NIS2
Guide
D.Lgs. 138/2024, art. 24
Updated 23 September 2026
by Victor Mita
Your client asks you for NIS2: what to do if you are a supplier
For companies that work for NIS entities without being one: why questionnaires and clauses arrive, what the ACN measures actually require and how to respond credibly.

In brief
If a client subject to NIS2 sends you a security questionnaire or new contract clauses, it is usually not the law that places the obligation on you: it is your client that must manage the risks of its own supply chain (Article 24(2)(d) of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition), and it does so by asking you for assurances. First check whether you are within the NIS scope yourself; then respond with facts and proof, not with generic statements of “compliance”. A clear, documented response helps you keep the contract at renewal too.
First question: are you a NIS entity yourself?
Many suppliers discover NIS2 through a client, but some are within the scope themselves. This often happens to those that provide IT services: the “digital infrastructure” and “ICT service management” sectors are in Annex I to the decree, and the scope generally starts from medium-sized enterprises upwards (FAQ REG.1). In addition, Article 3(9)(f) allows an entity to be included, regardless of size, if it is considered critical as a systemic element of the supply chain of essential or important entities.
This is also why ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) collects from NIS entities every year the list of their “relevant suppliers” (FAQ FRN.1). If you do not know which side you are on, the self-assessment gives you a first indication; the full picture is in the NIS2 guide.
Why your client is writing to you now
Your client must adopt the basic security measures of ACN Determination 379907/2025 by deadlines that are close: for those that entered the list in 2025, eighteen months from the notice, which means October 2026 for many (here is how it is calculated). Several measures concern suppliers directly. In Annex 1, for important entities, the client must:
- record its suppliers of supplies with potential security impacts, with the contact person for the supply and the type of supply (GV.SC-04);
- assess the risk of each supply, looking at least at your level of access to its systems, your access to data and intellectual property, the impact of an interruption, recovery times and costs, and your role in managing its systems (GV.SC-07);
- define security requirements consistent with its own measures and include them in offers, contracts and agreements (GV.SC-01, GV.SC-05);
- periodically verify and document that the supplies meet those requirements (GV.SC-07).
According to FAQ MSB.12, the requirements must be included in contracts signed, renewed or extended from the deadline for adopting the measures onwards. Existing contracts do not need to be rewritten, but the clauses will arrive at the first renewal.
Then there is the list for ACN. In the annual update, between 15 April and 31 May (FAQ AGA.1 and AGA.3), the client submits for each relevant supplier the company name, tax code (codice fiscale), country of the registered office, CPV codes of the supply and relevance criterion (Article 18 of ACN Determination 127437/2026, FAQ FRN.3). If it asks you for this data, that is why.
The questionnaire must be proportionate
Not all supplies are the same, and the ACN FAQs say so explicitly:
- security requirements need to be defined only for supplies with potential impacts on the security of the client's systems, not for all of them (FAQ MSB.15);
- there is no need to put all the requirements of the measures into contracts or to copy their text: those that emerge from the risk assessment, in their substance, are enough (FAQ MSB.16);
- the assessment is based on the criteria seen above, from the level of access to the impact of an interruption (FAQ MSB.14).
If you receive a two-hundred-question questionnaire for a supply that does not touch the client's systems, you can politely ask which risk assessment led to it. This is not a way of getting out of it: it is the same criterion that ACN asks the client to apply.
What you will probably be asked
The requests follow what the measures require of the client. Expect questions on:
- who your contact person is for the supply and how to reach them;
- what access you have to the client's systems and data, from where and with which credentials;
- multi-factor authentication, logs and updates on the systems you use to work for the client;
- your staff with access: the client must record the roles and responsibilities of third-party personnel in its organisation for security (GV.SC-02);
- how and how quickly you notify the client if you have an incident affecting its services: for ACN, the client must make sure the supplier promptly reports security events that affect it (FAQ ISB.F.1);
- continuity and recovery: what happens to the service if you stop;
- the right to verify what you declare over time.
On incidents, one thing is useful to know: if the incident occurs on the client's systems, even if you manage them, notification to CSIRT Italia (Italy's national CSIRT) is the client's responsibility. That is why the client needs to hear about it from you quickly. The timings and stages of notification are in the guide to incident notification in 24 and 72 hours.
How to respond credibly
- Start from what you actually supply. Describe in two lines the supply, the client systems you touch and the data you access. This is the basis of the risk assessment the client has to carry out.
- Respond with facts, not labels. The decree does not provide for any “NIS2 compliance” certificate for suppliers. “We have used multi-factor authentication on all remote access to your systems since 2025” is worth more than “we are NIS2 compliant”.
- Attach the proof you have. Approved policies, extracts from procedures, test results, existing certifications with scope and expiry date. If something is not in place, say so and state when it will be.
- Do not promise what you do not do. A questionnaire answer can end up in a contract, and then it becomes an obligation.
- Agree realistic reporting times. A commitment to inform the client within a few hours that you keep is better than an immediate one you cannot guarantee at night.
- Appoint a contact person and keep the details up to date: the client must have that contact in its inventory.
- Build a reusable file. Questions from NIS clients are similar. An up-to-date set of answers and documents saves you from starting again every time.
How Epic Assess helps you
Epic Assess is built for NIS entities, but the work it asks of your clients also helps you respond to them. You start from the ACN measures, prepare policies from drafts to complete and have approved, link the evidence, and can publish the adopted policies on a page reachable only through a link that you share and can revoke. It is not a certification and has no ACN recognition of any kind: it is an orderly way to show what you do.
Sources
The sources are official texts, published in Italian.
- Legislative Decree no. 138 of 4 September 2024 (Normattiva): Articles 3, 24, Annex I.
- D.Lgs. 138/2024 in the Gazzetta Ufficiale (Official Journal) no. 230 of 1 October 2024
- ACN, Modalità e specifiche di base (basic procedures and specifications) (ACN Determination 379907/2025)
- Annex 1, basic measures for important entities (GV.SC-01, 02, 04, 05, 07)
- ACN, NIS FAQ: misure di sicurezza e notifica di incidenti (security measures and incident notification) (MSB.12–MSB.16, ISB.F.1)
- ACN, NIS FAQ: registrazione (registration) (REG.1)
- ACN, NIS FAQ: aggiornamento delle informazioni (information update) (AGA.1, AGA.3, FRN.1–FRN.3)