NIS2 for suppliers: when customer compliance becomes yours

Picture of Anders m. Damgren

Anders m. Damgren

Head of Safety & Documentation

Most equipment suppliers and subcontractors to energy, transport and utilities are not themselves covered by the NIS2 directive. The requirements reach them anyway, because the directive obliges covered companies to manage the security of their supply chain, and they translate that duty into contract requirements towards their suppliers. The questions about documented security practices therefore come from your customers, long before any authority knocks.

Table of contents

Why NIS2 reaches suppliers without naming them

Supply chain security is one of the measures NIS2 requires of covered companies. They must assess security-related aspects of their supplier relationships and include supply chain risks in their overall risk management. They cannot do that without setting requirements down the chain.

The consequence is indirect regulation. A machine builder with 40 employees is generally not mentioned in the legislation, but if the company delivers equipment with network connectivity, remote access or control software to a utility, it becomes part of the utility’s risk picture. Then the requirements arrive with the next contract or the next supplier audit.

This development is not a transition phase that will pass. As covered companies get their own compliance in order, their attention moves exactly where the directive points: out into the chain. If you suspect you may in fact be covered yourself, start with the criteria in our article on who is covered by NIS2.

NIS2 directive
Requires covered companies to manage the security of their entire supply chain
Your customer
Energy, transport and utilities translate their duty into contract requirements
You, the supplier
Questionnaires, minimum measures, notification duties and audit rights
The requirements arrive with the next contract — not with the authorities.

What your customers typically ask about

The requirements vary from customer to customer, but the pattern is recognisable. Suppliers to covered companies typically meet a combination of:

It pays to read the requirements before signing. A notification duty without a defined threshold, or an unlimited audit right, can become expensive in practice, and most customers are willing to sharpen the wording if asked.

What to have ready before the questions arrive

An answer to a security questionnaire has to be backed by documentation, otherwise it falls apart at the first audit. The core of the preparation is a set of documents most technical companies can build in a few months:

The order matters. Start by mapping what you already do, because in most technical companies practice is better than the paperwork. The work then consists of getting practice described and the gaps closed, rather than building a security programme from scratch.

The documentation work itself is a bounded task that rarely justifies a permanent hire. It is the kind of task our interim documentation specialists handle together with your own staff, as a defined effort with a clear end date.

1
Information security policy
How you work with security and who is responsible
2
Risk register
Your main risks and the measures you have in place
3
Incident process
Who assesses, who decides, who notifies customers
4
Process descriptions
Access management, backup and updates
5
Training documentation
Staff training in basic cyber hygiene
Start by mapping what you already do — in most technical companies, practice is better than the paperwork.

ISO 27001 as a framework: useful, but not a requirement

Several suppliers consider ISO 27001 certification as the answer to customer requirements. The standard is a sound framework, because it covers the same areas NIS2 requires of your customers, and a certificate shortens many supplier approvals considerably.

Certification is not a legal requirement, though, and for smaller suppliers a well-structured documentation set following the standard’s principles can be sufficient for years. Judge it by your customer portfolio: If several large customers require a certificate, the calculation is one thing; if you mostly meet questionnaires, it is another. The documentation work is the same foundation either way, and it is described in more detail in our review of NIS2 requirements in practice.

FAQ

Not directly. But your customers are required to assess the security of their supply chain, and suppliers to covered companies therefore typically meet contract requirements for documented security practices.

That is a matter of contract. Typical requirements are technical minimum measures, notification of incidents, documentation of security practices and audit rights. Read the requirements carefully, and ask for unclear wording to be sharpened before you sign.

As a minimum an information security policy, a risk register, an incident process, process descriptions for access, backup and updates, and documentation of staff training. The scope depends on what you deliver and how critical it is to the customer.

No, it is not a legal requirement. Certification can be an advantage if several large customers ask for it, but documentation structured along the standard’s principles is often sufficient.

In the first instance it typically delays supplier approval or the contract. Over time you risk being deselected, because the customer is obliged to include supply chain security in its risk assessment.

The requirements are heaviest where there is network connectivity, remote access or control software. But documentation, spare parts supply and service access can also enter the customer’s supply chain assessment, so few suppliers escape entirely.

Often not. A single-discipline installation can run with one supervisor reporting to a remote project manager. Both roles become necessary when several disciplines and contractors work in parallel.

Both roles are roles we staff, separately or together, across heavy industry. If you are deciding how to structure supervision and site management on an upcoming installation, contact us to discuss your project.

With an overview. Map what you already have in practice and documentation, and hold it up against the requirements your customers set or will set. Our free gap workshop reviews 21 control areas with your team and gives you a prioritised picture in three hours.

Have the first security questionnaires arrived from your customers, or do you want to be ready before they do? Book a free NIS2 gap workshop, or contact us for a conversation about what your customers are going to expect.

Are you struggling to find qualified workforce for your project?

Fill our form and and receive a call within 24 hours.

We respect your privacy and will only use your personal data to administer your account and provide requested products/services. We may contact you about our products/services and other content of interest. Please indicate below if you consent to being contacted.

Opt-out anytime. See our Privacy Policy for details on how to unsubscribe and how we protect your privacy. By submitting, you allow Plant supervision to process your info for requested content. By clicking submit below, you consent to allow Plant supervision to store and process the personal information submitted above to provide you the content requested.