Anders m. Damgren
Head of Safety & Documentation
Most equipment suppliers and subcontractors to energy, transport and utilities are not themselves covered by the NIS2 directive. The requirements reach them anyway, because the directive obliges covered companies to manage the security of their supply chain, and they translate that duty into contract requirements towards their suppliers. The questions about documented security practices therefore come from your customers, long before any authority knocks.
Table of contents
Why NIS2 reaches suppliers without naming them
Supply chain security is one of the measures NIS2 requires of covered companies. They must assess security-related aspects of their supplier relationships and include supply chain risks in their overall risk management. They cannot do that without setting requirements down the chain.
The consequence is indirect regulation. A machine builder with 40 employees is generally not mentioned in the legislation, but if the company delivers equipment with network connectivity, remote access or control software to a utility, it becomes part of the utility’s risk picture. Then the requirements arrive with the next contract or the next supplier audit.
This development is not a transition phase that will pass. As covered companies get their own compliance in order, their attention moves exactly where the directive points: out into the chain. If you suspect you may in fact be covered yourself, start with the criteria in our article on who is covered by NIS2.
What your customers typically ask about
The requirements vary from customer to customer, but the pattern is recognisable. Suppliers to covered companies typically meet a combination of:
- Security questionnaires about your policies, access management, backup and incident handling, often as a fixed part of supplier approval.
- Contractual minimum requirements for technical and organisational measures, for example encryption, patch management and control of remote access to delivered equipment.
- Notification duties if you discover an incident that could affect the customer's systems or deliveries.
- Audit rights, where the customer or the customer's auditor can verify that what you answered is also what you do.
- Documentation requirements for the delivered equipment, including how control software is secured and updated.
It pays to read the requirements before signing. A notification duty without a defined threshold, or an unlimited audit right, can become expensive in practice, and most customers are willing to sharpen the wording if asked.
What to have ready before the questions arrive
An answer to a security questionnaire has to be backed by documentation, otherwise it falls apart at the first audit. The core of the preparation is a set of documents most technical companies can build in a few months:
- An information security policy describing how you work with security and who is responsible.
- A risk register covering your main risks and the measures you have put in place.
- An incident process: who assesses, who decides, and who notifies customers if something goes wrong.
- Process descriptions for access management, backup and updating of the systems relevant to your deliveries.
- Documentation of staff training in basic cyber hygiene.
The order matters. Start by mapping what you already do, because in most technical companies practice is better than the paperwork. The work then consists of getting practice described and the gaps closed, rather than building a security programme from scratch.
The documentation work itself is a bounded task that rarely justifies a permanent hire. It is the kind of task our interim documentation specialists handle together with your own staff, as a defined effort with a clear end date.
ISO 27001 as a framework: useful, but not a requirement
Several suppliers consider ISO 27001 certification as the answer to customer requirements. The standard is a sound framework, because it covers the same areas NIS2 requires of your customers, and a certificate shortens many supplier approvals considerably.
Certification is not a legal requirement, though, and for smaller suppliers a well-structured documentation set following the standard’s principles can be sufficient for years. Judge it by your customer portfolio: If several large customers require a certificate, the calculation is one thing; if you mostly meet questionnaires, it is another. The documentation work is the same foundation either way, and it is described in more detail in our review of NIS2 requirements in practice.
FAQ
Not directly. But your customers are required to assess the security of their supply chain, and suppliers to covered companies therefore typically meet contract requirements for documented security practices.
That is a matter of contract. Typical requirements are technical minimum measures, notification of incidents, documentation of security practices and audit rights. Read the requirements carefully, and ask for unclear wording to be sharpened before you sign.
As a minimum an information security policy, a risk register, an incident process, process descriptions for access, backup and updates, and documentation of staff training. The scope depends on what you deliver and how critical it is to the customer.
No, it is not a legal requirement. Certification can be an advantage if several large customers ask for it, but documentation structured along the standard’s principles is often sufficient.
In the first instance it typically delays supplier approval or the contract. Over time you risk being deselected, because the customer is obliged to include supply chain security in its risk assessment.
The requirements are heaviest where there is network connectivity, remote access or control software. But documentation, spare parts supply and service access can also enter the customer’s supply chain assessment, so few suppliers escape entirely.
Often not. A single-discipline installation can run with one supervisor reporting to a remote project manager. Both roles become necessary when several disciplines and contractors work in parallel.
Both roles are roles we staff, separately or together, across heavy industry. If you are deciding how to structure supervision and site management on an upcoming installation, contact us to discuss your project.
With an overview. Map what you already have in practice and documentation, and hold it up against the requirements your customers set or will set. Our free gap workshop reviews 21 control areas with your team and gives you a prioritised picture in three hours.
Have the first security questionnaires arrived from your customers, or do you want to be ready before they do? Book a free NIS2 gap workshop, or contact us for a conversation about what your customers are going to expect.