The email arrives from your largest customer, a bank. Attached is a 50-question supplier security assessment. Question 1: “Do you have an information security policy aligned with NIS2?”
You are a 15-person SaaS company. You do not have a NIS2 policy. You have a one-page IT rules document from 2022.
At Metaluxo we answer NIS2-related questionnaires for SME suppliers across the EU. The questions are predictable. The answers are straightforward if you have the documentation. This post provides the ten-point checklist that satisfies every NIS2 supply-chain security assessment we have seen.
The NIS2 supply-chain checklist
1. Information security policy
A one-page policy signed by the CEO, stating what you protect, why, and who is responsible. It does not need to mention NIS2 by name.
Evidence: The signed policy document.
2. Risk assessment
A list of your top risks, scored by likelihood and impact, with owners and treatment plans. Updated at least annually.
Evidence: Risk register with dates and owner names.
3. Access control
Multi-factor authentication on all admin accounts. Unique passwords. Access removed within 24 hours of staff departure.
Evidence: MFA enrollment report and HR offboarding checklist.
4. Encryption
AES-256 for data at rest. TLS 1.2 or higher for data in transit.
Evidence: Cloud console screenshots showing encryption settings.
5. Backup and recovery
Tested backups, stored separately from production, with a documented recovery procedure.
Evidence: Backup test log with restore times.
6. Patch management
Critical patches applied within 30 days. High-risk patches within 60 days. Exceptions documented.
Evidence: Patch log or vulnerability scan report.
7. Incident response plan
Who to call, in what order, and what to do in the first 24 hours. Tested at least annually.
Evidence: Incident response plan document and tabletop exercise minutes.
8. Third-party risk management
A register of all suppliers that process your data or have access to your systems. Critical suppliers assessed annually.
Evidence: Supplier register and assessment records.
9. Business continuity
A plan for continuing operations during a disruption. Key systems identified. Recovery time objectives documented.
Evidence: Business continuity plan and test results.
10. Staff training
All staff trained on information security basics. Phishing simulation at least annually. Training records kept.
Evidence: Training attendance list or completion certificates.
How to present this to a customer
Do not send ten separate documents. Create a single “Security Documentation Pack” with:
- A one-page index listing each control and the evidence file name
- One folder per control containing the evidence
- A cover letter stating that the pack was prepared for their assessment and reviewed on [date]
The customer is not looking for perfection. They are looking for evidence that you have thought about risk and taken reasonable steps. A complete pack, delivered in 48 hours, signals professionalism and reduces their audit burden.
At Metaluxo we build NIS2-ready security documentation packs for SMEs, typically delivering a complete pack in four weeks. If your customers are sending NIS2 questionnaires and you need answers quickly, book a free 30-minute consultation and we will tell you exactly what to produce.
Common questions
Do SMEs need to comply with NIS2 directly?
Most SMEs under 50 employees are not directly in scope. But if you sell to banks, insurers, or critical infrastructure, your customers will flow NIS2 requirements into their contracts.
What is the penalty for NIS2 non-compliance?
For essential entities: up to €10M or 2% of global turnover. For important entities: up to €7M or 1.4% of global turnover. For SMEs, the real risk is losing enterprise contracts.
Can ISO 27001 satisfy NIS2 requirements?
Yes. ISO 27001 Annex A covers all ten NIS2 risk-management areas. A certified SME with complete evidence can answer NIS2 questionnaires with minimal additional work.