NIS2 obligations propagate by contract. What your client's security questionnaire really asks, what you must have, what is negotiable, and a model reply.
Your company is too small for NIS2. You checked: you are not in the annexes, you are under the size caps, no regulator has ever written to you. Then one morning procurement at your biggest client forwards you a PDF titled something like "Supplier Cybersecurity Assessment, NIS2 Directive", forty questions, two weeks to answer, and a new contract annex attached. Nothing went wrong. This is the directive working as designed. NIS2 regulates roughly twenty thousand entities in Italy alone, and each of them is legally required to manage the security of its direct suppliers. The obligation does not stop at the perimeter: it propagates outward through contracts, to companies the law never names. In 2026 that second wave is exactly where the action is. I spend a good part of my consulting time on the receiving end of these questionnaires, so this article is written from that side: what the…