Law & Compliance · 2026-09-17 · 13 min read
Your biggest customer’s NIS2 questionnaire: eight pages, three weeks to respond — and not a word of it is in the statute

Michael Kaiser
Co-Founder & Head of Systems, Vincency
The email comes from your largest customer's purchasing department. Attached: a security questionnaire, eight pages, a three-week deadline, and at the end a signature line for the managing director. Since the German NIS2 implementation act entered into force on 6 December 2025, these forms have been landing on the desks of suppliers who are nowhere near the statutory thresholds themselves. The short answer first: almost nothing in that questionnaire is a legal obligation of yours. It is your customer's evidence, not your duty — and that distinction is worth money.
This piece reads the questionnaire the way it was written: from the provision your customer must satisfy, not from the form that arrived. What Section 30(2) no. 4 BSIG actually demands, why the sharpest part of the regime sits one level higher in Article 21(3) of the directive, which passages belong back on the customer's desk before signature, and how the honest answer turns into the argument that keeps you on the supplier list.
What Section 30(2) no. 4 BSIG actually requires — one half-sentence
The provision cited in almost every covering email is Section 30(2) no. 4 BSIG, Germany's transposition of the NIS2 directive. Its complete wording on the supply chain reads: "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers." That is all — a half-sentence inside a list of ten risk-management measures. It names no questionnaire, no audit, no frequency, no minimum number of questions and no certification.
Two further provisions set the frame your customer works within. The first is the proportionality clause in Section 30(1) sentence 2: the measures have to fit the entity's risk exposure, its size, the implementation cost, and the likelihood and severity of incidents. A sixty-employee tooling supplier is owed a different package than a logistics group. The second is one level up, in Article 21(3) of the directive itself: entities must take into account the vulnerabilities specific to each direct supplier and the overall quality of their suppliers' and service providers' products and cybersecurity practices, including their secure development procedures. That is the sharpest formulation in the regime — and it still says nothing about how the assessment reaches you.
One more text explains why some questionnaires look harsher than others. The Commission's Implementing Regulation (EU) 2024/2690 spells out technical and methodological requirements in detail — but it binds only providers of digital services: DNS, cloud, data centres, managed service and security providers, online marketplaces, search engines, social networks. A machine builder or plastics supplier is not governed by it. If the form you received reads like the implementing regulation, your customer likely copied a template built for IT providers — worth knowing before you answer line by line.
Why your customer has no choice
The questionnaire exists because your customer's obligation is personal, not departmental. Section 38 BSIG puts the implementation and supervision of the risk-management measures on the management body and demands its own regular training — which is why the signature line at the bottom of the form names a managing director and not a project manager. Behind that sits the sanction frame your customer faces: under Section 65 BSIG, breaches of the risk-management duties carry up to ten million euros for essential entities and up to seven million for important ones; the two-percent-of-turnover rule begins only above five hundred million euros of total turnover.
The arithmetic explains the timing. At 30 June 2026 the BSI counted 17,729 registered entities against a legislative estimate of around 30,000, and the registered ones are now working through the measure list — supply chain is number four of ten. Every regulated entity reaching that item sends the same document downstream, to suppliers who sit far below every threshold. The questionnaire wave running through the German mid-market this autumn is not an audit programme; it is ten thousand companies discharging the same half-sentence at the same time.
What the questionnaires ask — and where the statute actually sits
The forms resemble each other because they mirror the ten measure areas of Section 30(2). Mapping the typical blocks to their legal anchor shows how much is statute and how much is the customer's drafting choice:
| Questionnaire block | Typically asked | Statutory anchor |
|---|---|---|
| Access control | Multi-factor authentication, admin account protection, joiner/mover/leaver process | Measure areas 6 and 7 of Section 30(2) — for the regulated entity |
| Backup and recovery | Separated backups, documented restore tests | Measure area 3; the restore TEST is what distinguishes evidence from assertion |
| Vulnerability and patch management | Patch timelines, handling of disclosed vulnerabilities | Measure area 4; Article 21(3) of the directive pushes the supplier-specific part |
| Incident handling | Emergency plan, reporting channels, named contact | Measure area 5; the 24-hour early warning under Section 32 binds the entity to the BSI, not you to the customer |
| Training | Regular staff awareness measures | Measure area 10; Section 38(3) separately requires the customer's own management to be trained |
| Policies and documentation | Written security policies, ISMS, certificates | Measure areas 1 and 2; a certificate is ONE way to evidence, not the statutory form |
The pattern the table shows: the blocks are real, the binding object is always your customer. None of the ten areas of Section 30(2) applies to you directly if you are not yourself an important or essential entity. What binds you is the contract clause that arrives with the questionnaire — which is why the annex matters more than the form.
