FAQ
Regulatory Compliance

Are security questionnaires required by NIS2?

NIS2 does not prescribe a specific security questionnaire. It requires essential and important entities to implement appropriate and proportionate cybersecurity risk-management measures, including supply chain security. A questionnaire can support supplier due diligence, while the wider programme still needs risk-based oversight, evidence, monitoring and documented action appropriate to the organisation and its suppliers.