NIS2, Explained for Vendors Who Sell into the EU
What the EU's expanded cybersecurity directive actually requires, and how non-EU vendors get pulled into scope through their customers' supply chain obligations.
A procurement email lands from a healthcare network in the Netherlands. Their vendor questionnaire runs eleven pages, and near the end: "Does your organization comply with the requirements of the NIS2 Directive? If not, what is your roadmap to compliance?"
If you're a software vendor based outside the EU, get used to that question. The EU's updated Network and Information Security Directive went live across member states in October 2024, and one of its defining features is a supply chain security obligation. The companies it directly regulates are required to push those requirements down to their vendors. You don't need to be incorporated in the EU to feel the friction.
What NIS2 actually is
NIS2 (formally Directive (EU) 2022/2555) replaced the original NIS Directive and required EU member states to transpose it into national law by October 17, 2024. The transition from version one to version two wasn't incremental: scope expanded from seven sectors to eighteen, obligations became far more specific, and penalties climbed significantly, reaching up to €10 million or 2% of global annual turnover for essential entities and €7 million or 1.4% for important ones.
It is not a certification you earn, a report you commission, or a badge to display. It's a law with binding operational requirements, enforced by national authorities in each member state.
Who the directive actually covers
The directive establishes two tiers based on criticality.
Essential entities operate in sectors where disruption causes the broadest harm: energy, transport, banking and financial market infrastructure, health, drinking water, wastewater, digital infrastructure (cloud providers, DNS services, data centers, CDN operators, managed service providers), space, and central public administration.
Important entities face the same security obligations but lighter supervisory intensity: postal and courier services, waste management, chemicals, food production and distribution, manufacturing of certain critical products, and digital providers such as online marketplaces, search engines, and social platforms.
The size threshold is generally medium-sized enterprise and up (50 or more employees, or annual turnover above €10 million). Smaller companies aren't automatically exempt if they're the sole provider of an essential service in a member state, provide trust services, or operate public electronic communications networks. The rule is scoped by service criticality, not just headcount.
The supply chain clause is the mechanism for vendors
The most important piece for non-EU vendors is Article 21(2)(d): covered entities must implement security measures around supply chain security and relationships with direct suppliers. They're required to assess the security posture of the vendors they rely on and factor that assessment into procurement decisions. That's not advisory language. It's an obligation with enforcement teeth.
This gives organizations subject to NIS2 a legal reason to demand security documentation from their vendors, include NIS2 compliance language in contracts, and revisit vendor relationships that can't demonstrate adequate controls.
The extraterritorial dimension matters too. A US or UK SaaS company that provides cloud-based services to European hospitals or energy firms may fall under NIS2 directly, not only through customer contracts. The directive applies based on where services are delivered, not where the vendor is headquartered. The structure mirrors how GDPR applies to non-EU processors. Non-EU organizations that are directly in scope must designate an EU representative as a point of contact with national authorities.
For most non-EU software vendors, though, the indirect route is what creates actual deal pressure: your customer is a NIS2 essential entity, their obligation flows downstream via contract, and now you're answering a questionnaire that didn't exist before 2024.
What the directive requires in practice
Understanding what your EU customers are being told to do is the fastest way to predict what they'll ask of you.
Article 21 sets out ten categories of risk management measures every covered entity must implement:
- Written risk analysis and information security policies
- Incident handling procedures
- Business continuity and disaster recovery, including backup management
- Supply chain security
- Security in acquiring and maintaining network and information systems
- Effectiveness measurement and cybersecurity training
- Cryptography and, where appropriate, encryption
- Access control, asset management, and human resources security
- Multi-factor authentication across all critical access points
- Secure communications using encrypted channels
Incident reporting under Article 23 adds a timeline that cascades to vendors. When a significant incident occurs, covered entities must file a 24-hour early warning with their national CSIRT or competent authority, a 72-hour incident notification with a fuller technical assessment, and a final report within one month. The 24-hour clock starts when the organization becomes aware of the incident — not when it began. That compressed window means they'll need information from affected vendors fast.
What your customers will actually ask
The specific questions vary by sector and by how mature the procurement team is, but certain themes show up across every NIS2-facing questionnaire:
- Do you have a documented information security policy, and how frequently is it reviewed?
- How do you detect and respond to incidents affecting customer data or systems? What is your notification timeline?
- Do you enforce MFA across all administrative access to systems that touch customer environments?
- Do you conduct background checks on employees with access to customer environments?
- Do you have a tested business continuity plan?
- Which of your subprocessors or sub-vendors have access to customer environments, and how do you assess them?
That last question is the fourth-party angle: they're not just asking about your security, they're asking about your vendors' security. The fourth-party risk guide covers how to build a credible answer without trying to audit every tool in your stack.
The right response to most of these questions isn't a specific NIS2 certification. No formal NIS2 conformity mark exists. What satisfies the question is documented evidence: written policies, access logs, a tested incident response plan, and records of your own vendor reviews.
How to prepare without overcomplicating it
My standard advice to vendors in this position: if you're already working toward SOC 2 or ISO 27001, most of the underlying work is done. NIS2 doesn't invent new security practices — it encodes mainstream hygiene into law. The overlap with ISO/IEC 27001:2022 controls and the SOC 2 Trust Services Criteria is substantial. The same controls that satisfy a US or UK auditor largely satisfy the spirit of NIS2.
A few specifics worth getting right for EU-facing sales:
Incident response has to be operational, not theoretical. A policy document nobody has rehearsed won't hold up when a procurement team asks for your runbook. Get the incident response plan into a testable format with named owners and practiced procedures.
Access reviews need a documented cadence. Running access reviews on a defined schedule (quarterly for privileged accounts, annually for general access) and keeping the records gives you something concrete to show. NIS2-facing customers in regulated industries care about the historical record, not just current state.
Document your own supply chain. Know which of your infrastructure providers and sub-vendors touch customer environments, what security standards they meet, and when you last assessed them. Your EU customers will eventually ask, and "we haven't documented that" is a procurement blocker.
Prepare for contract addenda. Similar to GDPR Data Processing Agreements, some EU organizations are now introducing NIS2-specific contractual clauses. These typically commit vendors to minimum security standards, incident notification timelines, and audit rights. Having a version your legal team has already reviewed means a late-stage contractual ask doesn't stall a deal.
Scope is still settling across the EU
One honest caveat: NIS2 implementation is not uniform across the EU. The October 2024 transposition deadline was missed by the majority of member states, and the European Commission opened infringement proceedings against 23 of them in late 2024. National laws vary in how they interpret certain obligations.
That means the questionnaire from a German manufacturing firm may read differently from one sent by a Dutch cloud provider. The core Article 21 obligations are consistent, but the surrounding regulatory texture is still filling in country by country. Check the frameworks hub for country-specific guidance as national implementations develop.
The underlying advice holds regardless: build the controls, document them, and you'll be positioned to answer whatever version of the question shows up.