Open standard

NIS 2 Supplier Questionnaire

The questions a NIS 2 regulated entity needs to ask its suppliers. Anchored once to EU law. Free to use.

Almost every procurement team in the European mid-market is currently writing its own NIS 2 supplier questionnaire. The same EU-anchored questions, in slightly different forms, sent to suppliers who end up filling out five versions of the same thing. This questionnaire is the shared baseline.

Every question names its EU-level source: Implementing Regulation (EU) 2024/2690, ENISA's Technical Implementation Guidance, the GDPR or the Cyber Resilience Act. 46 of the 50 questions also name the ISO/IEC 27001:2022 Annex A controls they serve, from ENISA's mapping. Sector overlays like TISAX, VDA ISA, BSI C5 or KRITIS audit catalogues sit on top of this baseline, not in place of it.

Every supplier answers 21 questions. Which others it sees depends on what it reaches at its customers: their data, their systems, their premises, software it runs or ships, or IT it runs for them. Each conditional question states the answer it depends on.

Download
Use as is, or as a starting point for your own procurement template.
Version
4.0.0
Last updated
2026-10-04
Fields
50
License
MIT (schema) + CC BY 4.0 (content)

Supplier profile

16 fields

Legal name

stringRequired

Your company's registered name, as it appears in the commercial register. Example: Müller GmbH or Acme Software Ltd.

Legal basis: CIR 2024/2690 §5.2

Registered address

stringRequired

Your company's registered business address. One address is enough, even if you have several locations.

Legal basis: CIR 2024/2690 §5.2

Country

countryRequired

The country where your company is legally established. Two letters, e.g. DE for Germany.

Legal basis: CIR 2024/2690 §5.2

Primary domain

domainOptional

Your main domain, usually the URL of your website. Example: acmesoftware.com.

Legal basis: CIR 2024/2690 §5.2(a)

Description of services provided

textRequired

One paragraph on what you deliver to customers: concrete products, services or work, not marketing. Examples: “Office cleaning three evenings a week, with keys to the building” or “Payroll accounting for up to 200 employees”.

Legal basis: CIR 2024/2690 §5.2(b)ISO/IEC 27001:2022 A.5.19, A.5.22

Security contact name

stringRequired

Who customers contact when a security incident hits. In smaller companies often the managing director or IT lead. One person is enough.

Legal basis: CIR 2024/2690 §5.2(a)ISO/IEC 27001:2022 A.5.20, A.5.24

Incident contact email

emailRequired

Email address customers use to report a security incident. Ideally a distribution list like security@example.com that reaches multiple people.

Legal basis: CIR 2024/2690 §5.2(a)ISO/IEC 27001:2022 A.5.20, A.5.24

Incident contact phone

phoneOptional

Phone number for urgent incident reports. Add the hours it is answered in brackets; round-the-clock cover is not expected.

Legal basis: CIR 2024/2690 §5.2(a)ISO/IEC 27001:2022 A.5.20, A.5.24

How fast you inform customers of an incident (hours)

integerOptional

At most this many hours after you notice a security incident that affects a customer, for example a data leak, a hacked account or a lost key. A customer under NIS 2 must send its authority an early warning within 24 hours of becoming aware of a significant incident (Art. 23(4)(a) NIS 2), so a promise of 24 hours or less helps them most. Give a value you keep.

Legal basis: CIR 2024/2690 §5.1.4(d)ISO/IEC 27001:2022 A.5.20, A.5.24

We provide SaaS / hosted services

booleanRequired

You run software for customers on your own infrastructure and deliver it over the internet. Tick more than one box if you offer several models.

Legal basis: CIR 2024/2690 §5.2(b)ISO/IEC 27001:2022 A.5.19, A.5.22, A.5.23

We deliver on-prem software

booleanRequired

You deliver software that customers install and run on their own infrastructure.

Legal basis: CIR 2024/2690 §5.2(b)ISO/IEC 27001:2022 A.5.19, A.5.22

We provide managed services / MSP

booleanRequired

You operate parts of your customer's IT for them, with your own staff. Typical for MSP and MSSP models.

Legal basis: CIR 2024/2690 §5.2(b)ISO/IEC 27001:2022 A.5.19, A.5.22

We process or store our customers' data

booleanRequired

Tick yes if you hold or handle your customers' data or documents, electronically or on paper, for example in software, a data centre, a ticket system, accounting or an archive.

Legal basis: ENISA TIG §5.1.2ISO/IEC 27001:2022 A.5.19

Countries / regions where customer data is processed

stringConditional

Only if: We process or store our customers' data = Yes

Every country where your customers' data is stored or processed. Comma-separated, ISO country codes. Example: DE, NL, US. If you process entirely within the EU, listing the EU countries is enough.

