A company that sells a supplier-assurance platform probably shouldn't publish this post. Here it is anyway: below a certain size, you don't need us. A disciplined spreadsheet is a defensible NIS2 supplier register, and we have said so to prospects, to their visible surprise, and meant it every time.
What follows is the honest version of where the line sits — what a spreadsheet setup has to look like to hold up, and the specific ways it stops holding up. Not the ways a vendor wishes it failed. The ways it actually fails.
The setup that works
Four pieces. One register — a single sheet, one row per supplier, with the service they provide, a risk tier, the last review date, the next one, the decision, and an owner. One folder tree — a folder per supplier, evidence inside, filenames that carry dates. One decision log — who approved what, when, and why, written down at decision time, not reconstructed at audit time. And calendar reminders for every expiry date you're counting on.
If one person does the reviews, the log stays current, and the portfolio is small enough that you can hold it in your head, that setup is defensible. An inspection turns on whether the register is current, whether decisions have names on them, and whether the evidence matches what the register claims — not on what produced any of it.
Where it actually breaks
The failure modes are specific, and none of them announce themselves. The register looks fine right up until the morning you need it.
The second reviewer. One person, one spreadsheet: coherent. Two people: versions fork. The file called supplier-register_final_v3_reviewed-JK.xlsx is a real artefact of real companies, and by the time it exists, nobody can say which decisions live in which version — or who made them.
Expiry at scale. Even a modest portfolio, at four or five artefacts per supplier, is dozens of expiry dates, none of them synchronised. Calendar reminders decay — they fire on holiday weeks, they get snoozed, the person they fire at changes jobs. Expired evidence doesn't look different from current evidence in a folder listing.
Reconstruction under time pressure. A supplier discloses an incident and the CEO asks whether you're exposed. The register says "reviewed in April." The reasoning — what was checked, what was waved through, what was flagged for next time — lives in the inbox of a colleague who left in autumn. The register survived; the trace didn't.
The questionnaire round-trips. Word documents emailed out, answers pasted back in, attachments saved wherever. After the third supplier, provenance is gone: which answer came from whom, against which version of the questions, supported by which file. The information exists. The structure doesn't.
The test is two questions, not a headcount
Supplier count is a proxy. The real line is here: Could a colleague reconstruct your last supplier decision — what was approved, on what evidence, why — without asking you? And if a supplier disclosed a breach this morning, is "are we exposed?" a lookup or a project?
If both answers are the good ones, keep the spreadsheet. Genuinely. Spend the budget on one of the many NIS2 obligations that still needs it.
If either answer made you wince, you've crossed the line — usually about a year before the register makes it obvious.
What we'd suggest either way
The other side of that line is the job Vittnor — Supply Chain Assurance for the mid-market — was built for: one record per supplier, decisions with names and timestamps attached, evidence that knows when it expires. And because it's priced by in-scope suppliers, it's priced for the moment a portfolio outgrows the spreadsheet — not for the enterprise you aren't.
Not sure which side you're on? The readiness check takes twenty questions and gives you a directional answer for free.
And if you're staying with the spreadsheet for now — keep the log current and write decisions down the day you make them. That's the whole trick.