We are an industrial valve and automation components manufacturer based in Madrid, with 38 employees and an annual turnover around 4,2 million EUR. Our client portfolio includes two major regional utilities operating power distribution and water networks across Spain.
Last week, one of these clients sent an official notice stating that they have launched supply chain audits under the new EU cybersecurity directive, NIS2. Attached is an 18-page information security requirements questionnaire covering everything from MFA and incident reporting timelines to backup drill verifications and staff training logs. It explicitly states that failure to comply may lead to the suspension of our supplier contract.
We are a mid-sized manufacturer, not an operator of critical infrastructure ourselves. How does NIS2 legislation practically affect us in Spain? Are we legally mandated to comply, or is this purely client-driven contractual pressure? Where should we start?