NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?

TL;DR: Even if NIS2 does not bind you directly, it binds your EU customer — and tells them they are responsible for their suppliers' security. In practice that means security questionnaires, contractual security clauses and incident-notification commitments arriving at your door. The preparation list is known: core controls (MFA, tested backups, patching, an incident plan), written policy, and the ability to produce evidence; ISO 27001 is the tidiest single answer to all of it.
The European Union's NIS2 directive has been rolling out across member states since late 2024, imposing heavy cybersecurity obligations on companies across energy, manufacturing, food, logistics, healthcare and more. Before a Turkish SMB says "not our problem", note one article: in-scope companies must also manage the security of their supply chains. Your industrial customer in Germany, your distributor in Italy, your logistics partner in the Netherlands will meet that obligation by assessing the risk that comes from you — NIS2 crosses the border as contract annexes and supplier questionnaires.
Why Are They Asking the Supplier?
A large share of recent major cyber incidents started not at the target but at its supplier: service providers whose software updates were poisoned, vendors whose mailboxes were hijacked to send fake invoices, maintenance firms whose remote access was abused. Regulators turned that lesson into law: the NIS2-scoped company cannot escape liability by saying "my supplier was careless". So it must measure your risk, distribute it by contract, and demand evidence. Translated to your side of the table: your security posture is no longer an internal matter — it is part of your export qualification.
What the Requests Typically Contain
| Request | What it means concretely | Your answer if prepared |
|---|---|---|
| Security questionnaire | A 50–200 question form: policies, access, backup, incident history | A written policy set + technical evidence |
| Contract security annexes | Minimum controls, audit rights, incident-notification deadlines | Joint legal + IT review, realistic commitments |
| Incident-notification clause | "Notify us of any incident affecting you within X hours" | A customer-notification step in your incident plan |
| Certification question | ISO 27001 or equivalent? | The certificate, or a stated roadmap |
| Access security | If you connect to their systems: MFA, separate accounts, logging | A summary of your remote-access policy |
Preparation: the Foundation Before the Questionnaire
What you need when the questionnaire lands is not blanks to fill but controls actually running in the business — serious customers do not settle for declarations, they ask for proof:
- Identity and access: multi-factor authentication on all critical accounts; a process that demonstrably closes departed employees' access.
- Backup and recovery: tested backups — the proof of "do you have backups" is not the backup itself but the record of the restore drill.
- Patching and inventory: supported systems, a regular update cycle, a device inventory.
- An incident response plan: who does what, in which order; where customer notification sits — written down and rehearsed.
- Logging: records that can answer "what happened" after an incident.
- Ransomware resilience: the questionnaires' favourite topic — layered defence, documented.
ISO 27001: One Answer to a Hundred Questionnaires
As your customer count grows, wrestling each one's different questionnaire becomes unsustainable. This is where ISO 27001 is leverage: an internationally recognised management-system certificate answers the bulk of most questionnaires in one line and strengthens your hand in contract negotiations. At SMB scale it is reachable through a reasonable project. For those not investing in certification yet, the interim formula: build a genuine posture that lets you say "we base our controls on ISO 27001, and here is our certification plan".
What Not to Do
- Optimistic declarations: writing "MFA in place" without deploying it becomes a contract breach on incident day — questionnaire answers bind as contract annexes.
- Unrealistic notification commitments: do not sign "notification within 2 hours" without 24/7 monitoring capability; negotiate and write the period your capability supports.
- Treating the questionnaire as one-off: these requests recur annually; build the answers as a document folder and yearly updates take minutes.
Where Yamanlar Bilişim Fits
For our exporting customers we answer supplier questionnaires together, prioritise and implement the missing controls, and keep the evidence folder — policies, test records, inventory — audit-ready. Reviewing the technical commitments in contracts before signature, and making them "committable", is part of the work. Your EU customer's security question then stops slowing your sales cycle and becomes an advantage over competitors.
FAQ
Frequently Asked Questions
Does NIS2 apply directly in Turkey?
No; NIS2 is EU legislation, applied through member states' national law. What binds a Turkish company is not the directive itself but the contract terms and supplier assessments its EU customer passes down — and that is precisely its practical effect.
Our customer hasn't sent a questionnaire; should we wait?
The business that prepares before the questionnaire never holds up a sales process when it arrives. And the same core controls protect you regardless of any questionnaire — the problem is not the cost of preparing but the cost of being caught unprepared.
Can these questionnaires be passed without ISO 27001?
Yes; most ask about the actual existence of controls rather than a certificate. The certificate standardises the answers and lowers the cost of trust. The right order: controls first, certification when need and customer profile justify it.
We are a small workshop; isn't this burden too heavy?
The core set — MFA, tested backups, current systems, a written incident plan — is good practice at any scale and fits an SMB budget. The heavy parts, such as 24/7 monitoring, are covered through managed services; nobody expects you to build everything in-house.
We committed to incident notification; what do we actually do when one happens?
Your incident plan holds a "customer notification" step with an owner and a template text. The notification deadline is not the resolution deadline — an early, honest notice of "detected at this hour, these systems affected, these measures taken" is what preserves the contractual relationship.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide
Old computers gathering dust in the store room are not assets — they are open filing cabinets with customer data on their disks. Why formatting is not enough, the right destruction method per disk type, the record-keeping, and the e-waste handover, step by step.

A Free DLP Start with Microsoft 365 and Google Workspace's Built-In Rules
Data loss prevention is assumed to be an expensive enterprise product; yet the office suite most SMBs already pay for ships with built-in DLP rules. Stop ID numbers, IBANs and card numbers leaking out by email with a three-stage plan — watch first, then warn, block last.