A procurement email arrives with a Word document attached. Somewhere in it is a block of text about network and information systems security, a notification window measured in hours, a right to request evidence, and a demand that you flow the same terms down to your own subcontractors. Your customer is a mid-size European manufacturer, logistics operator or health provider. You are a fifteen person software company in Bengaluru, London or Singapore. Nothing about your regulatory position changed this week, and yet the clause is now yours to sign.
This is NIS2 flow-down, and it is the most common way a company that is not regulated ends up doing regulated work. The NIS2 Directive does not apply to you. It applies to your customer. It then obliges your customer to manage the cybersecurity risk you represent, and the only instrument they have for that is the contract they put in front of you.
Almost every article on NIS2 is written for the entity in scope. This one is written for the supplier who is not, because that is where the clause actually lands. What follows: what it demands, which parts a fifteen person team can answer this week, which parts need real engineering work, how this differs from SOC 2 and ISO 27001, and what changes when your company sits outside the EU.
Quick context: where you actually sit
NIS2 is Directive (EU) 2022/2555. Member states were required to transpose it into national law by 17 October 2024, and it splits covered organisations into two classes, essential entities and important entities, across eighteen sectors. Under Article 34 the fine ceilings are at least EUR 10 million or 2 percent of total worldwide annual turnover for essential entities, whichever is higher, and EUR 7 million or 1.4 percent for important entities. Article 20 puts the management body personally on the hook for approving and overseeing the risk-management measures, and requires them to take training.
You are probably neither class. What catches you is Article 21(2)(d), which makes supply chain security one of the minimum risk-management measures, and Article 21(3), which requires the entity to take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices, including their secure development procedures. No regulator is going to audit you. A regulator may audit whether your customer can show it managed you. That is the entire reason the clause exists.
1. The clause is your customer's Article 21 homework, handed to you
Read the clause as evidence generation, not as a negotiating position. Every sentence in it exists because your customer needs to be able to produce something in a file when a supervisory authority asks how supplier risk is managed.
The detail comes from Commission Implementing Regulation (EU) 2024/2690, which expands Article 21 into a long annex of specific controls. That regulation binds a defined set of digital infrastructure and digital service categories directly, including cloud providers, data centres, CDNs, managed service and managed security providers, DNS and TLD operators, online marketplaces and trust service providers. If you are one of those, it is your text too. If you are not, it still matters, because buyers and their law firms lift its language straight into supplier clauses.
Takeaway: map every sentence of the clause to the artefact your customer needs in their audit file, then answer with that artefact instead of with prose.
2. Nobody can sell you a NIS2 certificate
Say this plainly and early, because it saves a month. There is no NIS2 certification for an organisation. Article 21 sets obligations, and Article 24 allows member states to require in-scope entities to use ICT products, services and processes certified under European cybersecurity certification schemes established through the Cybersecurity Act, Regulation (EU) 2019/881. Those schemes certify products and services, not your company's compliance with a directive.
Practitioner opinion: any vendor selling you NIS2 certification is selling an audit against their own checklist. That can be a genuinely useful gap analysis, and it is worth paying for if you want one. It is not a certificate, and presenting it as one to an enterprise buyer is the kind of thing that gets discovered in the second procurement round rather than the first.
What to write in the questionnaire box instead: NIS2 is a directive placing obligations on in-scope entities and is not a certifiable standard, so no supplier can hold a NIS2 certificate, and here is our evidence pack against the clause terms.
Takeaway: replace the certificate question with an evidence pack, and put that sentence in your standard answer library today.
3. Decode the clause: the six things it is really asking
Strip the drafting and nearly every NIS2 supplier clause reduces to six asks. Sorting the text into these buckets is the fastest hour you will spend on it.
- A named security contact and a working incident channel. A person, an alias, and a route that functions outside business hours.
- Incident notification inside a fixed window. Usually expressed in hours from your awareness.
- A documented set of security measures applied to the contracted service. Policy, owner, review cadence.
- A right to request evidence, and sometimes a right to audit. These are two very different things and the clause often blurs them.
- Control over your own subcontractors, with the same terms flowed down. This is Article 21(3) reaching one layer past you.
- Notification of change. New subprocessors, new processing locations, change of control.
Takeaway: answer per bucket, not per sentence. Six well-evidenced bucket answers close a clause that looks like thirty separate questions.
4. The incident window is the term that will actually bite you
NIS2 Article 23 gives your customer a three-stage reporting duty for significant incidents: an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month, with the clock starting when the entity becomes aware. Because your customer's own 24 hour clock can be started by something happening inside your service, their supplier clause almost always compresses further, typically to 24 hours or less from your awareness.
