It has been happening for months, and it usually arrives without warning: an important client sends a cybersecurity questionnaire. Eighty questions, sometimes a hundred and eighty. Access policies, backups, incident handling, staff training, a list of your own subcontractors. At the bottom, the sentence that raises your blood pressure: contract renewal depends on the outcome.
And you are not a NIS2 entity. You never received anything from the national cybersecurity agency, you are on no list, your business classification appears in no annex.
You are asking the right question: why is this our problem?
The short answer is that since 2026 NIS2 no longer applies only to the entities in scope. It applies, by contract, to whoever supplies them. And there is a formal step, taken in spring 2026, that almost nobody explained to suppliers.
Your company name is probably already on a list at the agency
In April 2026 ACN, Italy's National Cybersecurity Agency, introduced a new requirement: entities in scope for NIS2 must declare to the agency, through its platform, a named list of their relevant suppliers. Not a generic description of supply categories: company name, tax code, country of registered office, procurement codes for the supply, and the criterion that makes the supplier relevant.
The first window closed on 31 May 2026.
A supplier is "relevant" when at least one of two conditions applies. The first is that the supply falls under digital infrastructure or managed ICT services. The second is broader and captures many more companies: an interruption of the supply would significantly affect the client's operational capacity. This is the non-substitutability test — not "you matter to us", but "we have no replacement available within an acceptable time frame".
Which means it captures things you would not expect: connectivity providers, whoever maintains the PLCs on the production line, whoever runs the ERP, whoever makes a component nobody else makes to those tolerances.
If you supply a utility, a hospital, a bank, a transport operator, a logistics company, a food business of meaningful size or a public administration, and your supply is not trivially replaceable, your company name and VAT number have in all likelihood already been transmitted to the agency. Without anyone being obliged to tell you.
This does not make you a NIS2 entity. It triggers no legal obligation, no penalty and no deadline for you. But it explains why the questionnaire arrived, and why it will arrive again.
Why your client is in a hurry right now
There is one date driving the behaviour of every client of yours that falls under NIS2, and it is worth knowing, because it is the reason for the pressure you are feeling.
Entities added to the national list in 2025 have eighteen months from receipt of their inclusion notice to adopt baseline security measures. The eighteen-month term appears in the text of the ACN determination notified to the European Commission, so it is solid. For the first wave of entities, that count lands in October 2026.
From that point the agency changes posture: the support phase ends and verification and inspection begin. For essential entities supervision is ex ante — they do not wait for something to go wrong. For important entities it is ex post.
And baseline security measures include supply chain security management. Which translates as: your client has to demonstrate to the agency that they did something about you. Saying they have known you for twenty years and you are good people does not count.
Hence the questionnaire. And hence the fact that it arrived late, badly built and with unreasonable deadlines: many of them are behind schedule and are pushing their own scramble downstream.
Knowing this changes the conversation. You are not dealing with a client trying to squeeze you: you are dealing with a client who has a documentation problem and a date on their back. That is a negotiating position, not an ultimatum.
The lever almost no supplier uses: requirements must be scaled
This is the most useful part of the article, and it is worth reading twice.
In July 2026 the agency updated its FAQs on supply chain security measures. The content, as reported consistently by several independent professional sources, sets out a principle that overturns the copy-paste questionnaire practice: a NIS2 entity must not push the entire set of baseline security measures onto its suppliers, nor the full body of obligations that applies to itself.
Requirements must be selected and scaled according to the risk actually associated with that specific supply, its criticality and the context — including, explicitly, dropping whole categories of measures where they are not relevant.
The process the client is supposed to follow has four stages: assess the risk associated with the supply, identify security requirements proportionate to that risk, embed them in the contract, and verify compliance over time.
What most suppliers receive instead is a single questionnaire, identical for the data centre operator and for the company delivering canteen meals.
If the package you were sent is manifestly disproportionate to what you actually touch, you have a documented basis to renegotiate it. This is not a commercial objection along the lines of "that is too much": it is an argument grounded in how the agency says the process should be run.
