Supplier portal

One security questionnaire for all your customers.

Your customers fall under NIS 2 and have to check how securely their suppliers work. So they send you security questionnaires, each one in a different format. Here you answer the questions once and release them to every customer who invites you. Open Source, no lock-in.

Does your own company fall under NIS 2? Check applicability.

NIS 2 Directive (EU) 2022/2555 · CIR 2024/2690 · ENISA TIG v1.0

The nisd2.eu supplier portal with a completed questionnaire

How it works

  1. 1Create the profile

    Sign in, enter your company name and domain. The profile belongs to you, not to one of your customers.

  2. 2Answer once

    59 questions on security management, certification, incident plans, access, and contract clauses. Every question names the paragraph it rests on. Drafts are saved as you go.

  3. 3Invite customers

    Each customer gets their own private link. They see your profile, the systems you run for them, and your certificates. They do not need an account.

  4. 4Report incidents

    If a customer's system is affected, you report it from inside the portal. Only that one customer sees the report. It is how they meet their Article 21(2)(d) duty to keep an eye on their suppliers.

What gets asked

The structure follows ENISA's NIS2 Technical Implementation Guidance v1.0 from June 2025. Every question names the paragraph in CIR 2024/2690 or BSI IT-Grundschutz it rests on. An auditor recognises the structure, so you do not have to invent one. The question set is public on GitHub.

nis2-supply-chain-questionnaire-schema
Identity and contact
Legal name, address, domain, and who a customer reaches when something goes wrong. Plus the window you commit to responding in.
Security practice
How your company runs information security: management system, certification, training, vulnerability handling, access, continuity planning.
Contract terms
Right to audit, data processing agreement, subprocessors, return of data at the end of the contract, notification of material changes.
Type of service
SaaS, software on the customer's premises, professional services, or managed services. You only answer the questions that match your business.
Certificates
Upload ISO 27001, BSI Grundschutz, or an equivalent as a PDF. Customers see how long it stays valid.

Bilateral and private

There is no public supplier directory. Only the customers you release it to can see your profile, and each of them can end their own access. No public address, no search engine indexing.

Wir begrüßen aktuelle Vorstöße der Wirtschaft, einen einheitlichen Fragenkatalog für Lieferanten zu erarbeiten."

We welcome current industry initiatives to develop a unified question set for suppliers.

BSI, FAQ on NIS 2 (supply chains and security). This portal is exactly that: a unified question set, built by a company, free for anyone to use.

Why free?

The supplier portal costs nothing and the code is open. We earn from training and hands-on implementation work, not from your data. Platform and question set are on GitHub, so you can check for yourself.

More in the Trust Center

Ready in two minutes.

Sign in, enter your company name and domain, work through the questionnaire at your own pace. When you are ready, invite your customers.

Create supplier profile