Compliance and Data ProtectionJune 23, 2026Serdar YAMAN5 min read

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?

TL;DR: Even if NIS2 does not bind you directly, it binds your EU customer — and tells them they are responsible for their suppliers' security. In practice that means security questionnaires, contractual security clauses and incident-notification commitments arriving at your door. The preparation list is known: core controls (MFA, tested backups, patching, an incident plan), written policy, and the ability to produce evidence; ISO 27001 is the tidiest single answer to all of it.

The European Union's NIS2 directive has been rolling out across member states since late 2024, imposing heavy cybersecurity obligations on companies across energy, manufacturing, food, logistics, healthcare and more. Before a Turkish SMB says "not our problem", note one article: in-scope companies must also manage the security of their supply chains. Your industrial customer in Germany, your distributor in Italy, your logistics partner in the Netherlands will meet that obligation by assessing the risk that comes from you — NIS2 crosses the border as contract annexes and supplier questionnaires.

Why Are They Asking the Supplier?

A large share of recent major cyber incidents started not at the target but at its supplier: service providers whose software updates were poisoned, vendors whose mailboxes were hijacked to send fake invoices, maintenance firms whose remote access was abused. Regulators turned that lesson into law: the NIS2-scoped company cannot escape liability by saying "my supplier was careless". So it must measure your risk, distribute it by contract, and demand evidence. Translated to your side of the table: your security posture is no longer an internal matter — it is part of your export qualification.

What the Requests Typically Contain

RequestWhat it means concretelyYour answer if prepared
Security questionnaireA 50–200 question form: policies, access, backup, incident historyA written policy set + technical evidence
Contract security annexesMinimum controls, audit rights, incident-notification deadlinesJoint legal + IT review, realistic commitments
Incident-notification clause"Notify us of any incident affecting you within X hours"A customer-notification step in your incident plan
Certification questionISO 27001 or equivalent?The certificate, or a stated roadmap
Access securityIf you connect to their systems: MFA, separate accounts, loggingA summary of your remote-access policy

Preparation: the Foundation Before the Questionnaire

What you need when the questionnaire lands is not blanks to fill but controls actually running in the business — serious customers do not settle for declarations, they ask for proof:

  • Identity and access: multi-factor authentication on all critical accounts; a process that demonstrably closes departed employees' access.
  • Backup and recovery: tested backups — the proof of "do you have backups" is not the backup itself but the record of the restore drill.
  • Patching and inventory: supported systems, a regular update cycle, a device inventory.
  • An incident response plan: who does what, in which order; where customer notification sits — written down and rehearsed.
  • Logging: records that can answer "what happened" after an incident.
  • Ransomware resilience: the questionnaires' favourite topic — layered defence, documented.

ISO 27001: One Answer to a Hundred Questionnaires

As your customer count grows, wrestling each one's different questionnaire becomes unsustainable. This is where ISO 27001 is leverage: an internationally recognised management-system certificate answers the bulk of most questionnaires in one line and strengthens your hand in contract negotiations. At SMB scale it is reachable through a reasonable project. For those not investing in certification yet, the interim formula: build a genuine posture that lets you say "we base our controls on ISO 27001, and here is our certification plan".

What Not to Do

  • Optimistic declarations: writing "MFA in place" without deploying it becomes a contract breach on incident day — questionnaire answers bind as contract annexes.
  • Unrealistic notification commitments: do not sign "notification within 2 hours" without 24/7 monitoring capability; negotiate and write the period your capability supports.
  • Treating the questionnaire as one-off: these requests recur annually; build the answers as a document folder and yearly updates take minutes.

Where Yamanlar Bilişim Fits

For our exporting customers we answer supplier questionnaires together, prioritise and implement the missing controls, and keep the evidence folder — policies, test records, inventory — audit-ready. Reviewing the technical commitments in contracts before signature, and making them "committable", is part of the work. Your EU customer's security question then stops slowing your sales cycle and becomes an advantage over competitors.

FAQ

Frequently Asked Questions

Does NIS2 apply directly in Turkey?

No; NIS2 is EU legislation, applied through member states' national law. What binds a Turkish company is not the directive itself but the contract terms and supplier assessments its EU customer passes down — and that is precisely its practical effect.

Our customer hasn't sent a questionnaire; should we wait?

The business that prepares before the questionnaire never holds up a sales process when it arrives. And the same core controls protect you regardless of any questionnaire — the problem is not the cost of preparing but the cost of being caught unprepared.

Can these questionnaires be passed without ISO 27001?

Yes; most ask about the actual existence of controls rather than a certificate. The certificate standardises the answers and lowers the cost of trust. The right order: controls first, certification when need and customer profile justify it.

We are a small workshop; isn't this burden too heavy?

The core set — MFA, tested backups, current systems, a written incident plan — is good practice at any scale and fits an SMB budget. The heavy parts, such as 24/7 monitoring, are covered through managed services; nobody expects you to build everything in-house.

We committed to incident notification; what do we actually do when one happens?

Your incident plan holds a "customer notification" step with an owner and a template text. The notification deadline is not the resolution deadline — an early, honest notice of "detected at this hour, these systems affected, these measures taken" is what preserves the contractual relationship.

Share:
SY

Author

Serdar YAMAN

Yamanlar Bilişim Expert

Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.

Professional Support

Get help on this topic

Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.

support@yamanlarbilisim.com · Response time: 1 business day