NIS2 supplier security assessment — without spreadsheets going round by email

New module: you send a supplier a security questionnaire from your system, they complete it in a portal (2FA login) and attach evidence — policies, certificates, reports. The result returns to the assessment order with a full history of who answered what, and when.

Where the obligation comes from

NIS2 extends security responsibility to the supply chain. Essential and important entities must manage supplier risk — and that obligation flows down to their suppliers and service providers. Risk-management measures include supply-chain security and the security of relationships with direct suppliers (Directive (EU) 2022/2555, Article 21(2)(d)).

It complements our ISO and NIS2 Portal; we cover the regulation itself in the article on NIS2 and the EU Machinery Regulation.

How it works — four steps

Assessment ordersupplier + templateInvitationone-time link + 2FASupplier fills it inanswers + evidenceResult on the orderstatus: to review
Three of the four steps happen without your involvement.
  • You create an assessment order — pick the supplier, a questionnaire template for their industry and a deadline. The checklist is built from the template.
  • The portal sends an invitation — the supplier gets an email with a one-time link, creates an account, sets their own password and a second factor (authenticator app). We never email passwords.
  • The supplier fills in the questionnaire — answers save as they go (they can pause and return). For mandatory questions a 'no' answer requires an explanation, and where indicated — an attached evidence file.
  • The result returns to the order — answers and documents land in the order checklist and the status changes to 'to review'. You see which mandatory requirements are unmet.
SimplyMobile supplier portal — list of security questionnaires with status and deadline (screenshot)
Supplier's questionnaire list
Filling in a NIS2 questionnaire in the supplier portal — a mandatory (MUST) question with comment and attachments (screenshot)
Filling in a questionnaire (MUST question)

This is the supplier portal

After logging in (2FA), the supplier sees only their own questionnaires, their status and deadline — on a phone too. Progress ('1 / 45') is visible at a glance.

For each question they answer YES / PARTIALLY / NO / N/A, add a comment and attach evidence. Mandatory (MUST) questions must be explained, and answers save automatically.

What you get

  • Templates per industry — separate question sets for IT, service and manufacturing suppliers; mark questions as mandatory, evidence-required or internal (the supplier does not see internal ones).
  • Evidence in one place — policies, certificates and reports sit next to the specific question, not in email attachments; each file goes through type checks and an antivirus scan.
  • Mandatory requirements — gaps in key areas (MFA, incident response, backups) are visible at once, with the supplier's explanation.
  • Follow-ups without starting over — the assessor asks about a specific answer; the supplier updates only that point.
  • Deadline reminders — the portal nudges the supplier before the deadline, so you do not track it in a calendar.
  • History and audit — a record of logins, answer changes and uploaded files; at the next assessment you see what changed.
  • Final assessment — inherent and residual risk, an acceptance decision and remediation actions with a due date and owner.
  • No double data entry — suppliers, orders and statuses come from your system; the portal is not a separate contractor database.

Portal security

Since we ask suppliers about access control and encryption, the supplier portal is held to the same bar — it is a separate application and we built it that way:

  • Two-factor login (2FA) with no exceptions — an account without a second factor sees no data.
  • Separated environments — the portal runs on a different domain than the internal system, with minimal database permissions.
  • Each supplier sees only itself — an account is tied to one company, with no path to other suppliers' data.
  • Files under control — allowed formats, content verification, a size limit and an antivirus scan before assessors can see them.
  • One-time invitations — the link works once and expires; we store only its hash, never passwords in messages.
  • Full audit trail — logins, failed attempts, answer changes and file operations with date, user and IP.

Want to see it on your own suppliers? In a demo we set up an assessment for a chosen supplier and walk the path from invitation to result. Book a free demo.

This functionality supports meeting NIS2 obligations for supply-chain security. It does not replace legal analysis or the decision on entity classification.

Frequently asked questions

  • What is supplier security assessment under NIS2?
  • Who has to assess suppliers?
  • Does the supplier have to create an account and 2FA?
  • What evidence can be attached?
  • How does this differ from the ISO and NIS2 Portal?

See SimplyMobile in action

Book a free, no-obligation demo — we'll show the system on your own processes.