secria.eu

Customer security questionnaire: what should you do with it?

A customer sends you a long questionnaire about your security and refers to NIS2. What that questionnaire means, why it arrives and how you can provide a useful answer.

## Why you are receiving this questionnaire If your company supplies something to an organization that falls under the NIS2 Directive — an essential or important entity, such as energy companies, hospitals, large transport companies or digital infrastructure — then that customer is required to assess its own suppliers. The Directive obliges that customer to map risks in its supply chain, not just its own systems. This is described in what is often called the duty of care, found in Article 21 of the Directive. The questionnaire you receive is the practical consequence: your customer must be able to demonstrate that they know who their suppliers are and how those suppliers handle security. It is important to understand: receiving a questionnaire does not automatically mean that you yourself fall under the NIS2 Directive. Most companies that receive such a list are what is called supply chain-affected — they do not fall under the law themselves, but are confronted with it through a customer. Whether that applies to your organization, and what type of affectedness that precisely is, you can check with [[LINK:/nis2-check|a short check that maps your situation]]. ## What is usually in them The questionnaires currently in circulation vary greatly depending on who prepared them — there is no mandatory format from the law. Yet certain topics almost always come up. Questions about who within your organization is responsible for information security, whether you have a policy for handling incidents, how you regulate access to systems, whether employees receive training, and whether you yourself set requirements for your own suppliers. Some lists also ask about certifications, previous incidents, or how you handle updates and remediation plans. The underlying logic is always the same: the customer is trying to get a picture of risks that could reach them through your supply. This is not distrust toward your company specifically, but an obligation that the customer must fulfill themselves. If you want to understand which ten measures serve as the starting point for this, you will find that explanation in [[LINK:/onderwerpen|the overview of topics per situation]]. ## What a useful answer requires A good answer to a security questionnaire is not necessarily one in which you answer 'yes' to everything. Supervisors and customers typically look for consistency: do your answers align with what you actually do, and can you substantiate that? A vague or overly optimistic response will generate more questions in the long run than an honest answer that identifies an improvement point with a timeline attached. It helps to have three things clear for each question: what the current situation is, who within your organization can confirm that, and what supporting document goes with it — a policy document, a screenshot of a setting, a training overview. Companies that do not have to look up these three points again for each question, but have already recorded them in an ongoing overview, can typically complete a questionnaire within an hour instead of days. That is exactly what a dossier with status, supporting document and owner per measure is intended for. ## What you do not have to do It is good to know that completing and sending this questionnaire remains your own responsibility — a service can help you prepare and structure answers, but should never submit on your behalf to a customer or supervisor. An audit, a pentest or a certification is also different from completing a questionnaire; that remains work for specialized parties, should a customer specifically ask for it. If you have doubts about whether the questions you receive are reasonable in relation to your size and role, that is a conversation you are best having directly with the customer, possibly with a lawyer if the requirements are being contractually formalized. Secria describes what the Directive and national legislation say, but does not judge individual contracts. ## Looking further If you first want to know where this information comes from and how it is maintained, you can read that on [[LINK:/hoe-het-werkt|the page about the platform's working method]]. If you do not yet have a picture of your own position in the chain, start with the free check — it provides an indication within a few questions and a logical next step, without needing an account for that.

This article is general information and not legal advice.