NIS2 Supplier Requirements: 8 Contract Clauses

Avatar
Author

NIS2 supplier requirements changed who carries the risk. The obligation to manage supply chain security attaches to the covered entity, which means the security posture of whoever builds and maintains your software became part of your own exposure. If your supplier cannot evidence its practices, the finding lands on your side of the table.

In Portugal the obligations arrived through Decreto-Lei n.º 125/2025 of 4 December, which approved the Regime Jurídico da Cibersegurança and entered into force on 3 April 2026. In Germany the NIS2-Umsetzungsgesetz has applied since 6 December 2025, with § 30 BSIG requiring covered entities to secure their entire supply chain and to impose stricter contractual terms on critical suppliers.

This article sets out the eight clauses worth reviewing at your next contract renewal, what a workable answer looks like for each, and what to do about agreements signed before any of this existed. The dates below show when each obligation started to bite.

Dec 2025
Germany: NIS2-Umsetzungsgesetz in force
Apr 2026
Portugal: Regime Jurídico da Cibersegurança in force
Sep 2026
CRA Article 14 reporting obligations apply
Next renewal
Where the contract work actually lands
The obligation attaches to the covered entity. Your supplier's security practices are not their compliance problem. They are yours.

What NIS2 supplier requirements put on you rather than your vendor

This is the part most procurement teams read backwards. NIS2 does not regulate every software company in Europe. It regulates essential and important entities, and then makes those entities answerable for the security of the suppliers they depend on.

So a supplier who falls outside the scope of the directive still ends up carrying its weight, because you cannot satisfy your own obligation without commitments from them. In practice the NIS2 supplier requirements reach them through your contract rather than through the law. Two columns below set out where the line sits.

Your obligation
Manage the supply chain
Assess the security practices of your direct suppliers, secure those relationships contractually, and be able to show a supervisor how you did it.
Their position
Often outside the scope
Many software suppliers are not covered entities themselves, so nothing compels them to volunteer any of this. It has to come through the contract.
Which is why the questionnaire has grown from two pages to twenty. It is doing work the contract should be doing instead.

Eight contract clauses that cover the NIS2 supplier requirements

None of these are exotic. Taken together, though, they are what turns a vague assurance into something you can put in front of a supervisor.

Incident notification windows. Set so they fit inside your own reporting duties, not your supplier's convenience. If you owe a report in 24 hours and they have 72 to tell you, the clause is decorative.
A named security contact. With a real out-of-hours escalation path. A shared inbox monitored during office hours is not an escalation path.
Component inventory or SBOM. Available on request, for anything running in your environment. This is the clause that tells you most about how a supplier actually works.
Vulnerability handling commitments. Response times by severity, written down. Without severity tiers the commitment means whatever is convenient at the time.
Access control and offboarding evidence. For anyone touching your systems. Ask specifically what happens in the week someone rolls off the project, since that is where credentials linger.
Subcontractor disclosure. Who else is in the chain, and where their people physically sit. European implementing guidance also expects cascading clauses, so the supplier passes the same terms down.
Data location and applicable jurisdiction. Stated explicitly, rather than inferred from where the company is registered.
A right to audit, or an accepted certification in its place. Few buyers ever exercise a right to audit. An accredited certification does the same job continuously, which is why most contracts now accept one in substitution.
Ask for a current component inventory. If it arrives in 48 hours, there is a process behind it. If it takes three weeks, you have learned something more useful than any questionnaire would tell you.
Reviewing supplier contracts and want to test these clauses against a real supplier?
Talk to our team

Which NIS2 supplier requirements a certified supplier answers already

Renegotiating eight clauses with every vendor is not realistic, particularly if you work with a dozen. In practice most teams triage, and certification is the fastest way to triage honestly against the NIS2 supplier requirements.

An accredited ISO 27001 certification covers risk assessment, access control, supplier management, incident response and continuity as an audited system rather than as promises. So five of the eight clauses above are already evidenced before you open the contract, and the certificate is verifiable independently in the IAF CertSearch database.

