What does a NIS2 supplier audit actually ask an AI vendor for?

NIS2 never regulates you as an AI vendor. It regulates your customer, and your customer passes the duty on through the contract. A supplier audit therefore asks for five artefacts: an asset inventory covering models and data stores, a patch and vulnerability window, an incident timeline you can hold under a 24 hour clock, a named subcontractor list, and an exit plan. Everything else in the questionnaire is a variation on those five.
Why does NIS2 land on a vendor that is not in scope?
Directive (EU) 2022/2555 applies to essential and important entities across eighteen sectors: energy, transport, banking, health, public administration, digital infrastructure and the rest. An AI vendor is rarely one of them. What makes NIS2 a vendor problem is Article 21, which obliges those entities to manage security risks in their supply chain and in their supplier relationships. The only enforcement tool a customer has against you is the contract, so that is where the directive arrives: as clauses, questionnaires and evidence requests.
That distinction changes the tone of the conversation. You are not being asked to prove compliance with a directive you are not subject to. You are being asked to let your customer prove theirs. Vendors who answer with a policy PDF lose weeks; vendors who answer with dated artefacts close the security review inside one round.
Which five artefacts do buyers actually request?
Across security reviews the wording differs and the substance does not. Prepare these five and you can answer most questionnaires by attaching a file instead of drafting prose.
| Artefact | What it must contain | Why the buyer needs it |
|---|---|---|
| Asset inventory | Models, model versions, data stores, interfaces, hosting regions, supporting infrastructure | Their risk analysis cannot cover what your inventory does not name |
| Patch and vulnerability window | Patch policy, standard windows, maximum time to remediate a critical finding | Article 21 requires vulnerability handling across the chain |
| Incident timeline | Detection, containment, eradication, recovery and post-incident review, with real dates | Their own reporting clock starts at 24 hours, so yours must be faster |
| Subcontractor list | Every sub-processor and model provider, its role, its location, the controls it operates | Supply-chain duties follow the chain past you |
| Exit plan | Data return or deletion, transition support, maximum time to exit | Continuity planning and, for cloud, the Data Act switching rules |
The clock that decides everything
Article 23 gives your customer an early warning duty within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. If the incident originates in your platform, their clock runs on your detection. That is why a contract will usually demand notification from you in a window shorter than 24 hours, often 12 or even 6. Agree to a number you can actually hit with the on-call rota you have, then write the escalation path next to it.
Note how this stacks with the Cyber Resilience Act. From 11 September 2026 CRA Article 14 gives you your own reporting duties for actively exploited vulnerabilities and severe incidents: 24 hours, 72 hours, 14 days. One incident, two clocks, one runbook. Building separate processes for them is the most common waste of effort we see.
What is specific to AI, not generic IT security
Generic security questionnaires miss the parts that matter in an AI product, and sharper buyers now add them. Expect questions on model provenance and licence terms, on whether customer data reaches training, on prompt and output retention windows, on the location of inference, and on what happens when an upstream model provider deprecates a version you depend on. Answer those in the same evidence pack, because they will otherwise arrive as a second round of questions three weeks later.
How do you prepare before the questionnaire arrives?
- Write the asset inventory first. It constrains every other artefact, and it is the one document that never survives being improvised.
- Fix your remediation windows in numbers, not adjectives, and check them against the last two quarters of real patch data.
- Rehearse one incident end to end and keep the timeline as your sample artefact, with names redacted.
- Publish the subcontractor list on your trust page, so procurement can read it without opening a ticket.
- Draft the exit plan with the Data Act in view: egress fees for switching are banned from 12 January 2027.
Two side effects make this worth doing before you need it. The same five artefacts answer most of a DORA register request from financial buyers, and they feed directly into the technical documentation the AI Act will require of Annex III systems from 2 December 2027. Preparing once for three regimes is the whole argument for treating the stack as one evidence file rather than four projects.
The security review is not a test of your intentions. It is a test of whether your evidence exists on the day it is asked for.
Frequently asked questions
- Does NIS2 apply directly to an AI vendor?
- Usually not. NIS2 applies to essential and important entities in eighteen sectors. It reaches an AI vendor indirectly, through the supply-chain security duties in Article 21 that those entities pass on in contracts and security questionnaires.
- How fast must we report an incident to a NIS2 customer?
- Their own early warning duty falls due 24 hours after they become aware of a significant incident, so contracts typically require vendor notification inside 12 to 24 hours. Agree a window your on-call rota can actually meet and document the escalation path.
- Is there a NIS3 directive we should prepare for?
- No. The Commission proposal of 20 January 2026 is an amendment to NIS2, not a new directive. Any plan or vendor document referring to NIS3 is working from a misunderstanding.
- Do we escape the audit if our member state has not transposed NIS2?
- No. Five member states had not finished transposition as of August 2026, but their essential and important entities still write supply-chain security duties into supplier contracts, so the audit arrives regardless.
Related articles
EU AI Compliance Stack 2026: One Map
One dated map of the AI Act, NIS2, GDPR/DORA and CRA obligations that hit AI vendors between August 2026 and August 2028, with EUR-Lex sources.
AI Act 2 August 2026: What Actually Applies
Only Article 50 applies from 2 August 2026; high-risk does not. What the Digital Omnibus changed in the AI Act calendar, with EUR-Lex sources.
Directive (EU) 2022/2555: Which Articles Bind an AI Vendor
NIS2 has 46 articles. Only a handful reach an AI vendor. A plain-language map of which ones bind you directly, which reach you through your customer, and what each demands.
Next step
Need this as an outcome, not an article? NIS2 supplier audit.
Your customer is in scope for NIS2, so you are audited as part of their supply chain. That audit asks for artefacts, not intentions: asset inventory, patch windows, incident timelines, subcontractor list, exit plan.
Explore NIS2 supplier audit


