Skip to main content
web60

Infrastructure

The NIS2 Supplier Questionnaire: A Law Ireland Has Not Passed Is Already on Your Desk

Graeme Conkie··14 min read
Flat illustration of a single small teal node connected by one line into a large dense grid of teal and navy nodes on a warm off-white background

The email arrives with the subject line "Supplier Assurance Review". Attached is a spreadsheet: forty-odd questions across six tabs, asking about multi-factor authentication, backup testing intervals, incident response times, sub-processors, and exactly where customer data is stored. The business owner opening it runs a precision engineering shop in Meath that machines components for a medical device plant. Eleven staff. Twenty-two years of trading. He has never heard of NIS2, and the form gives him fourteen days.

That scene is a composite, assembled from a conversation that now repeats across the country. None of it is unusual any more.

What catches people out is where that obligation comes from. The rule forcing that spreadsheet onto his desk is a piece of EU law that Ireland has still not written into Irish law. He is not being regulated. This is procurement.

A directive with no Irish statute, and it reaches you regardless

The NIS2 Directive, formally Directive (EU) 2022/2555, set 17 October 2024 as the deadline for member states to transpose it into national law. That date sits on the European Commission's own policy pages and has not moved since. Ireland missed it.

The General Scheme of the National Cyber Security Bill was published on 30 August 2024. As of the middle of September 2026, no bill carrying that name has been introduced in either House of the Oireachtas, which puts Ireland nearly two years past a deadline it has not yet met. The National Cyber Security Centre confirms the position on its own NIS2 page, noting that Ireland "continues to work through the transposition requirements of the Directive" while the older NIS1 framework stays in force for entities already designated under it.

So there is no Irish NIS2 statute. No registration portal has opened. Nobody from an Irish enforcement body is coming to fine a precision engineering shop in Meath.

And yet the spreadsheet is real.

Why you are out of scope and on the hook at the same time

NIS2 applies to medium-sized and large entities operating in eighteen critical sectors: energy, transport, banking, health, water, digital infrastructure, manufacturing of critical products, postal and courier services, public administration and the rest.

The size test matters more than most people realise. An Oireachtas Library and Research Service briefing paper on the National Cyber Security Bill sets it out clearly: an entity is in scope if it qualifies as a medium-sized enterprise or larger under Article 2 of the Annex to Recommendation 2003/361/EC, meaning it employs between 50 and 250 people with annual turnover between €10 million and €50 million, or a balance sheet total up to €43 million. Above those ceilings you are a large enterprise and in scope by default.

Eleven staff and a machine shop does not come close. Neither does most of the country's business base.

But read Article 21(2)(d), which the same Oireachtas briefing quotes directly. In-scope entities must take measures covering "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers".

Direct suppliers. That is the whole mechanism, sitting in one subsection. Your customer carries the duty. They discharge it by pushing it down the chain as a questionnaire, a contract clause, or a request for evidence. Article 21(3) tightens the screw further by requiring them to weigh the vulnerabilities specific to each direct supplier and the overall quality of that supplier's cybersecurity practices.

What that means at street level is simple and slightly brutal. Nobody from a state body is coming to inspect your systems. Your customer's procurement team is, and they do not need a commencement order to act. They need a signature on a renewal.

Flat illustration of a large teal mass funnelling downward through progressively narrowing channels into a small shape at the bottom
The duty sits with the large entity. The questionnaire lands on the small supplier.

What the form is actually asking

Almost every supplier questionnaire in circulation is a reworded version of the same ten baseline measures in Article 21(2). Once you recognise them, a forty-question spreadsheet stops looking arbitrary. In plain English, your customer is asking:

  • Do you know what you are protecting? Risk analysis and information system security policies. If you cannot list where customer data sits, you cannot claim to be protecting it.
  • What happens when something goes wrong? Incident handling. They want a person, a contact route and a rough response time, not a promise.
  • Can you come back from a bad day? Business continuity, backup management and disaster recovery. An untested backup is an assumption, and assumptions fail at the worst possible moment.
  • Who else touches this work? Supply chain security. Your own subcontractors and software vendors are now part of their risk picture.
  • How do you handle known holes? Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
  • How do you know any of this works? Policies and procedures to assess the effectiveness of your own measures.
  • Are your people trained? Basic cyber hygiene practices and cybersecurity training.
  • Is data encrypted? Policies on the use of cryptography and, where appropriate, encryption.
  • Who has access, and who used to? Human resources security, access control and asset management. The departed employee whose login still works is a classic finding.
  • Is multi-factor authentication switched on? Along with secured communications where appropriate.

