Supplier portal by nisd2.eu
Answer one security questionnaire. Share with every customer.
How it works.
Three steps, from first sign-in to first customer invite.
What is in the questionnaire.
Ten sections, each citing the underlying paragraph of ENISA TIG, CIR 2024/2690 or BSI IT-Grundschutz.
- Identity (CIR §5.2 / ENISA TIG §5.2 supplier register)
- Incident contact (customer-facing)
- Service type
- Mandatory contract clauses (CIR / ENISA TIG §5.1.4)
- Cybersecurity measures (NIS 2 Art. 21(2) / ENISA TIG §5.1.2)
- Additional contract clauses (ENISA TIG §5.1.4 TIPS)
- SaaS technical
- On-prem software technical
- Professional services, details
- Managed services, details
The full schema is public on GitHub and exportable as JSON.
Four technical sections per service type.
The Service type page in the portal surfaces four additional sections. Fill in only the ones that match what you offer.
SaaS
Hosting region, encryption at rest and in transit, MFA for admin accounts, recovery time objective.
On-prem software
Software Bill of Materials (SBOM), cryptographically signed releases, published vulnerability disclosure policy, patch SLA for critical CVEs.
Professional services
Background check scope, NDA with all consultants, documented customer-premises behaviour policy.
Managed services
Privileged access management, admin session recording, 24/7 on-call for security incidents.
Sample questions.
Six questions from different sections, with the help text suppliers see while filling them in. Identity, security practices, contract clauses, AI declarations, technical details.
Legal name
Your company's registered name, as it appears in the commercial register. Example: Müller GmbH or Acme Software Ltd.
ENISA TIG §5.2
Documented Information Security Management System (ISMS)
Tick yes if you have a written information security policy with assigned roles, regular reviews, and documented incident handling. ISO 27001 or BSI Grundschutz certification implies yes.
CIR 2024/2690 §5.1.2(a)
Accept customer right to audit (or provide audit reports)
Tick yes if you either grant customers an on-site audit right or provide substitute audit reports (for example SOC 2, ISAE 3402).
CIR 2024/2690 §5.1.4(e)
Provide incident assistance to customers at no / ex-ante cost
Tick yes if you commit to helping customers at no extra cost when an incident is caused by your product or service. If you agree a pre-defined day rate up front instead, also tick yes.
ENISA TIG §5.1.4 TIPS
We use, integrate or provide AI systems
Do your products or services process customer data through an AI or ML model? Includes external models you call through an API, for example OpenAI or Anthropic.
NIS2 Art. 21(2)(d)
Hosting region
The cloud region where customer data is hosted. Example: AWS eu-central-1, Azure West Europe. Name the primary region; secondary or backup regions can be added comma-separated.
ENISA TIG §5.2
Six of 59 questions. Full set in the portal.
„We welcome current industry initiatives to develop a unified questionnaire catalogue for suppliers."
BSI NIS-2 FAQ (supply chain and security).
This supplier portal IS that industry initiative. A privately built, unified questionnaire catalogue, structured by the canonical EU taxonomy (ENISA TIG §5) so every NIS 2 regulated entity can satisfy CIR §5.1.4 from a single source.
Bilateral and private.
Built in Germany, hosted in the EU, aligned with BSI Grundschutz. Your data is shared only with customers you explicitly invite. No public URL, no search-engine indexing.
Start in two minutes.
Sign in with Google. Enter company name and primary domain. Fill the questionnaire at your own pace. When you are ready, invite your customers.
Continue on nisd2.eu.
This tool is part of the nisd2.eu ecosystem. The rest lives here.
NIS 2 supplier portal
Same function, positioned from the NIS 2 perspective: for managing bodies implementing §30 BSIG.
Open questionnaire schema
The full JSON schema with source citations, free to reuse.
Guided NIS 2 implementation
If you want help on full implementation: 500 euro per month, no lock-in.
Open source
Full source on GitHub under AGPL-3.0.