The phrasing that works, in our experience, is this: ask in writing which risk assessment led them to assign your supply that level of requirements. In most cases that assessment does not exist, because the questionnaire was bought or downloaded. And the conversation immediately moves to more reasonable ground.
What they are actually asking
Length aside, these questionnaires systematically cover seven areas. Knowing them in advance lets you prepare once instead of chasing every client.
Access management. Who has access to what, how accounts are created and revoked, whether multi-factor authentication is in place, how administrative and third-party accounts are handled.
Backup and restore. Not whether you take backups — everybody says yes. Whether you have tested a restore, when, with what outcome and who was there. This is where more than half of companies fall over.
Incident handling. Whether a written procedure exists, who triggers it, how quickly you notify the client, how you classify severity.
Business continuity. What happens if everything stops for three days. Whether a plan exists and whether it has ever been rehearsed.
People security. Training, awareness, joiners and leavers procedures.
Systems security. Patching, vulnerability management, network segmentation, endpoint protection.
Your own subcontractors. Who the critical ones are, and what you have done about them. Yes: the chain continues below you too.
How to answer well: a dossier, not a scramble
The most common mistake is answering ad hoc, from scratch every time, with the sales lead forwarding questions to the IT person over WhatsApp the night before the deadline.
What works is building a reusable response dossier, once, and then adapting it. It lets you answer in three days rather than three weeks, and above all it lets you answer different clients consistently — because if two of your clients compare notes, and in your industry they do, contradictory answers are a problem.
The minimum dossier contains: a two or three page information security policy approved by management, the access management procedure, evidence that multi-factor authentication is enabled on exposed services, backup documentation including the record of the last restore test, an incident handling procedure with client notification timings, a business continuity plan, evidence of staff training with dates and attendees, and a list of your critical subcontractors.
It does not need to be perfect. It needs to exist, to be dated, and for somebody in the company to know where it is.
One note worth the money it costs: do not start with certification. ISO/IEC 27001 can be an efficient answer if many clients ask for it and if your questionnaire volume justifies the investment. But it is not a NIS2 legal obligation, it does not replace the specific evidence your client has to collect, and spending thirty or forty thousand euro to end a discussion with a client worth 4% of your revenue is a decision to take with the numbers in front of you, not under pressure.
Contract clauses: what to check before signing
The questionnaire is the visible part. The part that stays with you for years is the contract. Five points worth half an hour with somebody who understands them.
Audit rights. It is legitimate for the client to ask. It is not legitimate for them to be unlimited. Negotiate scope (which systems, which sites), notice (ten working days is reasonable), frequency (once a year absent an incident) and who pays. An unlimited audit right over a small supplier is a clause that, if actually exercised, stops your business.
Incident notification timings. This is where the most dangerous commitments get signed. If you do not have a 24/7 operation, do not sign a one-hour notification obligation: you are promising something you cannot deliver, and on the day it actually happens you will be in breach as well as under attack. Ask for timings compatible with your real structure — "within 24 hours of triage during business hours" is a defensible formulation for many SMEs.
Liability. Check whether the contract makes you liable for indirect damages or for the client's production downtime. A cap tied to contract value is normal; unlimited liability on a forty-thousand-euro-a-year contract is not.
Subcontractors. Many contracts require you to disclose and sometimes to obtain approval for subcontractors. If you work with freelancers or technology partners, understand upfront what you are accepting.
Consequences of non-compliance. Distinguish between "the client may request a remediation plan" and "the client may terminate with immediate effect". Those are two different worlds.
What you actually risk (and what you do not)
Let us get the proportions right, because commercial narrative on these topics tends to inflate.
You do not risk NIS2 fines. The penalties in the Italian decree — up to 10 million euro or 2% of annual worldwide turnover for essential entities, and 7 million or 1.4% for important ones — apply to entities on the lists. Not to you, who are not on them. Anyone telling you those figures apply to you is selling something.
