Prove It or Lose the Contract by Kai London
NIS2 does not regulate most suppliers directly. Their customers do it for it. If you sell to an essential or important entity, the security questionnaire, the contract clause and the evidence request have already arrived — and a weak answer now costs revenue. This guide is written for the supplier's side of that conversation.
What the book covers
Why the demands arrive
How NIS2 Article 21 supply-chain duties flow down through customers into contracts and questionnaires.
Answering credibly
Writing questionnaire responses that are accurate, consistent and defensible rather than aspirational.
Proportionate controls
A minimum credible security baseline for a small or mid-sized supplier, and what to do first.
Evidence over assertion
Which artefacts — policies, logs, test results, certifications — actually satisfy a reviewer.
Contract terms
Notification windows, audit rights, subcontractor flow-down and liability language, and how to negotiate them.
Incidents as a supplier
Telling a regulated customer quickly and clearly when something has gone wrong.
General guidance, not legal advice; contractual and regulatory positions vary by jurisdiction and customer. Independent, with no endorsement by or affiliation with any regulator or standards body.
Who it is for
Owners and directors of supplier businesses, sales and bid teams, IT and security leads without a large compliance function, and procurement teams on the other side of the table.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.