Legal basis: ENISA TIG §5.1.4 TIPSISO/IEC 27001:2022 A.5.20, A.5.23, A.5.34

We access our customers' systems

booleanRequired

Tick yes if you can sign in to your customers' systems, remotely, as an administrator or on site, for example for maintenance, support or operations.

Legal basis: ENISA TIG §5.1.2ISO/IEC 27001:2022 A.5.19

Our staff enter our customers' premises

booleanRequired

Tick yes if your staff or subcontractors go into a customer's offices or buildings, escorted or not, for example for cleaning, maintenance, repairs, deliveries into the building or on-site support. Holding keys, badges or door codes counts.

Legal basis: CIR 2024/2690 §11.1.2(a); §13.3.2(b)ISO/IEC 27001:2022 A.5.19

Security practices

28 fields

Staff who work for customers are instructed in security when they start and at regular intervals

booleanRequired

Tick yes if everyone who works for customers learns the security rules that apply to them when they start, and again at regular intervals, for example in a short briefing, an e-learning course or written rules they sign.

Legal basis: CIR 2024/2690 §5.1.4(b)ISO/IEC 27001:2022 A.6.3

We accept audits by customers or provide audit reports

booleanRequired

Tick yes if you either let customers audit you or give them audit reports instead (for example SOC 2, ISAE 3402).

Legal basis: CIR 2024/2690 §5.1.4(e)ISO/IEC 27001:2022 A.5.20, A.5.22

We use subcontractors to deliver our service

booleanRequired

Tick yes if other companies help you deliver your service and in doing so reach customer data, systems or premises. Examples: a cloud host such as AWS or Azure, a payment provider, or a subcontracted crew that works on site.

Legal basis: CIR 2024/2690 §5.1.4(g)ISO/IEC 27001:2022 A.5.20, A.5.21

List of subcontractors

textConditional

Only if: We use subcontractors to deliver our service = Yes

Every subcontractor with name, location and what they do for you. One per line is enough. Update it whenever you add or remove one.

Legal basis: CIR 2024/2690 §5.1.4(g)ISO/IEC 27001:2022 A.5.20, A.5.21

We bind subcontractors to comparable security requirements

booleanConditional

Only if: We use subcontractors to deliver our service = Yes

Tick yes if your contracts with subcontractors contain security requirements that match what your customers ask of you, for example on incidents, access and data handling.

Legal basis: CIR 2024/2690 §5.1.4(g)ISO/IEC 27001:2022 A.5.20, A.5.21

We inform customers of material changes, including where their data is processed

booleanRequired

Tick yes if you tell customers before anything material changes in how you deliver: a takeover, a new subcontractor, another hosting provider, or a new country where their data is processed.

Legal basis: ENISA TIG §5.1.4ISO/IEC 27001:2022 A.5.22

On request, we tell customers about security incidents that affected customers

booleanRequired

Tick yes if, when a customer asks, you say openly whether and which security incidents affecting customers you had in the past.

Legal basis: ENISA TIG §5.1.2ISO/IEC 27001:2022 A.5.22

We give customers the information their authority asks for

booleanRequired

Tick yes if you give your customers the information their supervisory authority asks for after an incident or during an audit. Unless you are an essential or important entity under NIS 2 yourself, you owe that authority nothing directly; the duty is your customer's, and you help them meet it.

Legal basis: ENISA TIG §5.1.4ISO/IEC 27001:2022 A.5.20, A.5.31

Everyone who works for our customers is bound to confidentiality

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or Our staff enter our customers' premises = Yes

Tick yes if everyone who works for customers has signed a confidentiality commitment, in the employment contract or a separate agreement, or is bound by professional secrecy by law.

Legal basis: ENISA TIG §5.1 TIPS; CIR 2024/2690 §10.3.2ISO/IEC 27001:2022 A.6.6

We check that staff who get access at customers are suitable

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or Our staff enter our customers' premises = Yes

Tick yes if, before they start, you check that people who will have access to customer data, systems or premises (key holders, for example) are suitable for that role, as far as employment and data protection law allow: references, for example, or a criminal record certificate where lawful and needed for the role. Checking every member of staff is not expected.

Legal basis: CIR 2024/2690 §10.2.1ISO/IEC 27001:2022 A.6.1

At contract end we hand back or destroy what we hold of the customer

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or Our staff enter our customers' premises = Yes

Tick yes if your contract commits you to hand back the customer's data in a usable, documented format (for example CSV or JSON) and then delete it, return keys, badges and documents, and close accounts you had with them.

Legal basis: CIR 2024/2690 §5.1.4(h); §5.1.2(d)ISO/IEC 27001:2022 A.5.11, A.8.10

Data processing agreement (Art. 28 GDPR)

enumConditional

Only if: We process or store our customers' data = Yes

Needed when you process personal data on a customer's behalf and on their instructions (Art. 28(3) GDPR). Some professions are controllers by law and sign none, in Germany tax advisers (§ 11(2) StBerG).

  • Yes, we offer a standard DPA
  • Not needed: we are an independent controller (for example a tax adviser)
  • Not needed: we process no personal data for customers
  • No

Legal basis: GDPR Art. 28(3); Art. 4(7)ISO/IEC 27001:2022 A.5.34

Customer data we hold electronically is encrypted

booleanConditional

Only if: We process or store our customers' data = Yes

Tick yes if customer data is encrypted wherever you store it electronically: on servers, laptops, phones and backups, for example with BitLocker, FileVault or your cloud provider's disk encryption.

Legal basis: CIR 2024/2690 §5.1.2(c); §9.2(a)ISO/IEC 27001:2022 A.8.24

Customer data we send is encrypted in transit

booleanConditional

Only if: We process or store our customers' data = Yes

Tick yes if your websites and interfaces use HTTPS with TLS 1.2 or higher, and files go to customers through an encrypted portal or encrypted email.

Legal basis: CIR 2024/2690 §5.1.2(c); §9.2(a)ISO/IEC 27001:2022 A.8.24

We run a documented information security management system (ISMS)

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Tick yes if you have a written information security policy with assigned roles, regular reviews and documented incident handling. ISO/IEC 27001 certification, also on the basis of IT-Grundschutz, implies yes.

Legal basis: CIR 2024/2690 §5.1.2(a)ISO/IEC 27001:2022 A.5.1

We hold a current security certificate or audit report that covers the service we deliver to customers

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Counts: ISO/IEC 27001 (also on the basis of IT-Grundschutz), a BSI C5 attestation, a TISAX label, a SOC 2 Type II or ISAE 3402 report, or a European cybersecurity certificate. Tick yes only if its scope covers the service you deliver to customers.

Legal basis: CIR 2024/2690 §5.1.2(a); ENISA TIG §5.1.2ISO/IEC 27001:2022 A.5.19, A.5.22

Certificate or report: standard, issuer, valid until, scope

textConditional

Only if: We hold a current security certificate or audit report that covers the service we deliver to customers = Yes

Copy the scope as it is printed on the certificate or report. Several? One per line.

Legal basis: CIR 2024/2690 §5.1.2(a); ENISA TIG §5.1.2ISO/IEC 27001:2022 A.5.22

We install security updates promptly and follow up known vulnerabilities

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Tick yes if you have a set routine for security holes in the systems and software you use for customers: you learn about them, judge how urgent they are, and install the update or take another measure in time.

Legal basis: CIR 2024/2690 §5.1.4(f)ISO/IEC 27001:2022 A.8.8

We have a written plan for security incidents

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Tick yes if a written plan sets out how you handle a security incident: who decides, who informs customers and who documents.

Legal basis: CIR 2024/2690 §5.1.2(a); §3.1ISO/IEC 27001:2022 A.5.24, A.5.26

We have a written plan for outages, including backups

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Tick yes if a written plan says how you keep working or restart after an outage, including backups of the data you hold for customers, kept apart from the live systems and test-restored. It names your critical systems, the fallback, and how long an outage may last and how much data may be lost at most.

Legal basis: CIR 2024/2690 §5.1.2(c); §4.1; §4.2ISO/IEC 27001:2022 A.5.29, A.5.30, A.8.13

All internal administrator accounts are protected with a second factor

booleanConditional

Only if: We process or store our customers' data = Yes or We access our customers' systems = Yes or We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Tick yes if every account with administrator rights in your own systems (email, cloud, servers, accounting) needs a second factor to sign in, such as an authenticator app or a security key. Codes by SMS count but are the weakest option.

Legal basis: CIR 2024/2690 §5.1.2(a); §11.7ISO/IEC 27001:2022 A.8.5, A.8.2

The systems we use to serve customers are security tested by an independent party

booleanConditional

Only if: We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes or We provide managed services / MSP = Yes

Tick yes if an independent party tests these systems for security holes, as often as your risk calls for. A penetration test and an external vulnerability scan both count.

Legal basis: CIR 2024/2690 §5.1.2(a); §6.5ISO/IEC 27001:2022 A.8.29, A.8.8

We develop to defined secure development rules

booleanConditional

Only if: We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes

Tick yes if your development follows set rules, for example a review before every change goes live, dependencies kept up to date, tests, and a check for known vulnerabilities. Asked only of suppliers who run software as a service or ship software.

Legal basis: CIR 2024/2690 §5.1.2(a)ISO/IEC 27001:2022 A.8.25, A.8.28

We publish how to report a security hole to us

booleanConditional

Only if: We provide SaaS / hosted services = Yes or We deliver on-prem software = Yes

Tick yes if your website says how to report a security hole and what you then do, for example in a security.txt file (RFC 9116). From 11 December 2027 the Cyber Resilience Act requires such a policy and a contact address from makers of software products.

