup regions can be added comma-separated.

ENISA TIG §5.2

Six of 59 questions. Full set in the portal.

We welcome current industry initiatives to develop a unified questionnaire catalogue for suppliers."

BSI NIS-2 FAQ (supply chain and security).

This supplier portal IS that industry initiative. A privately built, unified questionnaire catalogue, structured by the canonical EU taxonomy (ENISA TIG §5) so every NIS 2 regulated entity can satisfy CIR §5.1.4 from a single source.

Bilateral and private.

Built in Germany, hosted in the EU, aligned with BSI Grundschutz. Your data is shared only with customers you explicitly invite. No public URL, no search-engine indexing.

Start in two minutes.

Sign in with Google. Enter company name and primary domain. Fill the questionnaire at your own pace. When you are ready, invite your customers.

Continue on nisd2.eu.

This tool is part of the nisd2.eu ecosystem. The rest lives here.