Most small companies are not directly covered by NIS2. The law targets medium and large companies in 18 sectors. But if you supply goods or services to one of them, NIS2 will reach you anyway, through your client.
Why your clients will ask
Companies covered by NIS2 must manage the security of their supply chain. That means looking at the risks that come from their suppliers and service providers, and setting security requirements for them. A manufacturer, a hospital or a logistics company cannot be secure if the supplier with remote access to its systems is not.
What to expect
- Security questionnaires in tenders and contract renewals.
- New contract clauses about security measures, incident notification and audits.
- Requests for evidence: policies, backup tests, access controls, certificates.
- Short deadlines to report incidents that could affect the client.
Suppliers that can answer these questions quickly will win and keep contracts. Suppliers that cannot will be replaced.
How to be ready
You do not need a large compliance project. Most clients look for the same basics:
- Multi-factor authentication for email, remote access and admin accounts
- Backups that are tested, with a copy kept separately
- Up-to-date systems and protection against malware
- Clear rules for who can access what, and removal of access when people leave
- A short written incident procedure: who does what, and who informs the client
- A simple security policy that you actually follow
Write these down. A two-page document that matches what you really do is worth more than a thick policy nobody reads.
How we help
We check where you stand, fix the gaps and help you prepare the answers your clients ask for. Because we are certified to ISO 27001 ourselves, we know what auditors and large clients expect.