Back to knowledge baseCOMPLIANCE

Why your biggest client is suddenly asking how secure you are

Elli30 September 20264 min read

An SME that has worked with the same large client for years recently receives an unusual request: a questionnaire about how its IT security actually works. Is there a response plan for a cyberattack? Is an extra verification step used to log into important systems? Anyone getting that question for the first time might assume it's a mistake. It isn't — and it's happening more and more often.

What's going on

Since 18 April 2026, Belgium has become the first EU country where large and critical companies — the so-called "essential entities" under the EU's NIS2 law — must pass an independent check proving their cybersecurity is in order. According to the Centre for Cybersecurity Belgium (CCB), a company that cannot demonstrate this fully and on time risks fines or further scrutiny from the regulator.

To prove this, a company can choose between a recognised security framework such as the CCB's Cyber Fundamentals, ISO 27001 certification, or a direct inspection. Whichever route a company takes, the underlying question stays the same: can it concretely demonstrate that security is in order, rather than simply claim it is.

That check doesn't stop at a company's own walls. NIS2 also requires these organisations to actively manage the security of their own suppliers, and they're no longer allowed to simply hand that risk off through a contract clause. In practice, this is showing up as new terms in supplier contracts: specific security measures, a duty to report incidents, cooperation with audits, and sometimes even the right to end the relationship if security falls short. Where an annual questionnaire used to be enough, some clients now expect ongoing visibility into their suppliers' security.

Why this affects SMEs

Many Belgian SMEs supply services or products to companies in sectors that do fall directly under NIS2: energy, transport, financial services, healthcare, digital infrastructure, food, manufacturing. The SME itself is usually too small to fall under the law directly, but that no longer offers protection — the request isn't coming from the regulator anymore, it's coming from the client, who has to prove its own compliance.

This is also happening at a moment when large companies have become noticeably more cautious. In the first quarter of 2026 alone, the CCB recorded more than 3.6 million phishing reports — with daily peaks above 42,000 in March, up from a 2025 average of around 27,000 a day. For a client that is itself a target of increasingly sophisticated attacks, every link in the chain — including the smallest supplier — is a possible way in. For an SME without a good answer to a security question, the immediate risk usually isn't a fine, but a lost contract or a stalled renewal.

That's what makes this different from before. In the past, an SME could wait until a law applied to it directly before acting. Now it's enough that a client further up the chain is in scope — the pressure arrives through the relationship, not through a letter from a regulator. Which is exactly why many business owners only notice it once the question is already sitting in their inbox.

What to actually do about it

  • Map out which clients sit in NIS2-sensitive sectors. Energy, transport, finance, healthcare, food, manufacturing and government are first in line — a questionnaire is most likely from a client in one of these.
  • Know what an outsider can see of the business before a client asks. Which systems are reachable online, which software has fallen behind on updates, where a forgotten test environment might still be running. Finding those blind spots yourself beats hearing about them from a client first.
  • Put the basics in writing. Who is responsible for IT security, how quickly are updates applied, what happens when something suspicious turns up. A short, honest document carries more weight than no document at all.
  • Read a questionnaire or contract clause carefully before promising anything. A requirement like "continuous monitoring" or "unlimited audit rights" can sound routine to a large client, but isn't always realistic for a small organisation — negotiate what's actually achievable.
  • Consider a reusable proof point if several clients start asking similar questions. A light, recognised baseline such as the CCB's Cyber Fundamentals saves time on every questionnaire that follows.

How NetGuard helps

That first overview — what an outsider, or a client, can currently see of a business online — is exactly where External Attack Surface Management (EASM, the ongoing practice of mapping what an organisation exposes to the internet) makes the difference. Instead of scrambling for an answer every time a questionnaire arrives, there's an up-to-date, well-documented picture ready to go — along with, sometimes, a short list of things worth fixing first. A no-obligation introduction can be arranged by e-mail.

Share this article

Elli

No author profile available.

Related articles

News

The password on thousands of firewalls was simply “admin”

A flaw at firewall maker Fortinet gave hackers access to more than 270 Belgian businesses — often through a firewall whose default password was never changed. What happened, why SMEs are vulnerable, and which steps help starting today.

31 August 20264 min read
News

That voice on the phone might not be human

Scammers now use AI to mimic the voice of a business owner to push through an urgent payment. Here's how this new form of CEO fraud works, and five concrete steps to reduce the risk.

13 August 20265 min read
Why your biggest client is suddenly asking how secure you are | NetGuard