Choosing a NIS2-Compliant IT Supplier for a Tender

NIS2

If your organisation falls under NIS2, the IT supplier you pick isn’t just a technical choice anymore. NIS2 makes you responsible for the security of your whole supply chain, and that includes the IT partner running your infrastructure. So when you’re writing a tender, it’s worth knowing what NIS2-compliant supplier actually means in practice, and how to spot one.

This guide keeps things simple. No legal jargon, just what to check for before you sign a contract.

Why this matters for your tender

Under NIS2, Belgian organisations that count as “essential” or “important” entities need to manage cyber risk not only inside their own walls, but across every supplier they work with. If your IT partner has weak security practices, that risk becomes your risk too.

In practice, this means:

  • You need to be able to report serious incidents within 24 hours. That’s only possible if your IT supplier actually monitors your systems and catches problems early.
  • Your supplier’s own security habits (patching, access control, backups) become part of your risk picture.
  • You may be asked, during an audit or by a client of your own, to show that your suppliers meet a baseline level of security.

A good tender should ask suppliers to prove this, not just promise it.

What to look for: 7 simple checks

Use these as questions to put directly to bidders.

  • Can they tell you where you stand today? A serious supplier should be able to assess your current IT setup and tell you honestly how mature (or not) it is.
  • Do they have a clear plan to get you where you need to be? Not a vague promise, but concrete steps and a realistic timeline.
  • Do they actually monitor your systems around the clock? This is what makes the 24-hour reporting deadline realistic instead of impossible.
  • Do they layer their security? Firewall, endpoint protection, backups and access control should work together, not sit as separate boxes ticked off a list.
  • Do they give you paperwork you can actually use? Policies, risk overviews and documentation you can show an auditor or a client, not just a verbal assurance.
  • Have they done this before? Ask for examples of similar Belgian businesses they’ve helped.
  • Can they grow with you? Your needs today won’t be your needs in two years. Make sure the supplier can scale up as your business or your obligations change.

If a supplier can answer all seven with specifics, you’re in good hands.

It starts with knowing where you stand

Most businesses aren’t at “zero” and they’re not fully compliant either. They’re somewhere in between, and that’s normal. Think of IT maturity in four rough stages:

Stage What it looks like
1. Ad-hoc IT problems get solved as they come up, no real plan in place
2. Structured Things are stable, but still fairly basic
3. Managed Systems are actively monitored and controlled
4. Optimized Everything is documented, tested and continuously improved

The 24-hour reporting rule only becomes realistic once you’re at stage 3, because that’s the point where someone is actually watching your systems in real time. Moving up a stage usually takes a business 12 to 18 months, so it pays to start the conversation with your supplier early, not after the tender is already signed.

How ITAF can help

ITAF has been an IT partner for businesses in Belgium since 1999, and today supports more than 1,500 customers with IT support, IT security and full ICT infrastructure. Here’s specifically what ITAF offers when NIS2 is part of the picture:

If you’re drafting a tender right now, ITAF can also help you sanity check your requirements before you publish them, so you’re asking suppliers the right questions from the start.

Common questions

Do I need a NIS2-compliant supplier if my company isn’t directly covered by NIS2?

Possibly yes. If you supply a client who is covered by NIS2, they may ask you to meet similar standards, even if the law doesn’t apply to you directly. Better to check now than find out during a client audit.

How fast do I need to report an incident?

Within 24 hours for the first alert, with more details due at 72 hours and a full report within 30 days. That’s tight, which is exactly why real monitoring matters.

Can I ask suppliers about NIS2 readiness in my tender criteria?

Yes, and you should. Just keep the requirements clear, realistic and something bidders can actually prove, not just claim.

How long does it take to become NIS2-ready?

It depends where you’re starting from. Most businesses need 12 to 18 months per maturity stage, but a proper assessment will give you a real number for your situation.

Curious where your business stands today? ITAF can map your current IT maturity and show you exactly what it would take to get NIS2-ready.

Share this post:

Table of Contents

Use the button below to upload your resume and cover letter (mandatory).