NIS2 Reaches You Through Your Client’s Contract

Most web agencies, software shops and IT contractors are not regulated entities under NIS2 and never will be. That is the correct reading of the directive and it is also why so many of them were caught unprepared when the requirements arrived anyway — not from a regulator, but as four new pages in a client’s contract renewal.

NIS2 obliges regulated organisations to manage the security of their supply chain. You are the supply chain. The obligation is theirs, the evidence has to come from you, and the party that enforces it is not a national authority but the client who can terminate the agreement.

Who is actually in scope

The NIS2 Directive covers organisations in listed sectors above a size threshold — broadly, medium-sized and larger entities in energy, transport, banking, health, water, digital infrastructure, public administration, postal services, waste, food, manufacturing and several others. They fall into two classes, essential and important, which differ mainly in how supervision works: proactive for the first, reactive for the second.

The penalties explain why clients take this seriously. Essential entities face up to €10 million or 2% of worldwide turnover, whichever is higher; important entities up to €7 million or 1.4%. Management can be held personally responsible, which is what turns a compliance topic into a board topic and a board topic into a supplier questionnaire.

Two categories are directly in scope in a way that surprises people: managed service providers and managed security service providers. If you administer clients’ infrastructure, you may be regulated in your own right rather than through someone else’s contract.

Where enforcement stands in August 2026

Transposition took far longer than the October 2024 deadline. By mid-2026 most member states had national law in force, and on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition. Austria’s act takes effect in October 2026; Sweden’s came into force in January.

Entity-level enforcement has started. First fines have been reported in several member states, in the tens to hundreds of thousands of euros, and national CSIRTs have begun systematic audit programmes aimed at essential entities. Those audits are what push the questions downstream: an entity being audited on supply chain security has to produce evidence about its suppliers, and the fastest way to produce it is to ask them.

The mental model that saves the most time: your supervisor is your client. No inspector will visit your office over NIS2. Your client’s inspector will ask your client for evidence about you, and your client will pass the cost of that evidence to you in the contract. Every practical decision follows from this — you are not preparing for a regulator, you are preparing for a procurement questionnaire with contractual consequences.

What the clauses actually ask for

Article 21(2)(d) requires regulated entities to address supply chain security, including the security of relationships with direct suppliers. In practice this arrives as a recognisable set of clauses.

ClauseWhat it means in practiceWhat you need ready
Incident notificationNotify the client within a short window, often 24 hoursA named contact, a defined channel, an internal trigger for what counts
Right to auditThe client or their auditor may inspect your practicesWritten procedures that exist before the request
Minimum security measuresMFA, patching, logging, access control, backupsEvidence they are in force, not a policy document
Subcontractor disclosureNaming your own suppliers and their locationsA current list of services, hosting and data locations
Personnel securityBackground checks, training, offboardingAn offboarding checklist that revokes access the same day
Business continuityRecovery objectives and tested restorationA restore test with a date on it
SanctionsPenalties or termination for non-complianceNegotiated caps proportionate to contract value

None of it requires a security department. Almost all of it requires documentation of things a competent contractor is doing anyway, which is exactly the problem: doing it well and being able to prove it are different projects, and only the second one has a deadline.

What to have ready before the questionnaire arrives

Six documents cover the great majority of what gets asked. Written once, they answer questionnaires for years with small updates.

  1. An asset and access register. Which systems hold client data, who has access, and when that access was last reviewed. Most contractors fail here first, because access accumulates and nobody removes it.
  2. A patch and update policy with actual timeframes — critical within so many days, others within so many. Then evidence it happened, which matters because the practical exposure window on published vulnerabilities is measured in hours, as set out in our note on how quickly plugin vulnerabilities are exploited.
  3. An incident response procedure naming who decides, who calls the client, and within how long. One page is enough; ambiguity about who makes the call is what turns an incident into a contractual failure.
  4. A backup and restore record, including the date of the last successful test restore. An untested backup answers no question a client is actually asking, which is the argument in our note on what to test before you need it.
  5. A subcontractor list — hosting, CDN, monitoring, email, analytics, AI services — with data locations, which is also the basis of the assessment in our note on checking a vendor before integrating it.
  6. A joiners and leavers checklist that revokes credentials on the last day. This is the single most common finding in supplier reviews and the cheapest to fix.

