- Job title
- Field sales representative
- Sector
- Advertising and promotion
- Organization type
- two-branch business
- Joined
- Feb 2024
- Message
- 6
Doki · Log management setup · 2026
We are a family-owned manufacturing business in Brescia with 38 employees, producing industrial valves and mechanical parts. Our annual turnover sits around 6.5 million EUR. We supply some of our products as a subcontractor for power plants and drinking water infrastructure projects.
Yesterday we received a formal email from a major client. They stated that under the EU's NIS2 cybersecurity directive they are subject to supply chain audits, and they are demanding to know whether we fall directly under this scope—and if so, to submit our security certifications and risk management plans. They even mentioned heavy liabilities assuming we are covered.
When I look it up online, it says SMEs with fewer than 50 employees and a turnover under 10 million EUR are out of scope. However, since we supply parts to critical sectors, we can't tell whether an exception applies to us. How can we definitively confirm whether our company is legally subject to NIS2?