Practitioner opinion: negotiate the trigger, not the number. Arguing the hours makes you look like you are trying to buy silence. Tightening the definition is both easier to win and more useful. "Becoming aware of a confirmed security incident affecting customer data or the availability of the contracted service" is a defensible trigger. "Any suspected security event" is an obligation to phone your customer about every failed login spike at 03:00 forever.
Then build the thing that makes the number survivable: a rota, an alias more than one person watches, and a one page notification template already written so nobody drafts under pressure.
Takeaway: a 24 hour clause with no on-call rota behind it is a contractual breach waiting for a bad weekend, so fix the rota in the same sprint you sign.
5. What a fifteen person team can genuinely answer this week
More of the clause is answerable from systems you already run than you expect. Each of these is an export, a screenshot or a table, and each takes hours rather than sprints.
- A supplier and subprocessor inventory. One table: vendor, what it does, what data it touches, processing region, link to the signed agreement.
- A named security contact plus a monitored alias. Two people minimum on the alias.
- MFA state. The enforcement policy in your identity provider and your cloud accounts, exported, with the date.
- Access review evidence. A dated export of who holds production access and who approved it.
- Backup configuration. Retention, region, encryption, plus the date of the last restore you actually performed.
- Patching and dependency scanning cadence. A link to a real pipeline run beats a paragraph describing your intentions.
Takeaway: a week of assembling answers six of the buyer's questions, provided you answer with exports rather than adjectives.
6. What needs real work, and how to say so
The rest is not a week. Audit rights need scoping and legal review. Documented secure development procedures need writing and then following. Log retention with tamper resistance is engineering. Business continuity and crisis management, both named in Article 21(2), need a plan that has been tested at least once. Flowing the clause down into your own vendor contracts needs your suppliers to sign something they have not seen yet.
Practitioner opinion: a dated remediation plan is accepted far more often than founders expect. Name the control, name the owner, name the date, and offer to report progress at an agreed checkpoint. Buyers under their own deadline pressure would rather have a supplier with a credible plan than a supplier with an unverifiable yes.
Takeaway: answer honestly with dates, because the only answer that reliably ends a deal is a yes that fails at evidence time.
7. Evidence, not promises: what documented actually means here
When the clause says documented, the buyer is not asking for length. They are asking for four fields that let their auditor treat the document as evidence: a version, an owner, an approval date, and a review interval. A one page policy carrying all four is worth more than a forty page template carrying none.
This is the shape the implementing regulation itself uses. It requires relevant entities to establish, implement and apply a supply chain security policy governing relations with their direct suppliers and service providers, and to keep it reviewed. ENISA has published technical implementation guidance on those measures, which is the most useful free document available for seeing what an assessor expects a control to look like in practice.
Takeaway: version, owner, approval date, review interval. Four fields turn a document into evidence.
8. How this differs from SOC 2 and ISO 27001, and what each still buys you
They are three different objects. ISO 27001 certifies a management system through an accredited body. SOC 2 is an attestation by an audit firm, and a Type 2 report covers a window of time rather than a moment, which is why enterprise buyers ask for it (we covered that distinction in SOC 2 Type 1 vs Type 2). NIS2 is a directive with obligations, no organisational certificate, and enforcement pointed at your customer.
So neither attestation is NIS2 compliance, and Article 24's certification route runs through European schemes rather than through ISO or SOC 2 equivalence. That is the legal picture. The practical picture is friendlier: an ISO 27001 certificate or a current SOC 2 Type 2 report answers most of the six buckets in a single attachment, and turns a four week clause negotiation into a two email exchange. The same is true of the questionnaire pattern we described in the security questionnaire gauntlet.
Takeaway: existing attestations are not NIS2 compliance, and they are still the fastest way to evidence most of what the clause asks, so lead with them where you have them.
9. The part non-EU suppliers get told late: Chapter V
If the contracted service touches EU personal data and your company sits outside the EU and EEA, the supplier clause is not your only European obligation. GDPR Chapter V governs the transfer, and it is a separate analysis from anything in NIS2.
As of September 2026 there is no adequacy decision for India. The European Commission's adequacy list covers Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for organisations in the Data Privacy Framework, Uruguay and the European Patent Organisation. India is not on it, and neither is a long list of other delivery locations.
That means an Indian provider, MatrixGard included, transfers under the 2021 Standard Contractual Clauses in Commission Decision (EU) 2021/914, plus a transfer impact assessment. Clause 14 of those SCCs requires the parties to assess local laws and practices affecting compliance, and EDPB Recommendations 01/2020 set out the six step method and are explicit that contractual and organisational measures often need technical measures alongside them. In practice: pick the correct module (usually Module Two for controller to processor, Module Three for processor to processor), write a short honest assessment, and add real technical measures such as EU region processing, encryption with key control, and pseudonymisation where the data model allows.