If none of this exists, the baseline to build first is the same one every small organisation needs regardless of any directive, summarised in our note on baseline protection for a small business.

What is worth negotiating

Supplier security clauses are usually drafted for large vendors and applied unchanged to a five-person agency. Three points are legitimately negotiable, and asking marks you as competent rather than difficult.

Audit rights. Unlimited on-site audit at any time, at your cost, is disproportionate for a small contract. Counter with a documented annual questionnaire plus on-site rights limited to after a material incident, with reasonable notice.

Notification windows. A 24-hour window is workable; a 24-hour window for anything a client might later classify as an incident is not. Define what triggers notification — confirmed unauthorised access, confirmed data loss, confirmed unavailability beyond an agreed threshold.

Liability. Uncapped liability on a small annual contract is not insurable and not survivable. Caps proportionate to contract value are standard and accepted more often than people expect.

What is not worth arguing about: MFA, patching, logging, restricted access and offboarding. These are cheap, they are the ones actually driving incidents, and refusing them signals exactly what the client is checking for. This is the same class of question a serious client asks in any engagement, as set out in our note on nine questions to ask before signing.

What NIS2 does not require of you

A supplier-facing industry has grown around this directive, and a portion of what it sells is unnecessary. Three claims are worth resisting.

It does not require certification. NIS2 mandates risk-proportionate measures, not a certificate. ISO 27001 is a reasonable way to organise the work and a reasonable thing for a large supplier to hold, but no clause obliges a five-person contractor to obtain one. If a client’s contract demands it, that is a commercial requirement of that client, negotiable like any other, and worth pricing rather than absorbing.

It does not require a dedicated security officer. Someone has to be accountable and reachable. That can be a named person with other duties, provided the name is real and the phone is answered.

It does not require a specific product. No tool grants compliance. The measures the directive lists — risk analysis, incident handling, continuity, supply chain, access control, cryptography, training — are practices. Tools support some of them; none of them substitutes for a written procedure and evidence that it was followed.

The honest summary is that a competent small contractor is usually most of the way there in substance and almost nowhere in documentation. The gap that costs contracts is the second one, and it closes with a few days of writing rather than a budget.

If you are the regulated client

Seen from the other side, the failure mode is theatre: a sixty-question spreadsheet sent to every supplier including the office plant service, filed unread. It produces no security and consumes a great deal of goodwill.

The proportionate version has three steps. Classify suppliers by what they can actually reach — access to production systems, access to personal data, access to nothing. Ask the third group almost nothing. Then ask the first group specific questions with evidence attached, and record the answers somewhere a future auditor can find them. Finally, review the ones that matter annually rather than never, and treat the responses as input to a decision rather than as a filing exercise.

Where the supplier holds or processes data, ask where it physically sits and under whose jurisdiction, because that answer drives obligations beyond NIS2 — the reasoning is set out in our note on where your website data lives.

Key takeaways

  • You probably are not regulated; your client is. NIS2 reaches most contractors through Article 21(2)(d) supply chain obligations, enforced by the client, not by an inspector.
  • Managed service and managed security providers may be in scope directly, which is worth checking rather than assuming.
  • Enforcement is live in August 2026. Most member states have transposed, four were referred to the Court of Justice in July 2026, and the first entity-level fines and CSIRT audit programmes have begun.
  • Six documents answer most questionnaires: access register, patch policy, incident procedure, tested restores, subcontractor list, joiners-and-leavers checklist.
  • Negotiate audit scope, notification triggers and liability caps. Do not negotiate MFA, patching, logging and same-day offboarding.
  • If you are the client, be proportionate: classify suppliers by what they can reach, ask the ones that matter real questions, and keep the answers where an auditor can find them.

Contact us
to discuss your project

Fill out the form and we will contact you
to discuss the details of your project.

    Choose a convenient way to contact us:

    Telegram
    Viber
    E-mail