Still negotiate these. Notification windows, the named contact, and data location. They are specific to your reporting duties and no certificate sets them for you.
Read the scope statement before relying on it. A certificate covering a head office does not cover the team writing your code. The scope is the part almost nobody reads.
Check the certification body is accredited. An unaccredited issuer carries no weight, and a PDF by email is how most certificate fraud arrives.

Caixa Mágica Software holds certificate 26ISMS-1252 under ISO/IEC 27001:2022, with a scope covering design, development, delivery, maintenance and support of software and IT solutions, including nearshore and team augmentation. You can check what the certification covers or verify it directly in the IAF database.

What to do about contracts signed before the obligation existed

Here is the consequence almost nobody anticipates. Agreements signed before those dates meet none of the NIS2 supplier requirements, because no obligation existed when they were drafted. That is nobody's failure, although it is work outstanding.

The practical order matters more than the thoroughness. Start with suppliers who hold credentials to production systems, since that is where an incident becomes yours fastest. Then those processing personal data. Then everyone else, at natural renewal rather than through a reopening exercise that will cost goodwill and take a year.

One thing worth deciding early: what you will do when a supplier simply cannot meet these terms. Some will not have the processes, and no clause creates them. Better to know that eighteen months before the renewal than during an incident.

How to tell whether a supplier can actually meet them

Questionnaires measure whether a supplier can write plausible sentences. Three requests measure something harder to fake, and together they tell you more about the NIS2 supplier requirements being met than twenty pages of answers.

Three requests that settle it
The component inventory
Ask for a current one. Response time tells you whether a process exists.
The last incident
What happened, who was notified, what changed afterwards. An honest answer is specific.
The certificate and its scope
Number, issuing body, validity and scope statement. Then verify it yourself.
All three can be answered in days by a supplier with the processes in place. Response time is the signal, more than the content of any single answer.

The second request is the one that separates suppliers most reliably. A vendor describing a specific incident, including what went wrong, is telling you the process is real. A vendor describing a process in the abstract is telling you something else.

Frequently asked questions

Five questions come up in almost every supplier review, so the answers are collected here.

What are the NIS2 supplier requirements?
NIS2 requires essential and important entities to manage the security of their supply chain, which includes assessing the security practices of direct suppliers and service providers and securing those relationships contractually. The obligation attaches to the covered entity rather than to every supplier, so it reaches suppliers through contract terms instead of through the directive itself.
Does NIS2 apply to my software supplier?
Often not directly. Many software suppliers fall outside the scope of the directive because of their size or sector. Because their clients are covered, though, the requirements reach them through security questionnaires, contract clauses and evidence requests. A supplier outside the scope can still lose business by being unable to answer them.
Does NIS2 require ISO 27001 certification?
No. NIS2 does not name any specific certification. It requires you to demonstrate that your suppliers manage information risk in a structured and reviewable way. An accredited ISO 27001 certificate is the most widely accepted evidence of that, which is why contracts increasingly accept one in place of a right to audit.
What should be in a supplier contract under NIS2?
Incident notification windows aligned to your own reporting duties, a named security contact with out-of-hours escalation, component inventory on request, vulnerability handling with response times by severity, access control and offboarding evidence, subcontractor disclosure, data location and jurisdiction, and a right to audit or an accepted certification in its place.
What happens to contracts signed before NIS2 came into force?
They remain valid, although they contain none of these commitments, since no obligation existed when they were drafted. The practical approach is to review at natural renewal, starting with suppliers who hold credentials to production systems and those processing personal data, rather than reopening every agreement at once.
Caixa Mágica Software
Caixa Mágica Team
Caixa Mágica Software is a Portuguese software company with 20+ years of experience delivering custom software, AI solutions and nearshore development teams for European businesses.
Software Development · Caixa Mágica Software
Put these eight clauses in front of us
We hold an accredited ISO 27001 certificate you can verify without asking us, our scope covers the whole delivery chain including nearshore teams, and we answer evidence requests in days rather than weeks. Test it.