Takeaway: for a non-EU supplier this is the longest pole, so prepare the SCC module and a two page transfer impact assessment before the clause arrives, not after.
10. DORA, and the calendar that explains why the clause arrived now
If your customer is a bank, insurer, payment institution or another EU financial entity, the instrument is not NIS2 at all. It is DORA, Regulation (EU) 2022/2554, which has applied since 17 January 2025 and is considerably more prescriptive about contracts. Article 30 sets mandatory terms for every ICT contract and a heavier set again where the service supports a critical or important function, including full service level descriptions with quantitative targets, the locations where services are provided and data is processed, whether subcontracting is permitted and on what conditions, exit strategies, and participation in the entity's testing. Financial entities also maintain a register of information covering all ICT third-party arrangements, so your company name, your service and your processing locations are being reported upward.
Timing is national, and national deadlines are why the clause landed this quarter rather than last year. Italy is the clearest worked example. Its national cybersecurity agency, ACN, required listed NIS subjects to complete the categorisation of their activities and services on the ACN platform by 30 June 2026, and set the adoption of the basic security measures from its April 2025 determination for October 2026, after which ACN moves from a support posture to inspections. Other member states run their own clocks.
Takeaway: ask your customer which national deadline they are working to. The answer tells you how much room there is to negotiate and how fast they need your evidence.
The honest summary table
| What the clause asks for | Where it comes from | Answerable this week? |
| Named security contact and incident channel | NIS2 Art 21(2)(b), buyer clause | Yes, one day |
| Incident notification inside a fixed window | NIS2 Art 23 (24h, 72h, one month), compressed by contract | Yes to sign, only if a rota exists behind it |
| Supplier and subprocessor inventory | NIS2 Art 21(2)(d) and 21(3) | Yes, one to two days |
| MFA and access review evidence | NIS2 Art 21(2), CIR 2024/2690 annex | Yes, as exports not adjectives |
| Backup and a tested restore | NIS2 Art 21(2)(c) | Config yes, tested restore needs a scheduled test |
| Documented security measures policy | CIR 2024/2690 supply chain security policy | Yes, one page with owner and date |
| Evidence on request and audit rights | Buyer clause | No, scope it in legal review first |
| Secure development procedures | NIS2 Art 21(2)(e) and 21(3) | No, real engineering and writing work |
| Flow-down into your own vendor contracts | NIS2 Art 21(3) | No, needs your suppliers to sign |
| EU personal data leaving the EU | GDPR Chapter V, SCCs 2021/914 plus a TIA | No, longest pole for a non-EU vendor |
| A NIS2 certificate | Does not exist, Art 24 covers ICT product schemes | Nothing to produce, say so in writing |
Stage-specific recommendation
Pre-seed, under ten engineers, first EU enterprise customer: do not start a certification programme because of one clause. Build the evidence pack: subprocessor inventory, MFA and access review exports, backup and restore record, a one page security policy with an owner and a date, and a written incident notification procedure. That pack answers most of the six buckets and is reusable for every buyer after this one.
Seed, ten to forty engineers, several EU customers or one regulated one: the evidence pack stops scaling around the third clause. This is the point to pick one attestation and commit, usually SOC 2 Type 2 for US and UK buyers or ISO 27001 where the buyer base is continental European, and to get the SCC module and transfer impact assessment done properly if any delivery happens outside the EU.
Series A, selling to financial entities: read DORA Article 30 line by line before your next renewal, because the contract terms are mandatory for your customer and non-negotiable in substance. Budget for the exit strategy and testing participation clauses specifically.
If you want a second opinion on the clause in front of you
MatrixGard runs a free 20-minute review for early-stage founders holding a supplier security clause they did not expect. Your clause, your architecture, an honest read on which parts are a week of assembling and which parts are real work, and what to write back. No NDA required for the first conversation. Send a note, or start with the free scan.
Avinash S is the founder of MatrixGard. Fractional DevSecOps for early-stage startups, funded or bootstrapped, across India, the GCC, the UK and the US. Almost a decade of building, breaking and securing cloud infrastructure for fintech, healthtech and SaaS workloads.
Methodology note. Directive references are taken from the text of Directive (EU) 2022/2555 and Commission Implementing Regulation (EU) 2024/2690 as published on EUR-Lex, from Commission Decision (EU) 2021/914 for the standard contractual clauses, from Regulation (EU) 2022/2554 for DORA, and from the European Commission adequacy decisions page, checked on 7 September 2026. The Italian deadlines are the published position of ACN and are cited as one national example, not as EU-wide dates; other member states set their own. Everything described as a typical clause pattern, a negotiation approach or a sequencing choice is practitioner opinion and is labelled inline. This article is not legal advice; the drafting in front of you governs, and a clause with unusual terms deserves a lawyer who reads it.