NIS2 reaches you through your customers, even without a direct duty
If you sell to essential or important entities in the EU, NIS2 reaches you through the supply chain. Your customers must secure their providers and pass the security requirements down via contracts, audits and questionnaires. We make you ready to answer: a NIS2-aligned ISMS, prepared supplier answers and an audit-ready evidence pack.
Lead Auditor ISO 27001DE · FR · ENsecurity as a sales enabler
For SaaS vendors selling to essential and important entities in the EU
ISO 27001 / ISMS
set up NIS2-aligned
Supply chain
flow-down to you
Evidence pack
for customer due diligence
vCISO
answers questionnaires
CH · EU
multilingual DE/FR/EN
Responsible for this mandate
Philipp Staiger
M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)
Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.
Many SaaS vendors are not directly in scope of NIS2. The requirements still land on your desk, because your customers must pass them on.
NIS2 is an EU directive. It binds entities with an establishment in the EU and classifies them as essential or important entities, for example in energy, health, finance, digital infrastructure and public administration. These entities must run risk management, report incidents and explicitly govern the security of their supply chain.
This is exactly where you come in. If a customer is an essential or important entity, it must assess and contractually secure the security of its providers and service vendors. As a SaaS vendor you are part of that supply chain. The NIS2 requirements therefore reach you as a flow-down: through contract clauses, audit and inspection rights and security questionnaires in the procurement process.
Some SaaS, cloud and managed-service offerings are themselves in scope, for example as digital infrastructure or as providers of managed ICT services. Whether you are directly covered depends on activity, size and EU establishment. We assess that case by case, instead of broadly reassuring or dramatising.
Important for Swiss vendors: NIS2 is EU law that Switzerland has not transposed into national law. The Swiss reporting duty for cyber incidents affecting critical infrastructure, under the Information Security Act and the BACS, is a separate, distinct obligation. We keep both layers cleanly apart, so you can argue correctly and without confusion towards EU customers.
How we make you ready to answer
The goal is not a binder of paperwork, it is that you pass your customers' supplier due diligence quickly and confidently, so the deal does not stall in procurement.
We set up a NIS2-aligned ISMS based on ISO 27001 that covers the security measures NIS2 expects from suppliers: risk management, access control, encryption, vulnerability and patch management, backup and recovery and defined processes for handling incidents. On request we bring the ISMS to certification readiness, the certification itself is issued by an accredited certification body.
In parallel we prepare your supplier-security answers. We map your customers' typical NIS2 expectations to concrete contractual building blocks and evidence and store agreed wording, so audit and inspection rights, incident reporting channels and sub-contracting relationships are cleanly governed.
The result is an audit-ready evidence pack: ISMS evidence, a description of measures, results from penetration tests and vulnerability scans, a sub-processor list and prepared answers to recurring questionnaire items. So you answer supplier reviews in days instead of weeks and reuse the content across multiple deals.
On request a vCISO takes over the ongoing upkeep: keeping the evidence pack current, supporting customer audits and answering security questionnaires, so sales and engineering are relieved. A legally grounded data-protection part, for example data-processing agreements and data-residency statements, we coordinate from the same mandate.
Why SIDD for NIS2 in your supply chain
You need a partner who understands the EU requirement, translates it into evidence and speaks with your customers on equal footing.
ISMS from a lead auditor
Your NIS2-aligned ISMS is set up by an ISO 27001 lead auditor. We know which measures and evidence hold up in a customer review and build them audit-ready from the start.
Supply-chain flow-down translated
We translate your customers' NIS2 expectations into concrete contractual building blocks, measures and answers. So you do not respond to every questionnaire from scratch, you maintain a reusable baseline.
CH and EU cleanly separated
We keep NIS2 as EU law and the Swiss reporting duty under the Information Security Act and the BACS clearly apart. So you argue correctly towards EU customers and avoid mistaken commitments.
vCISO relieves your team
A vCISO keeps the evidence pack current, supports customer audits and answers security questionnaires. Sales and engineering stay focused, while security becomes a selling point.
Audit-ready evidence in tooling
We maintain measures, the sub-processor list and evidence in the Swiss Priverion Platform. When a customer asks, the current state is ready as maintained tooling, not as scattered files.
Multilingual & independent
We answer audits and questionnaires in German, French and English, relevant for EU customers and their parent companies. Because we do not sell an in-house SOC, our recommendations stay independent.
NIS2 Supply-Chain Readiness
NIS2 Supply-Chain Readiness
Fixed fee on request
You become ready to answer your customers' NIS2-driven supplier review: ISMS, contract and control mapping and an audit-ready evidence pack.
Scoping workshop: directly in scope or affected through the supply chain, a clear classification instead of a blanket statement
NIS2-aligned ISMS based on ISO 27001, with the measures expected from suppliers
Mapping of NIS2 expectations to contractual building blocks: audit and inspection rights, reporting channels, sub-contracting
Evidence pack: ISMS evidence, description of measures, test results, sub-processor list, prepared questionnaire answers
IT-security workshop for management, sales and engineering, so answers stay consistent
Optional: ongoing vCISO support with audit accompaniment and questionnaire answering
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your evidence pack, concretely: LexCommand runs each incoming NIS2 security questionnaire from Excel or DOCX and returns a source-backed answer per question, and it maps the NIS2 supplier expectations onto the matching ISO 27001 measures, so you pass customer reviews faster and more consistently.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
We are not in scope of NIS2. Does the directive still affect us?
In practice, yes. As soon as a customer is an essential or important entity, it must secure its supply chain and passes the security requirements down to you via contracts, audits and questionnaires. So you are reached through the flow-down, even if the directive does not bind you directly.
Could we also be directly in scope of NIS2?
Possible. Some SaaS, cloud and managed-service offerings themselves count as digital infrastructure or as providers of managed ICT services. Whether you are directly covered depends on activity, size and an establishment in the EU. We assess that case by case in the scoping workshop, instead of a blanket all-clear.
Does NIS2 apply to us as a Swiss vendor?
NIS2 is EU law that Switzerland has not transposed into national law. It binds entities with an establishment in the EU. As a Swiss vendor, NIS2 reaches you mainly through EU customers in the supply chain. The Swiss reporting duty for critical infrastructure under the Information Security Act and the BACS is a separate, distinct obligation.
Do we need an ISO 27001 certification for this?
Not necessarily. Many customers accept a well-run, NIS2-aligned ISMS with solid evidence. A certificate often shortens the review, however, because it counts as recognised evidence. On request we bring your ISMS to certification readiness, the certificate itself is issued by an accredited certification body, we consult and accompany.
Do you also answer the security questionnaires for us?
Yes. In the optional vCISO mandate, a vCISO keeps the evidence pack current, supports customer audits and answers recurring security questionnaires with consistent, evidenced statements. So your sales stay fast and your engineering stays undisturbed.
Are you a managed-SOC provider?
No. We are a governance, compliance, assessment and readiness partner with an in-house technical team for penetration tests and vulnerability scans. We coordinate 24/7 monitoring with specialised providers, which keeps our recommendations independent.
Related topics
Dive into the building blocks your customers most often want to see in a review: