NIS2 Reaches You Through Your Client’s Contract
Most web agencies, software shops and IT contractors are not regulated entities under NIS2 and never will be. That is the correct reading of the directive and it is also why so many of them were caught unprepared when the requirements arrived anyway — not from a regulator, but as four new pages in a client’s contract renewal.
NIS2 obliges regulated organisations to manage the security of their supply chain. You are the supply chain. The obligation is theirs, the evidence has to come from you, and the party that enforces it is not a national authority but the client who can terminate the agreement.
Who is actually in scope
The NIS2 Directive covers organisations in listed sectors above a size threshold — broadly, medium-sized and larger entities in energy, transport, banking, health, water, digital infrastructure, public administration, postal services, waste, food, manufacturing and several others. They fall into two classes, essential and important, which differ mainly in how supervision works: proactive for the first, reactive for the second.
The penalties explain why clients take this seriously. Essential entities face up to €10 million or 2% of worldwide turnover, whichever is higher; important entities up to €7 million or 1.4%. Management can be held personally responsible, which is what turns a compliance topic into a board topic and a board topic into a supplier questionnaire.
Two categories are directly in scope in a way that surprises people: managed service providers and managed security service providers. If you administer clients’ infrastructure, you may be regulated in your own right rather than through someone else’s contract.
Where enforcement stands in August 2026
Transposition took far longer than the October 2024 deadline. By mid-2026 most member states had national law in force, and on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition. Austria’s act takes effect in October 2026; Sweden’s came into force in January.
Entity-level enforcement has started. First fines have been reported in several member states, in the tens to hundreds of thousands of euros, and national CSIRTs have begun systematic audit programmes aimed at essential entities. Those audits are what push the questions downstream: an entity being audited on supply chain security has to produce evidence about its suppliers, and the fastest way to produce it is to ask them.
The mental model that saves the most time: your supervisor is your client. No inspector will visit your office over NIS2. Your client’s inspector will ask your client for evidence about you, and your client will pass the cost of that evidence to you in the contract. Every practical decision follows from this — you are not preparing for a regulator, you are preparing for a procurement questionnaire with contractual consequences.
What the clauses actually ask for
Article 21(2)(d) requires regulated entities to address supply chain security, including the security of relationships with direct suppliers. In practice this arrives as a recognisable set of clauses.
| Clause | What it means in practice | What you need ready |
|---|---|---|
| Incident notification | Notify the client within a short window, often 24 hours | A named contact, a defined channel, an internal trigger for what counts |
| Right to audit | The client or their auditor may inspect your practices | Written procedures that exist before the request |
| Minimum security measures | MFA, patching, logging, access control, backups | Evidence they are in force, not a policy document |
| Subcontractor disclosure | Naming your own suppliers and their locations | A current list of services, hosting and data locations |
| Personnel security | Background checks, training, offboarding | An offboarding checklist that revokes access the same day |
| Business continuity | Recovery objectives and tested restoration | A restore test with a date on it |
| Sanctions | Penalties or termination for non-compliance | Negotiated caps proportionate to contract value |
None of it requires a security department. Almost all of it requires documentation of things a competent contractor is doing anyway, which is exactly the problem: doing it well and being able to prove it are different projects, and only the second one has a deadline.
What to have ready before the questionnaire arrives
Six documents cover the great majority of what gets asked. Written once, they answer questionnaires for years with small updates.
- An asset and access register. Which systems hold client data, who has access, and when that access was last reviewed. Most contractors fail here first, because access accumulates and nobody removes it.
- A patch and update policy with actual timeframes — critical within so many days, others within so many. Then evidence it happened, which matters because the practical exposure window on published vulnerabilities is measured in hours, as set out in our note on how quickly plugin vulnerabilities are exploited.
- An incident response procedure naming who decides, who calls the client, and within how long. One page is enough; ambiguity about who makes the call is what turns an incident into a contractual failure.
- A backup and restore record, including the date of the last successful test restore. An untested backup answers no question a client is actually asking, which is the argument in our note on what to test before you need it.
- A subcontractor list — hosting, CDN, monitoring, email, analytics, AI services — with data locations, which is also the basis of the assessment in our note on checking a vendor before integrating it.
- A joiners and leavers checklist that revokes credentials on the last day. This is the single most common finding in supplier reviews and the cheapest to fix.
If none of this exists, the baseline to build first is the same one every small organisation needs regardless of any directive, summarised in our note on baseline protection for a small business.
What is worth negotiating
Supplier security clauses are usually drafted for large vendors and applied unchanged to a five-person agency. Three points are legitimately negotiable, and asking marks you as competent rather than difficult.
Audit rights. Unlimited on-site audit at any time, at your cost, is disproportionate for a small contract. Counter with a documented annual questionnaire plus on-site rights limited to after a material incident, with reasonable notice.
Notification windows. A 24-hour window is workable; a 24-hour window for anything a client might later classify as an incident is not. Define what triggers notification — confirmed unauthorised access, confirmed data loss, confirmed unavailability beyond an agreed threshold.
Liability. Uncapped liability on a small annual contract is not insurable and not survivable. Caps proportionate to contract value are standard and accepted more often than people expect.
What is not worth arguing about: MFA, patching, logging, restricted access and offboarding. These are cheap, they are the ones actually driving incidents, and refusing them signals exactly what the client is checking for. This is the same class of question a serious client asks in any engagement, as set out in our note on nine questions to ask before signing.
What NIS2 does not require of you
A supplier-facing industry has grown around this directive, and a portion of what it sells is unnecessary. Three claims are worth resisting.
It does not require certification. NIS2 mandates risk-proportionate measures, not a certificate. ISO 27001 is a reasonable way to organise the work and a reasonable thing for a large supplier to hold, but no clause obliges a five-person contractor to obtain one. If a client’s contract demands it, that is a commercial requirement of that client, negotiable like any other, and worth pricing rather than absorbing.
It does not require a dedicated security officer. Someone has to be accountable and reachable. That can be a named person with other duties, provided the name is real and the phone is answered.
It does not require a specific product. No tool grants compliance. The measures the directive lists — risk analysis, incident handling, continuity, supply chain, access control, cryptography, training — are practices. Tools support some of them; none of them substitutes for a written procedure and evidence that it was followed.
The honest summary is that a competent small contractor is usually most of the way there in substance and almost nowhere in documentation. The gap that costs contracts is the second one, and it closes with a few days of writing rather than a budget.
If you are the regulated client
Seen from the other side, the failure mode is theatre: a sixty-question spreadsheet sent to every supplier including the office plant service, filed unread. It produces no security and consumes a great deal of goodwill.
The proportionate version has three steps. Classify suppliers by what they can actually reach — access to production systems, access to personal data, access to nothing. Ask the third group almost nothing. Then ask the first group specific questions with evidence attached, and record the answers somewhere a future auditor can find them. Finally, review the ones that matter annually rather than never, and treat the responses as input to a decision rather than as a filing exercise.
Where the supplier holds or processes data, ask where it physically sits and under whose jurisdiction, because that answer drives obligations beyond NIS2 — the reasoning is set out in our note on where your website data lives.
Key takeaways
- You probably are not regulated; your client is. NIS2 reaches most contractors through Article 21(2)(d) supply chain obligations, enforced by the client, not by an inspector.
- Managed service and managed security providers may be in scope directly, which is worth checking rather than assuming.
- Enforcement is live in August 2026. Most member states have transposed, four were referred to the Court of Justice in July 2026, and the first entity-level fines and CSIRT audit programmes have begun.
- Six documents answer most questionnaires: access register, patch policy, incident procedure, tested restores, subcontractor list, joiners-and-leavers checklist.
- Negotiate audit scope, notification triggers and liability caps. Do not negotiate MFA, patching, logging and same-day offboarding.
- If you are the client, be proportionate: classify suppliers by what they can reach, ask the ones that matter real questions, and keep the answers where an auditor can find them.







