Your customer sends a security questionnaire — what now?
You are not subject to it yourself, but you do receive the requirements. Why that happens, and what a good answer is.
Why you receive this list
Your customer is subject to NIS2 and has a duty of care. One of the ten measures in that duty of care is explicitly about the supply chain: they must assess the security of their suppliers and service providers, insofar as it affects their own systems.
They cannot skip this. Their own supervisor can ask about it and their board is personally liable for it. Hence the questionnaire, and hence the insistence.
What is usually in it
The questions almost always come down to the same ten topics, because they are based on the same provision. Do you have an information security policy, how do you handle incidents, what do you do about continuity and back-ups, how do you assess your own suppliers, how do you deal with vulnerabilities, do you measure whether it works, how is it with updates and awareness, do you encrypt data, who is allowed to do what, and do you use two-factor authentication.
The format differs — an Excel file, a Word document, a portal where you have to log in yourself — but the content does not. That is precisely why it is much less work the second time.
What a good answer is
Honest and substantiated. Partly arranged, here is the policy document, this is scheduled for the third quarter: that is a better answer than a tick in every box. Your customer does not assess whether you are perfect; they assess whether they are at risk and whether you know where you stand.
What you must not do is make things up. An answer that does not match up in an inspection will cost you the contract and the relationship. If something is not in place, you report it as not yet arranged, with a date.
Frequently asked questions
Do I have to fill this in?
Not legally; you have no obligation yourself. Commercially it is different: without an answer you will lose the contract or the renewal.
May my customer ask all of this?
Yes. Unlike sustainability questionnaires, there is no legal ceiling on what a customer may ask under NIS2. However, it must be proportionate to the risk you pose to them.
I get a different list from each customer.
That is correct, and that is the real problem. The topics are the same, the form differs. Building up a file once and drawing answers from it is therefore the only workable route.
This is explanation, not advice about your own situation. secria.eu does not assess your organization and does not provide assurance.