Skip to content
EU AI Stack

Solution

Passing a NIS2 supplier audit as an AI vendor

Your customer is in scope for NIS2, so you are audited as part of their supply chain. That audit asks for artefacts, not intentions: asset inventory, patch windows, incident timelines, subcontractor list, exit plan.

What you get

  • An evidence pack mapped to the supply-chain articles your customer will cite
  • Incident handling that meets the CRA 24 h / 72 h / 14 d clock from 11 September 2026
  • Answers ready for the five member states that have not transposed NIS2 yet

How it runs

Gap review against ISO 27001

What your certificate already covers, and the NIS2 duties it demonstrably does not.

Incident runbook

Early warning, notification and final report, with log fields defined per stage and owners named.

Audit rehearsal

We play the auditor against your own documents and record where the answers run out.

Questions we get

Does NIS2 apply to us if we only sell software?
Often indirectly. If your customer is an essential or important entity, its supply-chain obligations become contractual requirements on you, whatever your own scope status is.
Is ISO 27001 enough?
It carries a large part of the control evidence and none of the reporting duties. The overlap is real but partial.

Background reading

Next step

Start with the document that is blocking you

Send the questionnaire, RFP section or audit request. You get a written read on the gaps and what closing them takes.

Request a review