Not one of those questions is unreasonable. Most of them are things a careful owner-operator half does already without writing it down. The failure is rarely the security itself. It is the evidence.

For context on how fast this area is moving, EU rules on vulnerability handling and disclosure have already started landing on ordinary business software, which we covered when EU vulnerability disclosure obligations reached Irish WordPress operators. NIS2 is the same regulatory current arriving through a different door.

The question that turns your hosting into someone else's compliance record

This is the part almost nobody sees coming, and it is specific to Ireland.

Head 21 of the General Scheme goes further than NIS2 Article 3 requires. It provides that in-scope entities may be required to supply the National Cyber Security Centre, on request, with the names of their service providers where those providers underpin an essential or important service. The list in the General Scheme is explicit: cloud computing service provider, data centre service provider, public electronic communications network provider, electronic communications service, managed service provider, managed security service provider, and technology vendor.

Read that again with your own supplier relationship in mind. If you build or host a website, a portal or a customer-facing system for an in-scope customer, the company you host with stops being a private procurement decision. It becomes a name your customer may have to hand to a state body.

That changes the calculation. "Some reseller panel, I think it renews in March" is not an answer anyone wants to write on a form going to the NCSC.

A defensible answer has a shape to it. You should be able to name the provider without checking an old invoice. Which country the data physically sits in should be something you can state without hedging. Backups should run on a schedule you can describe, with restores that have actually been tested rather than assumed. Updates should happen on a cadence somebody owns. There should be a real human to ring when something breaks, in a timezone that overlaps with your working day.

That is the standard. It is not an exotic one. Plenty of providers fail it anyway, which is exactly why the question is on the form.

It is also, as it happens, the reason we built Web60 the way we did. Every site runs on SmartHost's sovereign Irish cloud, so "where is the data" has a one-word answer. Nightly backups run automatically with one-click restore and pre-update safety snapshots. Support is handled by an Irish team of actual people. If you want the infrastructure detail in the form your customer's procurement team will ask for it, our Irish-hosted managed WordPress stack and what sits underneath it is documented rather than summarised. Whether a site costs €60 a year or €6,000 to build, the assurance questions are identical, and only one of those numbers leaves budget for answering them properly.

The honest limitation: your host answers maybe a third of it

This is where I would push back on anyone selling hosting as a compliance solution, including us.

Look back at those ten measures. A hosting provider can answer the infrastructure ones: data location, backup schedule, restore capability, server hardening, SSL, malware scanning, patching of the server stack. Call it a third of the form, and the third that is easiest to evidence.

The rest is you.

Nobody else can tell your customer whether your staff use multi-factor authentication on their email. No host controls whether the laptop in the van has full-disk encryption, whether the lad who left in March still has a login, whether anyone has written down what happens when a ransomware note appears on a Sunday, or whether your own subcontractor has ever been asked a single security question. Those answers live inside your business, and a questionnaire will find the gap whether or not your hosting is excellent.

The practical consequence: sort the infrastructure so it is a two-minute answer, then spend your effort on the access control, training and incident response questions, because those are the ones that will cost you the contract. A tested backup and restore routine is worth more on one of these forms than any certificate, precisely because it can be demonstrated.

Overlapping translucent circles in teal and navy on warm grey suggesting layered responsibility between two organisations
Infrastructure answers are the easy third. The rest sits inside your own operation.

Where a bigger provider genuinely beats us

If your customer's procurement team will not accept anything short of a formal attestation report, an ISO 27001 certificate or a SOC 2 Type II with a named auditor, then premium enterprise managed hosting providers are genuinely built for that and we are not. They maintain audit programmes, publish assurance reports, and will negotiate bespoke data processing agreements with a customer's legal team. If you are a supplier sitting deep inside a regulated chain where an attestation document is a hard gate, pay for that. It is the right tool.

That is a real distinction, and it is worth being straight about it. For the large majority of businesses receiving these forms, the questions are proportionate and the evidence required is practical rather than certified. Article 21(1) itself requires measures to be proportionate to the entity's size, exposure and risk. A supplier assurance review of a company with eleven staff should not, and usually does not, demand the same paperwork as one aimed at a multinational.

