Compliance
Compliance by proxy doesn't scale
The Cyberbeveiligingswet entered into force on 15 August 2026, formalising new obligations for roughly 8,000 organisations in the Netherlands (Rijksoverheid, 2026). It took the advisory market months to prepare for this date, and almost all of that preparation went to one group: the essential and important entities now directly obligated under the new law. Consultants have been booked solid helping those organisations map their duty-of-care measures, register with the NCSC, and get their governance in order.
Assume, conservatively, that each of those 8,000 organisations relies on at least twenty suppliers, and the number of businesses now facing a compliance question because of this law, not directly regulated themselves, already runs comfortably past 100,000.
NFIR noticed something else while doing exactly that advisory work. Sitting inside those conversations, again and again, the same gap appeared: the obligated organisation itself was usually in reasonable shape, often already ISO 27001 certified or well on the way, but its suppliers were not. Those suppliers had no certificate to point to, no shared way to demonstrate their security posture, and no idea how to answer the compliance question that was about to land in their inbox from several customers at once.
Bizway saw the same problem from the other side. As a supplier itself, Bizway had already started noticing an uptick in exactly this kind of request: customers asking, sometimes formally and sometimes as an afterthought in an account review, how Bizway could demonstrate that it met NIS2-related expectations. Two organisations, two vantage points, the same observation: the pressure of this law was never going to stay contained within the 8,000 directly regulated companies. It was always going to land one layer further down, on the people who supply them.
Why is your customer suddenly asking you for a compliance statement?
This is not a coincidence, and it is not overzealous account management. Article 21 of the NIS2 Directive requires essential and important entities to manage the security of their supply chain, including the security-related aspects of their relationships with direct suppliers (ENISA, 2023). In practice, that obligation cannot stay inside the regulated organisation. It has to be passed downward, into contracts, onboarding checklists and, most visibly, into a compliance question addressed to every supplier the organisation depends on.
ENISA’s own analysis of supply chain cybersecurity, published in 2023 and still the most cited EU reference on this mechanism, found that supply chain compromises had grown from under 1 percent of intrusions in 2020 to 17 percent by 2021. In 66 percent of the incidents it examined, the affected supplier did not know how it had been compromised, or could not explain it transparently to the customer relying on it. That is precisely the gap the Cyberbeveiligingswet is designed to close, and precisely why a regulated organisation now has every incentive to ask its suppliers to show their work rather than take it on trust.
Isn’t a certificate the obvious answer?
The tidy answer would be for every supplier to get ISO 27001 certified and put the matter to rest. For a handful of larger suppliers, that is a sensible route, and some are already doing it. For most, it is not realistic, and arguably it is not necessary either. A certificate is expensive, takes months to obtain, and is built for organisations of a certain size and maturity. Plenty of suppliers who present no meaningful risk to their customers’ NIS2 compliance are being asked, implicitly, to behave as though they do.
What those suppliers actually need is not a certificate. It is a credible, evidenced way to answer the question they are being asked, backed by something more solid than a reassuring email.
What happens when one supplier gets asked the same question fifty times?
Here the problem compounds. A supplier rarely has one customer asking this question; it has several, each with a slightly different form, a different deadline and a different set of expected answers. ISACA’s industry analysis from May 2026 describes this directly as a shift from questionnaire fatigue to the need for contextual, evidence-backed assurance, noting that the old model of ad hoc, one-off questionnaires simply does not scale once every customer starts asking independently (ISACA, 2026). Multiply that by the number of customers a mid-sized supplier serves, and the supplier ends up spending more time filling in forms than actually improving its security.
That is not a failure of any individual supplier’s diligence. It is a structural failure of a model built for occasional questions, now being asked continuously and simultaneously by everyone at once.
Wouldn’t a bespoke questionnaire from each customer be more thorough?
There is a real argument for the current approach. A customer who drafts their own questionnaire can tailor it precisely to the risk that supplier represents to them: a supplier handling sensitive data gets asked different questions from one supplying office furniture with an internet-connected badge reader. Bespoke questionnaires also keep ownership and accountability exactly where NIS2 puts it, with the regulated organisation itself, not with a shared template nobody has reviewed.
The trouble is that this thoroughness only works at small scale. Once an organisation has to assess dozens or hundreds of suppliers, and once each of those suppliers is fielding the same request from several customers in parallel, a bespoke, manual process does not become more accurate with volume. It becomes slower, more inconsistent, and more likely to be answered superficially just to get it off someone’s desk. Precision purchased at the cost of completion is not much use to anyone.
What does “showing your work” actually look like?
This is the problem Lighthouse’s new compliance questionnaires feature, built together with NFIR and Bizway, is aimed at. It gives an organisation standard NIS2/Cbw questionnaires, in variants scaled to whether its customer is an essential or an important entity, so a supplier can complete something proportionate to the actual obligation rather than a maximalist worst case. Answers are not reduced to yes or no; each one carries evidence, an explanation, or an expected date where something is still in progress, and every answer is timestamped with an audit trail.
The more useful shift is what happens after the first answer. A supplier can answer once, attach the evidence, and reuse that attested proof the next time a different customer asks the same question, rather than starting from a blank form every time. Better still, a supplier does not have to wait for the request at all: the same completed questionnaire can be shared proactively with every customer at once, pre-empting the question before it ever lands.
For the customer side, an organisation can register the suppliers it depends on, send each the appropriate questionnaire in its own name, and see a live view of where the whole chain stands, with re-assessment a single click away at the next cycle. The questionnaires are included at no extra cost for Guardian360 partners and their customers, so budget is not the reason to leave this until next quarter. Guardian360 is explicit that this is a readiness tool, not a certification: it does not replace a formal audit or conformity assessment, and it does not claim to. What it replaces is the fifty separate spreadsheets nobody had time to compare.
The point was never the 8,000
It is worth returning to where this started. NIS2, and the Cyberbeveiligingswet that transposes it, were never really about hardening 8,000 organisations in isolation. The entire logic of Article 21’s supply chain requirement is that a regulated organisation’s security is only as good as the suppliers underneath it. Treat the law as a compliance exercise for the companies named in its scope, and the actual ambition, raising the security floor across an entire supply chain of well over 100,000 businesses, quietly fails at the first link outside that scope.
NFIR spotted this from the advisory chair, watching organisation after organisation get its own house in order while its suppliers had nowhere to turn. Bizway spotted it from the receiving end, answering the same question more often and with less patience each time. The two observations point at the same conclusion: compliance by proxy, one customer, one questionnaire, one supplier at a time, does not scale to the size of the problem NIS2 was written to solve. Building for the layer beneath the 8,000 is not a side project. It is closer to the actual point of the law than the certification race has been.
Sources
- Rijksoverheid (7 July 2026). Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht.
- NCSC. Cyberbeveiligingswet (NIS2).
- ENISA (June 2023). Good Practices for Supply Chain Cybersecurity.
- ISACA (4 May 2026). Enhancing Third Party Risk Management: Moving From Questionnaire Fatigue to Contextual Assurance.