Legal basis: CIR 2024/2690 §5.1.4(f); CRA Annex I Part II(5), (6)ISO/IEC 27001:2022 A.8.8, A.5.21

Access to customer systems uses personal accounts with a second factor

booleanConditional

Only if: We access our customers' systems = Yes

Tick yes if everyone who signs in to customer systems uses their own account with a second factor, including remote maintenance tools such as TeamViewer; nobody shares a login.

Legal basis: CIR 2024/2690 §5.1.4(a); §11.3.2(a); §11.5.2(b)ISO/IEC 27001:2022 A.8.2, A.8.5, A.5.16

Administrative access to customer systems is logged

booleanConditional

Only if: We access our customers' systems = Yes

Tick yes if it is recorded who accessed your customers' systems with administrator rights, and when, so it can be traced afterwards. Recording whole sessions is not expected.

Legal basis: CIR 2024/2690 §5.1.4(a); §3.2.3(e)ISO/IEC 27001:2022 A.8.15

We keep track of the keys, badges and codes customers give us

booleanConditional

Only if: Our staff enter our customers' premises = Yes

Tick yes if you always know who holds which key, badge or code, take it back when someone leaves or changes job, and tell the customer without delay when one is lost.

Legal basis: CIR 2024/2690 §5.1.4(a); §11.2.2(d); §13.3.2(b)ISO/IEC 27001:2022 A.7.2, A.5.11, A.5.18

Our staff on customer premises follow written rules of conduct

booleanConditional

Only if: Our staff enter our customers' premises = Yes

Tick yes if your staff have written rules for working at customers, for example: let no one in, leave screens, devices and documents alone, report anything unusual to the customer.

Legal basis: ENISA TIG §5.1 TIPS; CIR 2024/2690 §8.1.1ISO/IEC 27001:2022 A.7.2, A.7.7, A.6.3

Software as a service (SaaS)

2 fields

Customers can protect their accounts with a second factor

booleanConditional

Only if: We provide SaaS / hosted services = Yes

Tick yes if your application offers sign-in with a second factor (an authenticator app, a security key or a one-time code), at least for your customers' administrators. Your own internal admin accounts are a separate question under security practices.

Legal basis: CIR 2024/2690 §5.1.2(c); §11.7ISO/IEC 27001:2022 A.8.5, A.5.23

Longest outage until your service is restored (hours)

integerConditional

Only if: We provide SaaS / hosted services = Yes

The most hours your service may be unavailable before it is restored. Give a value you keep.

Legal basis: ENISA TIG §5.1 TIPSISO/IEC 27001:2022 A.5.30, A.5.23

Software on the customer's premises (on-premise)

4 fields

Until when you supply security updates for the version you deliver

stringConditional

Only if: We deliver on-prem software = Yes

Month and year, or the rule you apply. From 11 December 2027 the Cyber Resilience Act requires manufacturers to state this date at the time of purchase.

Legal basis: CIR 2024/2690 §6.1.2(b); CRA Art. 13(19)ISO/IEC 27001:2022 A.5.21

Deadline for security updates for critical vulnerabilities (hours)

integerConditional

Only if: We deliver on-prem software = Yes

Hours from a critical vulnerability becoming known to your fixed release. From 11 December 2027 the Cyber Resilience Act requires manufacturers to fix vulnerabilities without delay.

Legal basis: CIR 2024/2690 §5.1.4(f); CRA Annex I Part II(2)ISO/IEC 27001:2022 A.8.8

Customers can get a Software Bill of Materials (SBOM)

booleanConditional

Only if: We deliver on-prem software = Yes

Tick yes if you give customers an SBOM for your releases (CycloneDX or SPDX). From 11 December 2027 the Cyber Resilience Act requires manufacturers to keep an SBOM in the technical documentation of products with digital elements; handing it to customers is up to you.

Legal basis: CIR 2024/2690 §6.1.2(c); CRA Annex I Part II(1)ISO/IEC 27001:2022 A.5.21

Releases and updates are signed

booleanConditional

Only if: We deliver on-prem software = Yes

Tick yes if every release and update carries a signature your customers can check before installing, for example Sigstore, Authenticode or PGP.

Legal basis: CIR 2024/2690 §6.6.1(c); CRA Annex I Part II(7)ISO/IEC 27001:2022 A.5.21

How to use it

This questionnaire covers the EU legal substance for NIS 2 supplier due diligence. It is meant as a shared baseline, not a full sector-specific template.

TISAX, VDA ISA, BSI C5, KRITIS audit catalogues, and your own risk overlays sit on top as extensions. Fork the repository, add your sector questions, or use the shared fields as the foundation for your own template.

Supplier assessment with audit log
On the nisd2.eu platform these questions are sent, answered, signed, and stored auditably out of the box. Free, open source, no lock-in.