Skip to content

Knowledge base

A customer asks for NIS2 evidence: now what?

More and more procurement terms refer to NIS-2 or the Cyberbeveiligingswet, even towards suppliers who have no duty of care of their own. Here's how to handle that request.

Why your customer is asking

If your customer is themselves in scope of the Cybersecurity Act, article 21, third paragraph, opening (d), requires them to manage risk in their supply chain. In practice that means: asking suppliers how they've arranged their security. You're not getting this question because you're in scope. You're getting it because your customer is.

Check whether you're in scope yourself first

Even if the question comes from a customer, you might also have a duty of care of your own. Take the free scope check: it applies the consolidated size test and separately states whether you're seen as a supply-chain partner.

What a customer can reasonably ask

A reasonable question is about concrete measures: do you have a security policy, how do you handle access and passwords, what do you do in an incident, how do you test backups. A customer cannot demand a formal NIS-2 conformity statement from you if you're not in scope yourself: that statement does not exist for supply-chain partners.

How to approach it

Record per relevant measure what you've arranged, who owns it and what evidence backs it up: a policy, a screenshot of a setting, a test report. A shared link to that file is often enough to close out your customer's question, without starting a full compliance programme of your own.

What you never need to do

You don't need to claim you're "NIS-2-compliant": that term doesn't exist, which is why Munitor never uses it either. You demonstrate what you've arranged; whether that's enough is judged by your customer or, for entities that are themselves in scope, by the supervisor.