NIS2 and your website: what your clients will ask you as a supplier
A client covered by NIS2 has sent you a supplier security questionnaire. Where the questions come from, which ones your website and email domain already answer, and how to prepare the evidence.
The email comes from a client you have worked with for years. Attached is a supplier security questionnaire: dozens of questions about encryption, patching, backups and incidents, due by the end of the month. You run a small firm. You are not a bank, a hospital or a power company. So why the sudden interest?
Because your client is very likely covered by NIS2, the EU directive on cybersecurity, and it makes them responsible for the security of their supply chain. It puts no direct duty on you. The questionnaire is how your client meets their own duty and gets it on paper.
This article covers what the law says, which of those questions your public website and email domain answer for you, and how to gather evidence before anyone asks for it. It is not legal advice. If you are not sure whether your own company falls under NIS2, check your national authority's guidance first.
Where the questions come from
Directive (EU) 2022/2555, known as NIS2, lists in Article 21 the cybersecurity risk-management measures that essential and important entities must take. Point (d) of paragraph 2 reads: "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers".
Paragraph 3 goes further. When choosing those measures, entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of their products and cybersecurity practices.
Your client cannot judge your cybersecurity practices without asking. So they pass part of the obligation down the chain, through questionnaires, contract clauses and requests for evidence. If you supply software, hosting or IT support, or you have access to their systems, expect a long list. If you sell something unrelated, the list may be shorter, but it can still arrive, because it is simpler for a procurement team to send one form to every supplier.
There is also a very ordinary reason your domain matters. You are one of the addresses your client receives invoices from. If someone can send an email that looks like yours, they can send a fake invoice with different bank details. For your client that is a supply chain risk, even if you never touch their servers.
Why now
A directive does not bind companies by itself. Each EU country writes it into national law, on its own timetable. Poland, for example, did it with an act of 23 January 2026 amending its Act on the National Cybersecurity System (Dz.U. 2026 item 252), in force since 3 April 2026. The amended Article 8 of that act lists the security and continuity of the ICT supply chain among the measures a covered company has to put in place.
The Polish Ministry of Digital Affairs gives companies that already met the criteria when the act took effect until 3 October 2026 to register and until 3 April 2027 to implement their obligations. Other countries have their own dates. Wherever your client is based, the pattern is the same: as their deadline gets close, their security and procurement teams work through the supplier list.
Questions your website and email answer
Part of every questionnaire covers things anyone can check from the outside in a few minutes. Your client or their auditor can do it without asking you, so it is better if you know the answers first.
Encryption in transit. Usually phrased as "Is data encrypted in transit?" or "Which TLS versions do you support?" A good answer: the site runs only on HTTPS, http:// redirects to https://, the certificate is valid, and the old protocol versions, TLS 1.0 and 1.1, are switched off. The free SSL certificate checker shows all of this.
Email authentication. "Do you use SPF, DKIM and DMARC?" This one comes up often, because it is about someone impersonating your company. A good answer is all three in your DNS, with DMARC at p=quarantine or p=reject. A p=none record only watches and stops nothing. Run your domain through the SPF, DKIM and DMARC check, and if the acronyms are new to you, this article explains them.
Patching. "How do you manage security updates?" "How quickly do you apply critical patches?" Your website gives away more than you might expect. WordPress and its plugins often show their version numbers in the page code, and a scanner can match them against known vulnerabilities. If your site runs a plugin with a published hole, "we patch promptly" will not survive the first check.
Files left in public. Questions about data protection and backups have an outside angle too. Is there a backup.zip, a database dump or a configuration file with passwords sitting where anyone can download it? Bots try those addresses on every site they reach. More on that in the forgotten backup on your server.
Security headers. Rarely named, but they sit behind questions about hardening web applications. A missing HSTS or Content Security Policy header does not mean the site is wide open. It does show whether anyone is looking after it. The security headers check lists what is there and what is missing.
Reporting a vulnerability. Some questionnaires ask how an outsider can report a security problem to you. The simplest answer is a security contact address published in a /.well-known/security.txt file on your site.
Questions your website cannot answer
The rest is invisible from outside. Who has admin access to your website, email and domain, and whether they use two-factor login. Where your backups are and whether anyone has ever restored one. What you do after an incident and how quickly you tell the client. Whether your staff would spot a phishing email.
No scanner helps with these. Short, true answers and a document to back them up do.
Do not tick "yes" to everything. Questionnaire answers often end up in the contract as representations, and an untrue one is worse than an honest "in progress, done by December". Your client needs suppliers whose risk they can manage. They do not expect suppliers with no risk at all.
Preparing the evidence
Before you reply, set up a folder, with the date in every file name.
- A report on your website and domain. It shows the state of the certificate, email records, headers and exposed files on a given day. If something needed fixing, add a second report after the fix. A before-and-after pair tells the client more than a single result.
- Your SPF, DKIM and DMARC result. A dated screenshot is enough.
- One page on updates. Who updates the website and your other systems, how often, and how quickly critical patches go in.
- One page on backups. Where they are kept, how often they run, and when someone last restored from one.
- An access list. Who holds admin accounts for the website, email, domain registrar and hosting, and whether each of those accounts has two-factor login.
- An incident contact. Name, email and phone number of the person responsible, and how quickly you will tell the client about an incident that affects them.
Write points 3 to 6 together with whoever looks after your website and IT. If you are not sure how to open that conversation, the five questions at the end of this article are a good start.
Repeat the website check every quarter and after any major change. Your client will come back with another questionnaire, and a report from two years ago proves nothing.
What to do this week
If the questionnaire is already on your desk:
- Check your website and domain from the outside. It takes minutes, and the result may change some of your answers.
- Fix the quick things: move DMARC from
p=nonetoquarantine, remove backup files from the web folder, force HTTPS, switch off old TLS versions. With SPF and DKIM already working, that is usually hours of work, not weeks. - Describe the rest honestly: what works, what is in progress, and when it will be done.
You can do the first step with ShieldWave. Type your address, and in about 90 seconds it checks the certificate, headers, SPF, DKIM and DMARC, software versions and exposed files from the outside, then explains the result in plain language with a ready brief for your developer. The first check is free, and a one-off full scan with the complete report for your folder costs $9.