- Job title
- Agency Founder
- Sector
- Law
- Organization type
- 120-person company
- Joined
- Nov 2025
- Message
- 19
Doki · Server maintenance contract · 2025
We are a 42-person engineering firm based in Bilbao, designing molds and industrial components for the automotive supply chain. Our annual turnover is around 6 million euros. Last week, one of our major OEM clients in Germany and Spain sent us an extensive cybersecurity compliance agreement, stating that we must comply with the NIS2 directive, otherwise we will be removed from their approved vendor list.
We discussed this internally, but nobody could figure out the exact scope. From what I read online, it appears to be a new European Union cybersecurity regulation covering critical infrastructure. But we're not a power plant, water utility, or bank; we are a mid-sized contract manufacturing and design shop.
What is the NIS2 directive, who falls under its scope, and what is its legal status in Spain? Is an SME with fewer than 50 employees like us genuinely subject to direct enforcement under this law, or is our large client just pushing their own legal obligations onto us via contractual pressure?