If in recent months you have received from a large client a security questionnaire several pages long, a contract annex about “technical and organisational measures” or a request to name someone responsible for incidents, it is not a whim of their legal department. It is NIS2 — the European cybersecurity directive — which has reached you by the only road that touches you: through the contract.
This article is for small companies, under 50 employees and under 10 million euros in turnover, that discover somewhat puzzled that a law they are exempt from still hands them homework. We explain why this happens, what you can concretely be asked for and how you answer without turning the company into a compliance department.
How NIS2 arrived in Romania
The NIS2 directive was transposed into Romanian legislation through Legea 58/2024 (Law 58/2024), supplemented by OUG 155/2024 (an emergency government ordinance). The competent authority is the Directoratul Național de Securitate Cibernetică (DNSC — the national cybersecurity directorate). The law targets essential and important entities in sectors such as energy, transport, healthcare or digital infrastructure — generally medium and large companies.
2026 is the year the discussion moved from theory to practice: the adjustment period has ended, and inspections are starting. Companies targeted directly risk penalties of up to 10 million euros or 2% of global turnover — enough to make them take every link in their chain seriously. Including you.
The exemption that does not let you off
The general rule sounds reassuring: micro-enterprises and small companies — under 50 employees and under 10 million euros in turnover — are exempt from the directive's obligations. If you stop at that paragraph, the subject looks closed.
Except that Article 21 requires the companies in scope to secure their supply chain. That is, to make sure their suppliers — of services, components, software, maintenance — are not the weak link an attack comes in through. The large company cannot transfer its liability, but it can transfer its requirements: by contract, to you.
The practical result: you have no obligations towards the DNSC, but you have obligations towards your client. And the client, unlike the authority, does not fine you — it replaces you with a supplier who ticks the requirements.
What the client can ask of you, concretely
Article 21 covers four broad areas: security policies, incident management, business continuity and supply chain security. Translated into the requests you will see in black and white, they look roughly like this:
- Written security policies: how you manage passwords, who has access to which systems, what happens to accounts when an employee leaves.
- Incident management: a designated point of contact, a way of detecting problems and the commitment to notify the client within an agreed period if an incident could affect them.
- Business continuity: tested backups, a minimal restart plan, proof that ransomware will not take you out of operation for weeks on end — and, with you, the deliveries to your client.
- The security of your own chain: yes, your suppliers matter too; your subcontractors become a legitimate topic of discussion.
On top of these frequently sit audit clauses (the client's right to verify what you declared), employee training requirements and questions about encryption and two-step authentication.
The moment the requirements arrive is not accidental: at contract renewal, at the extension of a framework agreement, at pre-qualification for a private tender — exactly when the commercial relationship is on the table and the negotiating power sits with the client. The sooner you put your paperwork in order on your own initiative, the less exposed the discussion finds you.
Why treating the questionnaire as “it'll be fine” does not pay
Three reasons. First: the questionnaire is not an opinion poll but a filter — the answers feed into your supplier assessment, and at contract renewal they carry weight. Second: your competitors receive the same questionnaire, and some will treat it as an opportunity, not a chore. Third, less obvious: almost everything the client asks for are things your company needs anyway. Modern ransomware does not check turnover before it strikes, and restoring from backup no longer frees you from blackmail — we have explained at length why backups alone no longer save you.
In other words: the client is asking you, at zero cost, for exactly the security plan you should have made for yourself.
The minimum base that covers most of the requirements
- The inventory: what equipment, accounts, applications and data the company has. You cannot protect what you do not know exists.
- Short, written policies: access and passwords, equipment, an employee's departure. One page of a document kept up to date beats ten pretty pages nobody reads.
- Basic technical measures: two-step authentication on exposed accounts, updates kept current, backup under a clear rule — tested periodically through a real restore, not just ticked off.
- A one-page incident plan: who isolates the problem, who notifies the client, who calls in outside help, in what order.
- The supplier file: gather all the documents above in one place, so the next questionnaire means an hour of work, not a week of panic.
If you want someone to structure this package together with you, a focused IT consulting engagement is the right format — and for the small uncertainties that come up along the way there are the frequently asked questions about IT security.
How to answer the questionnaire without tripping yourself up
Three simple rules. Answer honestly: declaring measures that do not exist is worse than admitting gaps, because the declaration becomes a contractual commitment, and the audit clause exists precisely to be used. Attach evidence where you have it: a written policy, a screenshot from the backup console, a restore test report. And mark clearly what is “in progress”, with a committed deadline — large clients are not looking for perfection in small suppliers, they are looking for signs that you take the subject seriously and that in six months you will stand better than today.
The next step: re-read the last questionnaire you received — or proactively request one from your most important client — and note, point by point, what you can prove today and what you cannot. The difference between the two columns is your security plan for the coming quarter. Neoxis, an IT services company founded in 2015 in Pitești, holds ISO 9001 and ISO 27001 certifications and works with SMEs across Romania.