NIS2Suppliers

The questions you are going to ask us anyway.

Since 15 August 2026 the Dutch Cyber Security Act (the Dutch implementation of NIS2) applies. If your organisation falls under it, you have to show that you manage your suppliers, us included. Below are the questions we get most often, with our answer. Where something is not finished yet, we say so.

Suppliers are not in scope. Their customers are.

A common misconception: that every supplier has to comply with NIS2 itself. The law places the duty on the organisations in scope; they must manage the risks in their supply chain and may ask for evidence. There is no NIS2 certification mark for suppliers.

We sit on both sides. We are in scope ourselves as an essential entity, and our customers ask us the same things the supervisor asks us. So we would rather answer those questions once and properly, with evidence, than in ten different questionnaires.

Supplier dossier

What you get from us.

Answers with evidence
For each question the answer and the document behind it: policy, procedure or configuration, instead of a tick box in a questionnaire.
A notification time that fits
We report an incident affecting your service within 8 to 12 hours, so you can meet your own early warning within 24 hours.
One standard questionnaire
We prefer filling in one standard, such as the Dutch NIS2 Cyber Score, over a different format per customer. If you have your own list, you get it back with references.
People who explain it
You discuss a supply-chain question with the engineers who build the network, not with a department copying answers.
How it works

From questionnaire to dossier.

  1. Request the dossier
    Send your questionnaire or request our standard dossier through the contact form.
  2. Match it to your risk
    Not every question is relevant for every service. Together we look at which questions belong to what you take from us.
  3. Answers with evidence
    You get the answers with the supporting documents, and where something is still in progress we tell you when it will be done.
  4. Agreements in your contract
    Notification time, contacts and what you get from us during an incident are recorded in your contract and the SLA.
The questions

What NIS2-regulated customers ask us

Are you in scope of NIS2 yourselves?

Yes, as an essential entity. We have the same duty of care and reporting obligation as our customers who are in scope. How we approach it is described in our article on NIS2 in practice.

Within what time do you report an incident affecting our service?

Within 8 to 12 hours after we have established it, to the technical contacts you set in our dashboard. That leaves you enough time for your own early warning within 24 hours.

Which certifications do you have?

Our ISMS is set up according to ISO 27001; certification is in preparation. The BIT data centres in Ede are certified to ISO 27001 and NEN 7510. Which data centre applies to your service is stated in the dossier.

Which sub-processors and data centres do you use, and does the CLOUD Act apply?

Our services run in Dutch data centres in Amsterdam, Ede and Naaldwijk, on our own network. We are a Dutch company without a US parent. The full list of sub-processors is in the supplier dossier.

How is administrative access arranged?

With personal accounts, management only through VPN and a separate management network, out-of-band access over WireGuard, and MFA or passkeys on management systems. In our customer dashboard a passkey is mandatory for staff; customers can use one too.

How long do you keep logs, and can we get them during an incident?

Which logs you get from us during an incident and how long we keep them is agreed per contract, matched to what you need for your own report and investigation.

What are your patching deadlines?

Critical vulnerabilities in network and server equipment within 7 days at the latest, high within 30. That is the ceiling; in practice we are faster. Where possible we test on a redundant node first.

How do you protect us against DDoS?

Every IP transit connection includes baseline protection: we detect and filter attacks at our edge, in practice often within seconds, and can blackhole an address. Per attack the dashboard shows what happened. Extended protection is available on request.

How are backups arranged?

Backups of managed servers are kept off-site, at a different location from the servers, and are encrypted before they leave the server. Periodic restore tests are part of our policy; the first is scheduled for November 2026, and its report will be added to the dossier afterwards.

What are the recovery times?

Availability, response times and compensation are set per service in our SLA. Anything not covered there is agreed in your contract.

How do you handle configuration changes?

Network configuration is kept in version control, changes are reviewed and router changes use commit confirmed: if the BGP session does not stay healthy, the router rolls the change back by itself.

May we audit you or run a pentest?

Yes, by arrangement. Scope, time window and advance notice are agreed beforehand, especially for a DDoS test, so our detection does not mistake your test for an attack. We do not perform pentests ourselves; for that we recommend a specialised party.

Do you fill in the NIS2 Cyber Score or our own questionnaire?

Either is possible. We prefer one standard such as the NIS2 Cyber Score, because it saves both of us time. We also answer your own questionnaire, with references to the dossier.

Request the supplier dossier.

Send your questionnaire or request our standard dossier. Together we look at which questions belong to your service.