Does NIS2 Apply to You? If You Have EU Customers, Maybe Already.

Does NIS2 Apply to You? If You Have EU Customers, Maybe Already.

8/1/2026 · Compliance365

NIS2 is an EU directive. Your business is in Australia. It's a reasonable assumption that it doesn't apply to you — and it's often wrong.

NIS2 doesn't just regulate EU entities directly. It pushes security obligations down their supply chains, contractually, to every vendor those entities rely on — including an Australian SaaS product sitting several steps removed from Brussels. If you have EU customers, there's a real chance this is already showing up in your contracts without anyone on your side clocking why.


Why an Australian business would ever need to care about an EU law

NIS2 significantly widened the scope of EU businesses required to manage cyber risk across their own supply chains, and it explicitly makes them responsible for the security posture of their vendors and service providers — wherever those vendors are based. An EU company that’s in scope for NIS2 doesn’t get to say “our supplier is offshore, not our problem.” Their obligation follows the data and the dependency, not the border.

The practical effect: if you sell SaaS to a company operating in the EU, and that company is directly or indirectly in NIS2’s scope (which now covers a much broader range of “important” and “essential” entities than the earlier NIS directive did), their own compliance obligations increasingly require them to push security requirements onto you. That shows up as:

  • New clauses in contract renewals asking for specific security certifications
  • Vendor security questionnaires that look meaningfully more detailed than they used to
  • A customer suddenly asking, out of nowhere, “do you have ISO 27001?”

The signal to watch for

You don’t need to interpret EU law yourself to know if this applies to you. Watch for these signals in your own sales and account-management conversations:

  1. A renewal or new-deal conversation suddenly asks for a security certification you’ve never been asked for before, especially ISO 27001.
  2. An EU customer’s procurement or security team gets looped into a conversation that used to be commercial-only.
  3. Contract redlines start including specific supply-chain security clauses — incident notification timeframes, audit rights, subcontractor disclosure.

Any one of these is a reasonable prompt to ask the customer directly: “has your own NIS2 status changed what you need from us?” Most will tell you plainly if you ask — it’s usually not a secret on their end, just something that hasn’t been explained to you yet.


Why ISO 27001 is the practical answer either way

You don’t need to become an expert in EU regulatory scope to respond to this. The practical fix is the same regardless of exactly which NIS2 category your customer falls into: ISO 27001 certification is the credential EU procurement and security teams recognise fastest, because it’s the closest thing to a universal answer to “how do we know your security is adequate” that doesn’t require them to interpret your specific compliance posture themselves.

If you’re already fielding more detailed security questionnaires from EU customers than you used to, that’s the signal to get ahead of it — not wait for a deal to stall on a certification you don’t have yet.

Selling into the EU and starting to see more detailed security questions? Worth a quick conversation before it becomes a blocker on a live deal rather than a proactive move.

See our ISO 27001 services, try the free readiness checklist, or book a call to talk through what your EU customers are actually asking for.

Share this article: Share on LinkedIn

Found this useful? Get the ISO/Privacy/AI readiness checklists.

Browse resources

Ready to take the next step?

ISO 27001 Certification

Full ISMS implementation and Stage 1/Stage 2 audit support. Typically certified in 12–16 weeks.

Learn more Book a free call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.

Keep reading

Microsoft Teams