NIS2 supplier requirements changed who carries the risk. The obligation to manage supply chain security attaches to the covered entity, which means the security posture of whoever builds and maintains your software became part of your own exposure. If your supplier cannot evidence its practices, the finding lands on your side of the table.
In Portugal the obligations arrived through Decreto-Lei n.º 125/2025 of 4 December, which approved the Regime Jurídico da Cibersegurança and entered into force on 3 April 2026. In Germany the NIS2-Umsetzungsgesetz has applied since 6 December 2025, with § 30 BSIG requiring covered entities to secure their entire supply chain and to impose stricter contractual terms on critical suppliers.
This article sets out the eight clauses worth reviewing at your next contract renewal, what a workable answer looks like for each, and what to do about agreements signed before any of this existed. The dates below show when each obligation started to bite.
What NIS2 supplier requirements put on you rather than your vendor
This is the part most procurement teams read backwards. NIS2 does not regulate every software company in Europe. It regulates essential and important entities, and then makes those entities answerable for the security of the suppliers they depend on.
So a supplier who falls outside the scope of the directive still ends up carrying its weight, because you cannot satisfy your own obligation without commitments from them. In practice the NIS2 supplier requirements reach them through your contract rather than through the law. Two columns below set out where the line sits.
Eight contract clauses that cover the NIS2 supplier requirements
None of these are exotic. Taken together, though, they are what turns a vague assurance into something you can put in front of a supervisor.
Which NIS2 supplier requirements a certified supplier answers already
Renegotiating eight clauses with every vendor is not realistic, particularly if you work with a dozen. In practice most teams triage, and certification is the fastest way to triage honestly against the NIS2 supplier requirements.
An accredited ISO 27001 certification covers risk assessment, access control, supplier management, incident response and continuity as an audited system rather than as promises. So five of the eight clauses above are already evidenced before you open the contract, and the certificate is verifiable independently in the IAF CertSearch database.
Caixa Mágica Software holds certificate 26ISMS-1252 under ISO/IEC 27001:2022, with a scope covering design, development, delivery, maintenance and support of software and IT solutions, including nearshore and team augmentation. You can check what the certification covers or verify it directly in the IAF database.
What to do about contracts signed before the obligation existed
Here is the consequence almost nobody anticipates. Agreements signed before those dates meet none of the NIS2 supplier requirements, because no obligation existed when they were drafted. That is nobody's failure, although it is work outstanding.
The practical order matters more than the thoroughness. Start with suppliers who hold credentials to production systems, since that is where an incident becomes yours fastest. Then those processing personal data. Then everyone else, at natural renewal rather than through a reopening exercise that will cost goodwill and take a year.
One thing worth deciding early: what you will do when a supplier simply cannot meet these terms. Some will not have the processes, and no clause creates them. Better to know that eighteen months before the renewal than during an incident.
How to tell whether a supplier can actually meet them
Questionnaires measure whether a supplier can write plausible sentences. Three requests measure something harder to fake, and together they tell you more about the NIS2 supplier requirements being met than twenty pages of answers.
The second request is the one that separates suppliers most reliably. A vendor describing a specific incident, including what went wrong, is telling you the process is real. A vendor describing a process in the abstract is telling you something else.
Frequently asked questions
Five questions come up in almost every supplier review, so the answers are collected here.