The four passages that should go back before signature
Questionnaire and contract annex travel together, and the annex is where a disclosure exercise becomes liability. Four formulations recur that the statute does not require and that you can negotiate without endangering the order:
Unlimited audit rights. A clause granting the customer audits at any time, at your cost, goes beyond anything Section 30 demands. What is defensible: audits on reasonable advance notice, during business hours, accompanied, and bounded in scope to the systems that touch the customer's data or deliveries. Anything wider is procurement boilerplate, not NIS2.
Incident reporting in hours. The 24-hour early warning of Section 32 BSIG runs from the regulated entity to the BSI. A clause that obliges you to report every incident — or every potential incident — within 24 hours imports a deadline you may be unable to keep on a Saturday. Reporting windows of 24 to 72 hours for incidents that could affect the customer are customary and defensible; sign what you can hold.
Liability for the customer's own incident. Some annexes shift the consequences of the customer's regulatory breach onto the supplier, or make the supplier liable for any incident occurring in the customer's environment. Your sphere ends at your systems and your deliveries. A liability clause that reaches past it converts the annex from evidence into insurance — priced at zero, carried by you.
Certification as a condition. Where a form makes ISO 27001 or IT-Grundschutz certification a hard condition, it exceeds the statute: the proportionality clause exists precisely so that a forty-employee firm is not asked for a group-grade management system. The counter-offer that usually works is documented measures plus a self-assessment — the BSI's own supply-chain guidance names an ISMS as a suitable basis, not as the only admissible one.
How to answer without building an ISMS from scratch
The working order that keeps the effort at days rather than months:
| Step | What it contains | Why in this order |
|---|---|---|
| 1. Classify the sender | Is your customer an important or essential entity under Section 28 and Annexes 1/2? Does the form mirror the digital-sector regulation 2024/2690? | Decides how much of the form is statute and how much is template |
| 2. Honest internal pass | One run through the six to eight blocks, marking what exists, what is half-done, what is missing | The answer can only be as good as this inventory; everything later reuses it |
| 3. Answer with evidence, not ticks | "Restore test documented 12 May" instead of "yes"; policy name and date instead of "available" | Evidence survives the audit; a tick box does not |
| 4. Name gaps with measure and date | "MFA for remote access planned, rollout by March" beats an optimistic yes | A dated plan is assessable; a false yes is a contract breach waiting for the loss event |
| 5. Read the annex before the form | Audit rights, reporting windows, liability scope, termination | The form informs, the annex binds — negotiation happens in the annex |
The temptation to tick yes everywhere is understandable and wrong. The questionnaire is not graded like an exam; it is filed as your customer's evidence that its suppliers were assessed. An honest form with three named gaps and three dated measures reads as a manageable risk. A spotless form from a forty-employee firm reads as what it usually is.
The part that turns into an advantage
Your competitors are holding the same form. The assessment your customer runs on the answers is a ranking: suppliers are sorted into documented, partially documented and not assessable, and that ordering feeds the next award decision. The company that returns a clean, evidenced, honestly bounded answer moves up a list that its competitors are quietly descending — without a single euro spent on a certificate nobody legally required.
The second-order effect runs further. Once your answers exist as a documented set, every later questionnaire costs hours instead of days, and the same file answers the security annex, the cyber-insurance application and the tender section that asks about information security. The work is not the burden of one customer's compliance; done once properly, it is a sales asset.
What belongs on your desk this week
Three tasks, none of them requiring an external consultant:
| Task | Who | Behind it |
|---|---|---|
| One documented pass through the six blocks: access, backup, patching, incidents, training, policies | Operations plus whoever owns IT | Every incoming questionnaire, current and future |
| A named owner for security annexes — who reads, who signs, who negotiates | Management | Section 38 puts supervision on the customer's leadership; the answer should not sit lower on yours |
| Check whether your own company is in scope after all — 50 employees plus an Annex 2 activity is a shorter reach than most assume | Management | 17,729 registered entities against roughly 30,000 expected — the gap sits exactly in this size band |
Whoever takes one thing from this piece: the questionnaire on your desk is your customer's statutory duty travelling downstream, not yours. You owe an honest, evidenced answer — and nothing in the statute stops you from making it the best one on the customer's desk.
