Do I need NIS2 compliance if I'm a supplier to an essential entity?
Not directly, unless your own sector and size put you in scope. But essential and important entities must manage supply-chain security under Article 21(2)(d), so they pass requirements down to suppliers through contracts, questionnaires and audits. Managed IT and security service providers are often in scope themselves under Annex I.
Last updated: 2026-09-30
Two separate questions
- ▸Am I in scope myself? — Check your own sector and size. ICT Service Management (B2B), which covers managed service and managed security service providers, is an Annex I sector; Digital Providers are Annex II.
- ▸What will my customers ask for? — Article 21(2)(d) requires in-scope entities to address the security of relationships with their direct suppliers and service providers.
What in-scope customers typically ask suppliers for
- ▸Completed security questionnaires and supporting evidence
- ▸Contract clauses on incident notification and cooperation
- ▸Evidence of basics such as MFA, backups and vulnerability handling
- ▸Audit or assessment rights
Related question
Does NIS2 apply to small suppliers?
A small supplier outside the NIS2 size threshold is not directly regulated, unless a size-independent rule applies. It will, however, often have to meet security requirements that its in-scope customers set in contracts.
Next steps
- Check your own NIS2 scope →
- NIS2 for ICT service management (B2B) →
- NIS2 checklist (Article 21) →
- NISDESK für IT-Dienstleister (DE) →
More answers:
For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.