You do not automatically become a NIS2 entity by virtue of being declared a relevant supplier. The decree does allow the authority to bring entities into scope on the basis of how critical their supply is, which makes it plausible in future, but as of today no source states that inclusion is automatic. Anyone telling you otherwise is running ahead of the facts.
You risk the contract. That part is real. Clauses conditioning renewal on compliance are becoming standard practice, and a client facing inspection who cannot document what they did about suppliers has a direct incentive to replace the ones who did not answer. The risk is not a fine: it is revenue.
So size the investment commercially, not legally. Work out what share of your revenue depends on clients subject to NIS2, DORA or public tenders. That percentage is the measure of what it is worth spending.
To do this week
- Ask your main clients in writing whether they included you in the relevant supplier list sent to the agency, and under which criterion. It is information that concerns them and they normally share it without difficulty.
- Map the exposure: how much revenue depends on NIS2 entities or public contracts.
- Collect what you already have. Many companies have tested backups, MFA and procedures but never wrote them down. Half the work is documenting things you already do.
- Before answering the next questionnaire, ask which risk assessment generated it.
- Do not sign notification timings you cannot meet.
Questions we get asked
A client put us on a list sent to the agency without telling us. What can the agency do? Will we be inspected?
The listing gives the agency a map of the country's critical dependencies, not a basis for opening proceedings against suppliers. It creates no obligation for you, and the agency is not expected to inspect you in your capacity as a supplier. The one who will come asking is the client.
We are not on the NIS list. If something goes wrong, who pays the fine — us or our client?
Your client. The penalties in the decree apply to entities on the lists, and you are not on them. What you are exposed to is contractual: penalties, non-renewal, replacement.
A client worth 4% of our revenue sent a 180-question form. Can I say it is disproportionate without losing the contract?
Yes, and you have grounds. The agency's FAQs establish that requirements must be scaled to the actual risk of the supply, up to excluding entire categories of measures. Ask in writing which risk assessment produced that questionnaire: in most cases it does not exist, and the conversation moves to reasonable ground.
Should we just get ISO 27001 and be done with it?
It depends how many clients ask for it. It is not a NIS2 obligation and it does not replace the specific evidence your client still has to collect. At two questionnaires a year it costs more than the disease; at twenty it starts to make sense.
The contract includes audit rights. Can they show up whenever they like?
Only if you sign it that way. It is normal for a client to ask for verification rights; it is not normal for them to be unlimited. Negotiate scope, notice, frequency and who pays. Ten working days' notice, once a year absent an incident, is a defensible position.
They want incident notification within one hour and we have no night cover. What can we accept?
Not that. Signing a deadline you cannot meet means being in breach on the worst possible day. Propose a term anchored to your actual operation — twenty-four hours from triage during business hours, for instance — and put it in writing.
Who decides whether our supply is "non-substitutable"? Can we challenge it?
The client assesses it, based on the impact an interruption would have on their operations. You can discuss it, but first ask whether you want to: being considered irreplaceable is a strong commercial position, not just a bureaucratic nuisance.
Do we have to send the same questions to our own suppliers?
For genuinely critical supplies, yes — and it is one of the things your client will ask you to evidence. It does not take a questionnaire: it takes knowing who they are, what happens if they stop, and having a written answer from them.
A note on sources
There is a lot of imprecision circulating on this topic, so let us be straight about it. The eighteen-month term for adopting baseline measures is confirmed by the text of the ACN determination notified to the European Commission's TRIS system. The April 2026 determination on listing relevant suppliers, the 15 April – 31 May 2026 window and the July 2026 agency FAQs on scaling requirements are reported consistently by several independent professional sources, but the agency portal was not machine-readable at the time of writing: if you are making a contractual or spending decision, have the original text checked on acn.gov.it.
No NIS2 penalties have been publicly documented in Italy to date.
If you want a hand
We work with SMEs in north-east Italy and Milan who are in exactly this position: solid suppliers, technically fine, who never needed to write down what they do. The useful work is almost always less than they fear — and it only has to be done once.
If a questionnaire has landed on your desk and you want to understand what to answer before committing, get in touch: we will look at what they are actually asking together.
Related articles: