Supplier portal

One security questionnaire for all your customers.

Your customers fall under NIS 2 and have to check how securely their suppliers work. So they send you security questionnaires, each one in a different format. Here you answer the questions once and release them to every customer who invites you. Open Source, no lock-in.

Does your own company fall under NIS 2? Check applicability.

NIS 2 Directive (EU) 2022/2555 · CIR 2024/2690 · ENISA TIG v1.0

The nisd2.eu supplier portal with a completed questionnaire

How it works

  1. 1Create the profile

    Sign in, enter your company name and domain. The profile belongs to you, not to one of your customers.

  2. 2Answer once

    Up to 50 questions on commitments, security management, incident plans and access; you only see the ones that fit what you deliver. Every question names the provision it rests on. Drafts are saved as you go.

  3. 3Invite customers

    Each customer gets their own private link. They see your profile, the systems you run for them, and your certificates. They do not need an account.

  4. 4Report incidents

    If a customer's system is affected, you report it from inside the portal. Only that one customer sees the report. It helps them with their duty under Art. 21(2)(d) NIS2 to keep the security of their supply chain in view.

What gets asked

The questions rest on Art. 21 NIS2, Implementing Regulation (EU) 2024/2690 and ENISA's Technical Implementation Guidance v1.0 from June 2025; each names the provision it rests on and, where one applies, the matching ISO 27001 control. It asks what a customer needs for their supply chain, and no more. The question set is public on GitHub.

nis2-supply-chain-questionnaire-schema
Identity and contact
Legal name, address, domain, and who a customer reaches when something goes wrong. Plus the window you commit to responding in.
Security practice
How your company runs information security: management system, certification, training, vulnerability handling, access, continuity planning.
Contract terms
Right to audit, data processing agreement, subcontractors, confidentiality, hand-back at the end of the contract, notification of material changes.
What you reach at customers
Whether you hold your customers' data, reach their systems, enter their premises or deliver software. A tax adviser, a cleaning company and a software house each see only the questions that fit them.
Certificates
Upload ISO 27001, BSI C5, TISAX, SOC 2 or an equivalent as a PDF. Customers see how long it stays valid.

Bilateral and private

There is no public supplier directory. Only the customers you release it to can see your profile, and each of them can end their own access. No public address, no search engine indexing.

„Wir begrüßen aktuelle Vorstöße der Wirtschaft, einen einheitlichen Fragenkatalog für Lieferanten zu erarbeiten."

We welcome current industry initiatives to develop a unified question set for suppliers.

BSI, FAQ on NIS 2 (supply chains and security). This portal is exactly that: a unified question set, built by a company, free for anyone to use.

Why free?

The supplier portal costs nothing and the code is open. We earn from the guided walkthrough for companies under NIS 2, not from your data. Platform and question set are on GitHub, so you can check for yourself.

More in the Trust Center

Ready in two minutes.

Sign in, enter your company name and domain, work through the questionnaire at your own pace. When you are ready, invite your customers.

Create supplier profile