why do I receive security requirements if I myself do not fall under NIS2
The supply chain carries the duty of care through to suppliers
This is due to the way the duty of care is structured. An organization that falls under the NIS2 Directive itself must not only put its own security in order, but also assess how secure its suppliers and service providers are — this is part of what the duty of care means in plain language. That obligation extends beyond the organization's own chain. A subject organization cannot simply secure its own systems; it must also have visibility of the risks coming in through sub-suppliers, software partners and service providers. Hence the questionnaire, the contractual requirement or the request to provide evidence.
For the recipient of such a questionnaire, this does not automatically mean that their own organization falls under the NIS2 Directive. It means that a customer that does fall under it is obliged to check this with their suppliers. Anyone who is not themselves subject to the rules but is part of the supply chain of a subject organization will face the same kind of questions — about access control, about incident reporting, about security measures — without having their own registration or reporting obligation to supervisory authorities. Anyone who wants to know for certain whether their own organization also falls under the Directive separately can check this via how to know if your company falls under NIS2. For anyone who already has such a questionnaire on their desk, there is a separate explanation about what to do if a customer asks for a security questionnaire.
Where this comes from: Article 21(2) of the NIS2 Directive
Article 21(2) of the NIS2 Directive explicitly names the security of the supply chain and the relationship with suppliers as part of the ten measures that essential and important entities must take. This obligation has been incorporated into Dutch law in the Cybersecurity Act. The NCSC explains in its guidance on the duty of care that this chain responsibility leads in practice to questionnaires and contractual requirements sent to suppliers that do not themselves fall under the law.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.