NIS2 · Suppliers and SMEs

Prove It or Lose the Contract by Kai London

NIS2 does not regulate most suppliers directly. Their customers do it for it. If you sell to an essential or important entity, the security questionnaire, the contract clause and the evidence request have already arrived — and a weak answer now costs revenue. This guide is written for the supplier's side of that conversation.

Coming soonAll books

What the book covers

Why the demands arrive

How NIS2 Article 21 supply-chain duties flow down through customers into contracts and questionnaires.

Answering credibly

Writing questionnaire responses that are accurate, consistent and defensible rather than aspirational.

Proportionate controls

A minimum credible security baseline for a small or mid-sized supplier, and what to do first.

Evidence over assertion

Which artefacts — policies, logs, test results, certifications — actually satisfy a reviewer.

Contract terms

Notification windows, audit rights, subcontractor flow-down and liability language, and how to negotiate them.

Incidents as a supplier

Telling a regulated customer quickly and clearly when something has gone wrong.

General guidance, not legal advice; contractual and regulatory positions vary by jurisdiction and customer. Independent, with no endorsement by or affiliation with any regulator or standards body.

NIS2 Article 21ISO 27001NIST CSF 2.0Cyber Essentials

Who it is for

Owners and directors of supplier businesses, sales and bid teams, IT and security leads without a large compliance function, and procurement teams on the other side of the table.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.