Your Enterprise Customers Are NIS2-Obligated. They Will Audit You.
Under NIS2 Article 21(2)(d), companies in healthcare, energy, banking, and critical infrastructure are legally required to assess the security of their suppliers. If you sell to them, that means you.
Most B2B SaaS companies aren't directly in scope for NIS2.
That doesn't mean it won't affect them.
Enterprise buyers in regulated sectors are already embedding security requirements into procurement contracts. The questions are changing. The bar is rising. And when your customer's auditor asks them to assess their supply chain, you will be on that list.
The companies getting caught out aren't unprepared — they just didn't know what their customers were about to require.
NIS2-obligated buyers will require suppliers to demonstrate:
A documented information security policy
An incident response process with defined notification timelines
Regular security assessments and evidence of testing
Supply chain security management — including how you vet your vendors
Security awareness training for all staff
Business continuity and disaster recovery plans

