A long-time customer of yours emails on a Wednesday afternoon. Subject line: "Annual supplier security review — please complete by end of month." Attached: a sixty-question Excel sheet, three policies they want signed copies of, and a list of sub-processors they want disclosed.
Two years ago you got something like it but shorter. Last year it was a slightly longer version. This year it's longer still, with terms like Article 21(2)(d) and sub-processor lineage that weren't there before.
The customer hasn't become difficult. They've become NIS2-regulated. And you're in their supply chain.
This post is for the supplier sitting at that desk. It explains why the questionnaire got longer, what to do about it, and how to make next year's version easier than this year's — without hiring a consultant for every request.
Why this is happening
NIS2 — the EU's expanded cybersecurity directive — is in force across the EU, with enforcement ramping through 2025 and 2026. Article 21(2)(d) specifically requires every covered entity to assess and document the cybersecurity posture of its direct suppliers. "Document" is the operative word — your customer can't just trust you, they have to show the regulator that they assessed you.
That's why the questionnaire got longer. It's not paranoia. It's the difference between an internal trust signal and a defensible regulator artefact.
The five-step flow — what to actually do
Most people answer questionnaires badly the first three times and well from the fourth onwards. The difference isn't skill; it's having a small library of already-answered evidence to pull from. Here's the flow that makes the fourth time easy.
1. Read the whole thing first. Don't answer anything yet.
Skim every question before you start typing. You're looking for three things:
- Repetition. The same question asked three different ways. Answer it once and copy the answer.
- Out-of-scope items. Questions about systems your customer doesn't actually use, or services you don't actually provide. Mark these as "not applicable" with a one-line reason — don't leave them blank.
- Genuine information requests. The remainder — usually fewer than half the questions — that need a real, considered answer.
Reading the whole thing first stops you from answering question 8 differently from question 41 when they're effectively asking the same thing. Inconsistency is the single most common reason customers send a questionnaire back for re-work.
2. Build a library — once. Reuse forever.
Most questions across most questionnaires have the same answers. ISO 27001 certificate copy. SOC 2 report (under NDA). Sub-processor list. Privileged access policy. Encryption statement. Incident response policy. Backup and disaster recovery summary. Data residency statement. Penetration test summary letter (most recent).
That's a list of ten or fifteen artefacts that satisfies eighty percent of every questionnaire you'll receive. Build it once. Store it in a folder named clearly. Version-control the documents. When a question hits, you're not writing — you're attaching.
Don't over-engineer this. A SharePoint folder, a Notion page, or a labelled Google Drive will do. The point is the artefacts exist and you can find them.
3. Map prior evidence to the new question.
For each genuine information request, ask: have I answered this before? If yes — for the same customer or a different one — copy that answer forward. Adapt only the specifics that change. Customers don't mind copy-pasted answers; they mind different answers to the same question across years.
If you genuinely haven't answered before, write the answer once, save it to your library, and use the same words next time.
4. Answer with provenance, not just text.
A good answer cites its source. "Yes, we have an information security policy approved by the board on 14 March 2025; copy attached." Not just "yes."
Provenance does three things:
- It tells your customer's reviewer they don't need to follow up to verify
- It establishes a date — useful when next year's questionnaire arrives
- It's defensible if the regulator later asks your customer how they assessed you
Where you can't share the underlying document (e.g. a SOC 2 Type II is usually under NDA), say so plainly: "Available on request under mutual NDA." That's a complete answer.
5. Submit and track.
Send what you've got, with a one-paragraph summary at the top: what you provided, what's under NDA and how to access it, what's genuinely not applicable. Note the date you submitted.
If your customer is using a structured platform like Vittnor — Supply Chain Assurance for the mid-market — you'll see when items are approved, sent back for clarification, or marked complete. If they're still on email and Excel, follow up at two weeks if you haven't heard.
What to have on file before the next request arrives
From the most-asked questions across NIS2-flavoured questionnaires we've seen this year, the artefacts to have ready (or know where to get fast):
- ISO 27001 certificate (if you have one) and Statement of Applicability
- SOC 2 Type II report (if you have one) — usually shareable under NDA
- Sub-processor list with the services each one provides
- Information security policy with version, owner, last-reviewed date
- Incident response policy / runbook and most recent test record
- Business continuity plan with last-tested date
- Privileged access management statement — who has admin, on what, reviewed how often
- Encryption-at-rest and -in-transit statement, including key management
- Most recent penetration test summary letter (often shareable; full report rarely is)
- Data residency / hosting statement, especially the EU-hosting bit
- MFA / training / access-review evidence — even simple screenshots-with-dates are valuable
- DPA template (GDPR Article 28-compliant)
That's your evidence library. Build it once. Maintain it lightly. Re-use it forever.
Common pitfalls
Don't answer questions you didn't understand. Ask. Customers appreciate a clarifying question more than a wrong answer.
Don't over-promise. "Yes, we have continuous penetration testing" when you have an annual external test is the kind of thing that comes back to bite you when an incident happens. Be specific. Be honest.
Don't treat each customer as a separate problem. The NIS2 evidence bar is broadly the same across regulated buyers; the questionnaires diverge in wording, not in substance. Build to the common denominator.
Don't silo this. The person filling in the questionnaire usually isn't the person who maintains the evidence. Establish a workflow between them — a weekly fifteen-minute sync is enough.
The economics
A typical mid-market supplier we've talked to receives between three and twelve NIS2-flavoured assurance requests per year. The first one takes a week. The fifth one, with a library in place, takes a day. The fifteenth, if you've invested in the library, takes hours.
That's the entire business case for treating supplier-side assurance as a workflow, not a fire drill. It's also why the supplier side of Vittnor exists — to give you the library and the workflow without you having to build them yourself. But you don't need our product to do this well. You need a folder, a discipline, and the patience to build the library once.
Next time the email arrives, you'll find yourself attaching, not writing. That's the goal.