my customer is asking me to fill out a security questionnaire what should I do
A security questionnaire is usually a supply chain signal, not a legal obligation
A questionnaire from a customer usually means that the customer themselves falls under NIS2 regulation and is required to assess their suppliers. This also applies if the receiving organisation is not subject to the rules at all: the customer must map their own supply chain, and the questionnaire is the result of that obligation. This situation — receiving questions without being subject to the law yourself — is common among many SMB suppliers and is explained further on the page about why suppliers receive security requirements without being subject to the law themselves.
The questionnaire itself usually covers the same topics: access control, patching policy, incident detection, backups, supplier management, and who within the organisation is responsible for security. Anyone who has not yet organised these topics or documented them should ideally do so before answering the questionnaire — otherwise a patchwork of isolated answers emerges that will need to be collected again when the next questionnaire arrives. A good first step is to find out which ten measures are used as the basis, because virtually every questionnaire is based on these at its core, and to determine where to start if nothing has been documented yet.
Why customers ask for it this way: Article 21(2) NIS2
The obligation to assess suppliers follows from Article 21(2) of the NIS2 Directive, which sets out the ten measures that an entity subject to the rules must take — including explicitly the security of the supply chain. An essential or important entity that wants to comply with that measure can only demonstrate this by also checking its own suppliers, and the security questionnaire is the usual instrument for that. In the national transposition, the Cybersecurity Act, this obligation is reflected for organisations falling under the law in the Netherlands. Anyone who wants to check for themselves whether that obligation also applies directly to their own organisation can do so by addressing the question how to determine if a company falls under NIS2.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.