An email lands in your inbox. Your biggest client (a hospital, a logistics company, an energy supplier) sends you a “supplier cybersecurity questionnaire”. Forty questions. About your backups, your incident detection, your logging, your access management. And at the bottom: “Please respond within thirty days.”
Your first reaction might be: but we’re not subject to NIS2, are we? Probably true. But that’s not the question. The question is whether your client is. And if so, you are now part of their problem, or part of their solution.
The law works through the chain
NIS2 has been in force in Belgium since October 2024. The law requires thousands of “essential” and “important” entities, from hospitals to food companies, to manage their cyber risks. And one of those risks is explicitly named in the law: the supply chain.
Concretely: a NIS2 entity must assess the cybersecurity of its suppliers and service providers. Not as a nice-to-have, but as a legal obligation, with the Centre for Cybersecurity Belgium (CCB) as supervisor and fines that can run into millions of euros. No compliance officer takes chances with that anymore.
The consequence is predictable. The obligation trickles downward. The hospital questions its software vendor. The software vendor questions its hosting provider. And the accounting firm that processes the hospital’s payroll? It receives the very same questionnaire. You don’t have to be in scope of the law to feel its consequences.
What actually gets asked
The questionnaires differ by sector, but the core keeps coming back:
- Do you know what’s running in your IT environment? An up-to-date inventory of systems, software and services.
- Do you notice when something goes wrong? Detection of outages and suspicious activity, preferably with demonstrable response times.
- Do you keep track of what happens? Event logging, and the ability to reconstruct afterwards what went wrong.
- How quickly are you operational again? Backups, recovery times, availability figures.
Note what is not being asked: an expensive certificate, a compliance department, a full-time security officer. What’s being asked is proof that you have your affairs in order.
Answering “no” is also an answer, and an expensive one
What happens if you send the questionnaire back empty or negative? Usually nothing dramatic right away. But at the next contract renewal, there’s a competitor on the table who could answer the questions. Supplier assessment isn’t a one-off formality; it’s becoming a permanent part of purchasing decisions. The question isn’t whether cybersecurity becomes an award criterion, but when you lose your first contract because of it, without anyone telling you.
Turn it around, and it becomes an asset. The SME that is first in its sector to answer “yes, and here’s the monthly report” effortlessly stands out from the rest.
Getting started without drowning
The good news: Belgium has, with CyberFundamentals (CyFun), a framework built precisely for this: a practical roadmap sized for SMEs, developed by the CCB. The Basic level covers the essentials: knowing what’s running, detecting problems, logging events, monitoring availability.
And it’s no coincidence that this is my line of work. Professional monitoring delivers a large part of those answers automatically: an inventory that keeps itself current, detection within the minute, logging you can present in black and white. Not as a paper exercise, but as a running system.
Have you received such a questionnaire, or do you want to get ahead of one? Book a no-obligation call and we’ll walk through what your clients will soon expect from you, and what can already be in place today.