Related service
Turning obligations into systems
This article clarifies the legal position. It gets implemented in software and processes: product inventory, reporting channel, data access, invoice format, update documentation. We take the inventory off mid-sized companies, order the obligations by deadline and effort and, if you wish, implement them.
IT strategy consultingFrequently asked questions about the NIS2 supply-chain questionnaire
Do I have to fill in my customer’s NIS2 questionnaire?
Not by law: the BSIG contains no duty to complete questionnaires, and if your company is not itself in scope under Section 28, no provision says you must answer. Economically the picture differs: your customer is obliged, as an important or essential entity, to secure its supply chain, and the questionnaire is its cheapest evidence. A supplier who does not respond is filed as not assessable — which, at the next award, is the more expensive answer.
We have 35 employees. Does NIS2 apply to us?
Directly, almost certainly not: the thresholds sit at roughly 50 employees or ten million euros of turnover, combined with activity in a sector of Annexes 1 or 2 of the BSIG. Indirectly the directive reaches you anyway once a regulated customer classifies you as a direct supplier. Your obligation then is not the statute but the contract — and that distinction decides what you can negotiate and what you cannot.
What happens if I give false answers in the questionnaire?
For you the questionnaire is a contractual basis, not a filing to an authority. False answers stay without consequence until they do not: at the customer’s first audit, or in a loss event where a measure that did not exist had been agreed as existing. Then the order itself is joined by a damages question, on a document signed by management. The cheaper answer is the honest one: name the gap, name the measure, name the date.
Does the questionnaire require ISO 27001 certification?
Some questionnaires ask for it; the law does not. Section 30(1) sentence 2 BSIG contains an express proportionality clause: what matters is risk exposure, the size of the entity, implementation cost, and the likelihood and severity of incidents. A business with 40 employees owes documented, risk-appropriate measures — not a certified management system. Anyone requiring a certificate grounds it in contract, not in the BSIG.
Must I report security incidents to the customer within 24 hours?
Only where the contract says so. The 24-hour early warning under Section 32 BSIG binds the regulated entity towards the BSI, not you towards your customer. Customary and defensible are reporting windows of 24 to 72 hours for incidents that could touch the customer. Check the clause before signing: whoever signs a deadline they cannot keep has turned a disclosure term into a breach of contract.
What does answering realistically cost?
The first questionnaire costs one to three working days: one internal pass through the six to eight topic blocks, collecting the evidence you already have, and honestly marking the gaps. Every further questionnaire from the same customer circle costs hours, because the answers are reusable — provided they were documented cleanly once rather than rephrased per form. It only gets expensive when answers given optimistically the first time have to be produced later.
Can we reject the security annex to the contract?
You may reject anything — but your customer cannot reject its statutory duty. The realistic room sits in the detail: limit audit rights to advance notice and accompanied access, adjust reporting windows to what your operation can keep, and cap liability at your own sphere of responsibility. Anyone rejecting the annex outright should expect to be sorted downwards in the supplier assessment — the alternative to the annex is rarely no annex, but another supplier.
Sources, status and note: All provisions were checked verbatim against the statute texts, retrieved on 17 September 2026: Section 30 BSIG for the measure catalogue, the supply-chain limb and the proportionality clause; Section 28 and Annex 2 BSIG for scope and size thresholds; Section 32 for the reporting deadlines that bind the entity, not the supplier; Section 33 for the registration duty; Section 38 for the management duties; and Section 65 for the sanction frame. On the European level, Directive (EU) 2022/2555, Article 21(2)(d) and (3), for the supplier-specific assessment; Implementing Regulation (EU) 2024/2690 for the scope of the stricter technical requirements limited to digital services. The registration figures are from the BSI page NIS-2 in Zahlen, status 30 June 2026; the supply-chain framing follows the BSI guidance note Sichere Lieferkette. This piece assesses the legal position; it does not replace advice on the individual case.
Related insights