forumNew topic

Our client told us the NIS2 directive affects us, what exactly is this and is it mandatory in Spain?

TTuğçe T***Member
Job title
Agency Founder
Sector
Law
Organization type
120-person company
Joined
Nov 2025
Message
19

Doki · Server maintenance contract · 2025

#1

We are a 42-person engineering firm based in Bilbao, designing molds and industrial components for the automotive supply chain. Our annual turnover is around 6 million euros. Last week, one of our major OEM clients in Germany and Spain sent us an extensive cybersecurity compliance agreement, stating that we must comply with the NIS2 directive, otherwise we will be removed from their approved vendor list.

We discussed this internally, but nobody could figure out the exact scope. From what I read online, it appears to be a new European Union cybersecurity regulation covering critical infrastructure. But we're not a power plant, water utility, or bank; we are a mid-sized contract manufacturing and design shop.

What is the NIS2 directive, who falls under its scope, and what is its legal status in Spain? Is an SME with fewer than 50 employees like us genuinely subject to direct enforcement under this law, or is our large client just pushing their own legal obligations onto us via contractual pressure?

AAycan P***Member
Job title
Production planning
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Apr 2024
Message
109
Most Helpful#2

Short answer: NIS2 is the updated European Union cybersecurity directive aimed at bolstering the resilience of critical and important sectors against cyberattacks. While the direct legal scope generally applies to entities with more than 50 employees or over 10 million euros in annual turnover, smaller subcontractors are indirectly forced to comply because large enterprises are legally required to secure their supply chains.

The directive establishes two primary classifications: "Essential" and "Important" entities. The general SME threshold to directly fall into these categories is at least 50 employees or an annual turnover of 10 million euros. With 42 employees and a turnover of 6 million euros, your firm does not technically fall under the direct legal scope; meaning Spanish authorities cannot come knocking to issue direct NIS2 administrative fines against your company. However, your prime client in the automotive or defense industry definitely does fall under the direct scope.

NIS2 places a statutory obligation on covered entities to audit and manage the security of their supply chains and supplier relationships. To avoid penalties during their own audits, your primary client is passing down these security requirements to you as a contractual condition. In Spain, the enforcement and transposition of the directive is coordinated under the National Cybersecurity Institute (INCIBE) and CCN-CERT.

At this stage, there is no need to panic; simply review the clauses in the agreement they sent over. Typically, they will ask for basic cyber hygiene measures such as: 1) multi-factor authentication (MFA), 2) keeping offline system backups, 3) encrypting sensitive data, and 4) prompt notification in the event of a security incident. Preparing a security assessment report confirming that you meet these baseline measures will be sufficient to protect your business relationship.

DDeniz K***ExpertCommunity member
Joined
Nov 2024
Message
154
#3

Here is exactly how the process works: 1) The major primary manufacturer is directly subject to the NIS2 directive. 2) The law tells this manufacturer, "any vulnerability in the suppliers you work with is your vulnerability, audit them." 3) To fulfill their own obligation, the manufacturer tries to get you to sign this form. So, you aren't impacted by the law itself, but by the contract.

PPolat K***MemberCommunity member
Joined
May 2025
Message
27
#4

The technical clauses in the client's form are usually standard: mandatory VPN and MFA for remote access to servers hosting CAD/CAM design files, up-to-date endpoint security on employee devices, and weekly offline backups. If you can document that you meet these four requirements, you'll easily pass the audit.

PPınar Ç***Expert
Job title
Call center representative
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
189
#5

Many companies relax after seeing the "under 50 employees is exempt" clause in the law, but in practice, that's an illusion. When major automotive giants put that contract in front of you and say "sign this or we won't buy parts," the legal exemption has zero commercial value.

MMeryem Ö***Member
Job title
Export manager
Sector
Cleaning services
Organization type
40-person manufacturing company
Joined
Feb 2024
Message
13
#6

We're a 25-person industrial automation team in Barcelona. Last month, a similar German client sent us a 40-item NIS2 security commitment form. We paid a freelance specialist 3,800 euros for internal logging and firewall configuration, patched the gaps, and got the form approved.

AAhmet Y***Expert
Job title
Field sales representative
Sector
Consulting
Organization type
regional distributor
Joined
Oct 2023
Message
2
#7

Is your client just asking for a self-assessment declaration signed by an authorized company officer, or are they requiring a penetration test or audit report from an accredited third-party cybersecurity firm? This distinction will massively change your operational costs.

HHalideNew member
Job title
Foundation manager
Joined
Aug 2024
Message
44
#8

In Spain, the National Cybersecurity Institute (INCIBE) provides guidelines and self-assessment tools for businesses in the supply chain. Before responding to your client, it would be beneficial to review the minimum security measures outlined in INCIBE's SME guides.

OOsmanMember
Job title
Agricultural machinery dealer
Joined
May 2024
Message
70

Doki · Incident response support · 2023

#9

You aren't in the tier that directly faces statutory fines under the law, but implementing the minimum measures in the specifications is a must if you don't want to lose the client.

EEmine T***Expert
Job title
Marketing manager
Sector
E-commerce
Organization type
medium-sized business
Joined
Jan 2023
Message
23
#10

When we first heard about it it felt like just another piece of pointless European Union red tape. But when we audited our systems at the client's request, we realized our on-prem server was completely exposed to the outside world and former employees' passwords were still active. As annoying as the requirement is you're actually saving your own company from disaster.

Correction: I misremembered the figure, it was a bit lower.

DDoruk Y***ExpertCommunity member
Joined
Feb 2025
Message
99
#11

I'm curious too.

FFurkan U***Member
Job title
Administrative manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
84
#12

I agree, and I'd like to emphasize that. Processes without records never improve, because you don't know what to fix.

RReyhan N***MemberCommunity member
Joined
May 2022
Message
223
#13

Good call starting this thread. Having backups accessible on the same network and with the same identity makes them part of the target.

Proven by experience.

ZZerrin K***ExpertCommunity member
Joined
Sep 2024
Message
139
#14

Three different views emerged, they all complement each other. Most incidents start with a leaked password, not a vulnerability.

Of course, it varies if your situation is different.

EEmrahMember
Job title
Business Analyst
Organization type
chain store
Joined
Feb 2024
Message
108
#15

How did you solve this? Hasty decisions become decisions you have to fix six months later.

Don't rely on a single measure; go layer by layer. I'm also curious if anyone does it differently.

EElif G***ExpertCommunity member
Joined
Mar 2025
Message
3
#16

Theres a trap here let me mention it. btw mistakes made on the what is NIS2 side are usually reversible but expensive.

If you have questions write them; I'll answer as best I can.

HHavva K***MemberCommunity member
Joined
Jul 2024
Message
111
#17

There's also a measurement aspect to this. If you scold false alarms, nobody will report again.

That's all, sorry if I went on too long.

EEsra K***MemberCommunity member
Joined
Feb 2023
Message
3
#18

Theres a common mistake people make when doing this. Just because everyone does it doesnt mean its right.

Just leaving this note it might be useful.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#19

The most overlooked point about what is NIS2 is this: Everyone rushing into what is NIS2 gets stuck at the same point.

Correct me if I'm wrong.

GGürkan B***MemberCommunity member
Joined
Oct 2024
Message
407
#20

I think it's hard to be that definitive about what is NIS2. Trying to do this alone is the most expensive way.

Most time waste accumulates in tasks waiting for approval.

Reply