Introduction
"We're way too small for NIS2" — we hear this a lot from SME suppliers, trade businesses, and specialized service providers. Legally speaking, that's often even true, since the directive usually only applies from 50 employees upward. But the economic reality of B2B business looks completely different.
More and more mid-sized companies are losing contracts or getting dropped from tenders because they can't provide evidence of information security. Existing customers are suddenly demanding audits, and new contracts include pages of security clauses.
The reason is what's known as the NIS2 domino effect. Large, directly regulated companies are legally required to comprehensively monitor the cybersecurity of their supply chain. This scrutiny affects every partner in the chain — from cloud providers to maintenance service providers to component suppliers. Anyone who fails to meet the requirements puts their ability to deliver at acute risk.
What Does NIS2 Mean for the Supply Chain?
The NIS2 Directive requires companies in critical and important sectors (such as energy, healthcare, transport, or digital infrastructure) to meet strict cybersecurity standards. A key and often underestimated lever of the directive is mandatory risk management across the entire supply chain.
Companies that fall directly under NIS2 must demonstrate that their suppliers and service providers don't offer an entry point for cybercriminals either.
For you as a supplier, this means:
- Your IT systems and processes are systematically scrutinized by customers.
- Contracts are expanded with strict security and reporting obligations.
- In the worst case, you're classified as a security risk and excluded from the supply chain.
The legal obligation of the "big players" thus becomes a practical obligation for the "small players."
The Difference: Direct Obligation vs. Indirect Market Pressure
To avoid costly missteps, it's important to draw a clear distinction:
Direct NIS2 obligation applies when your company itself operates in one of the regulated sectors and exceeds the size thresholds (generally 50+ employees or €10 million+ in revenue). Violations here risk substantial government fines and personal liability for management.
Indirect market pressure arises when you fall below the size thresholds but work for large customers who are subject to NIS2. Here, the risk isn't government sanctions but a direct loss of revenue and market share. For most SMEs, this economic pressure is the far greater, existential threat.
Why Large Customers Are Now Scrutinizing Their Suppliers
Vendor Risk Management — the process of reviewing supplier risks — isn't new, but NIS2 turns it from a voluntary best practice into a hard legal requirement. In practice, SMEs mainly encounter three instruments:
- Extensive supplier questionnaires: B2B customers request detailed information (often 50+ questions) about your IT security measures and certifications.
- Strict contract clauses: Contracts include tightened minimum standards for encryption, patch management, and extremely short response times in an emergency.
- Audit and inspection rights: Customers secure the right to review your security architecture via remote audit or on-site inspection.
Specific Requirements: What Customers Will Expect From You
When B2B customers come knocking, they typically demand a mix of technical and organizational measures:
- Basic technical security: Consistent use of multi-factor authentication (MFA), comprehensive encryption of sensitive data, and documented, timely patch management.
- Emergency preparedness: Tested backup processes that guarantee fast recovery, plus a rudimentary incident response plan for cyberattacks.
- Organizational requirements: A written IT security policy along with regular phishing and security training for your team.
- Contractual obligations: The obligation to report security incidents that could affect the customer extremely quickly (often within 24 to 72 hours).
The Competitive Advantage of Proactive Compliance
What initially sounds like tedious bureaucracy can be turned into a powerful sales lever. Companies that proactively do their cybersecurity homework secure tangible market advantages:
- Securing your core business: You remain reliably able to deliver for regulated large customers, while unprepared competitors get weeded out.
- Faster sales cycles: If you can present standardized security evidence right from the first contact, that dramatically shortens the customer's approval process.
- Image as a premium partner: Strong, demonstrable security maturity builds trust and often justifies higher pricing compared to low-cost providers.
Practical Checklist for Suppliers
You don't need to invest huge amounts of budget right away. Approach the topic in a structured way:
Phase 1: Analysis & Quick Wins
- Review your customer structure: Which of your customers fall directly under NIS2 or supply critical industries themselves?
- Activate MFA: Enforce multi-factor authentication for all business-critical accounts and admin access.
- Test your backup routine: Don't just create backups — actually test the recovery process in an emergency.
Phase 2: Organization & Documentation
- Clarify responsibilities: Who in the company is accountable for IT security in an emergency?
- Create a security policy: Document a simple, understandable IT security policy for all employees in writing.
- Train your team: Run regular, short awareness sessions on phishing and social engineering .
- Define reporting channels: Establish how and how quickly large customers are informed in the event of your own security incident.
ISO 27001 as a Bridge to NIS2 Compliance
For suppliers looking for a universal, unassailable proof point, there's almost no way around ISO 27001.
This international framework for information security management systems (ISMS) covers most of the requirements that NIS2-regulated companies must impose on their supply chain. In practice, such a certification usually frees you from having to fill out dozens of individual, time-consuming supplier questionnaires from your customers.
Conclusion
The NIS2 domino effect has arrived in the B2B world. If you work for larger corporations, you can no longer hide behind the argument "We're too small for the law." The market regulates itself here through contracts.
Don't wait until an important large customer pressures you or ends the collaboration. Use this time now to build the technical foundations, document your processes cleanly, and use compliance as a powerful sales argument.
FAQ
What happens if I, as a supplier, ignore my customer's NIS2 requirements?
What happens if I, as a supplier, ignore my customer's NIS2 requirements?
As a non-regulated SME, you won't face direct government fines. Economically, however, you risk immediate exclusion from new tenders or the termination of existing contracts, as your customers are legally required to replace insecure partners.
Is cyber insurance enough as proof for my customers?
Is cyber insurance enough as proof for my customers?
No. Insurance merely covers financial losses — it doesn't raise the security level of your systems. NIS2 explicitly requires the implementation of technical and organizational defense measures. What's more, modern cyber insurance policies now require exactly these baseline measures as a condition for coverage.
As a small business, do we have to get expensive ISO 27001 certification right away?
As a small business, do we have to get expensive ISO 27001 certification right away?
Not necessarily. As a first step, it's often completely sufficient for large customers if you can provide a well-founded self-declaration and present a clear, documented roadmap for how you're aligning your IT security with standards such as ISO 27001. If you're not sure which option would be best for your company, feel free to contact us without obligation.
Who can support me with implementing the NIS2 Directive?
Who can support me with implementing the NIS2 Directive?
We at heyData are happy to help you with all questions around NIS2. You'll get a digital platform that covers all processes conveniently and automatically, plus expert advice from one of our compliance experts. Feel free to reach out to us for a free initial consultation.