A mistake worth admitting

Some years back I treated one of these assurance forms as procurement noise and sent back a short, dismissive answer. It was not arrogance so much as misreading the audience. The same question came back six months later with a named contact, a deadline and a clear implication about the renewal. Now I treat the first one as the cheap version of a conversation that only gets more expensive.

What to do before the next one lands

The thing about supplier questionnaires is that the deadline is never generous, and you cannot build a security posture inside fourteen days. You can, however, assemble evidence in advance.

The NCSC recommends the CyberFundamentals framework, known as CyFun, as a structured, voluntary route for organisations working towards NIS2-aligned measures. It is built on the NIST Cybersecurity Framework and runs across three assurance levels, Basic, Important and Essential, so a small supplier is not measured against the same bar as a utility. The NCSC describes it plainly as a business enabler in supply chains, which is an unusually honest framing for a government framework.

One caveat, and it is a real one. A national certification system takes an estimated 18 to 24 months to stand up, so a formal Irish certificate is not something you can obtain this quarter. The framework is usable now regardless. Work through the Basic level, write down what you find, and you will have answered most of the spreadsheet before anyone sends it to you. The NCSC also recognises ISO 27001 and other international standards where an organisation already holds them.

Nothing here requires a consultant on retainer. It requires a morning, a document, and a willingness to write down what you actually do.

Conclusion

The odd thing about NIS2 in Ireland is that the absence of a statute has made almost no difference to who feels it. No bill has been introduced, the NCSC has no registration portal open, and a small supplier faces no Irish penalty. Meanwhile the questionnaires keep arriving, because a customer's obligation under Article 21(2)(d) does not wait for the Oireachtas.

Which means the practical question was never "does this law apply to me". It is whether you can describe your own security clearly enough that a procurement team ticks the box and moves on. Most businesses can, once somebody writes it down. The ones that lose contracts over this rarely lose them because their security was poor. They lose them because nobody could answer the question in time, and the work quietly moved somewhere that could.

The form will come. You get to decide now whether it takes you an afternoon or a fortnight.

Frequently Asked Questions

Does NIS2 apply to my small business in Ireland?

Almost certainly not directly. NIS2 applies to medium-sized and large entities in eighteen critical sectors, and the size threshold starts at roughly 50 employees with turnover above €10 million. A business below that is out of scope. You can still be affected indirectly, because in-scope customers must manage security across their direct suppliers under Article 21(2)(d), and they do that by sending you questionnaires and contract clauses.

Has Ireland passed a NIS2 law yet?

No. The General Scheme of the National Cyber Security Bill was published on 30 August 2024, but as of September 2026 no bill of that name has been introduced in either House of the Oireachtas. Ireland's EU transposition deadline was 17 October 2024. Until the legislation is enacted, the older NIS1 regime continues to apply to entities already designated under it.

Can I refuse to complete a supplier security questionnaire?

You can, but it is a commercial decision rather than a legal one. Your customer is using the questionnaire to discharge its own obligation, so a refusal usually reads as an unmanaged risk on their register. In practice the contract does not get cancelled dramatically. It quietly fails to renew.

What do these questionnaires usually ask about?

Most are reworded versions of the ten baseline measures in Article 21(2): risk policies, incident handling, backups and disaster recovery, supply chain security, vulnerability handling, effectiveness reviews, cyber hygiene training, encryption, access control and asset management, and multi-factor authentication.

Does my web hosting provider matter for this?

More than most people expect. Head 21 of Ireland's General Scheme would let the NCSC ask in-scope entities to name their cloud, data centre, managed service and technology providers where those underpin an essential or important service. Being able to name your provider, state which country the data sits in, and describe your backup and restore process covers several questions at once.

What can I do to prepare before a questionnaire arrives?

Work through the NCSC's recommended CyberFundamentals framework at the Basic level and document what you already do. Confirm where your data is hosted, verify that a backup restore actually works, switch on multi-factor authentication everywhere it is available, remove logins belonging to people who have left, and write a one-page incident response note with a named contact.

Sources

Graeme Conkie
Graeme ConkieFounder & Managing Director, Web60

Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.

More by Graeme Conkie

Ready to get your business online?

Describe your business. AI builds your website in 60 seconds.

Build My Website Free →
Buy NowTry Free
The NIS2 Supplier Questionnaire Nobody Warned You About | Web60