forumNew topic

We were told NIS2 applies to us — are we legally liable in Spain, and what do we need to do?

OOkan F***Expert
Job title
Fintech product manager
Organization type
chain store
Joined
Aug 2023
Message
146
#1

We are an industrial valve and automation components manufacturer based in Madrid, with 38 employees and an annual turnover around 4,2 million EUR. Our client portfolio includes two major regional utilities operating power distribution and water networks across Spain.

Last week, one of these clients sent an official notice stating that they have launched supply chain audits under the new EU cybersecurity directive, NIS2. Attached is an 18-page information security requirements questionnaire covering everything from MFA and incident reporting timelines to backup drill verifications and staff training logs. It explicitly states that failure to comply may lead to the suspension of our supplier contract.

We are a mid-sized manufacturer, not an operator of critical infrastructure ourselves. How does NIS2 legislation practically affect us in Spain? Are we legally mandated to comply, or is this purely client-driven contractual pressure? Where should we start?

DDamla C***Member
Job title
Customer Relations Manager
Sector
Printing
Organization type
300-person organization
Joined
Nov 2022
Message
229
Most Helpful#2

Short answer: While your headcount and revenue fall below the medium-to-large business thresholds that trigger direct NIS2 obligations, you are indirectly bound by it due to supply chain security mandates on critical sectors. Even if the state cannot penalize your firm directly, your client legally cannot retain suppliers that fail to meet these baseline security requirements.

Direct scope under the NIS2 directive generally starts at 50 employees or 10 million EUR in annual turnover. With 38 staff and 4,2 million EUR in revenue, you are not categorized directly as an 'essential' or 'important' entity. However, Article 21 strictly requires in-scope entities—such as your energy and water utility clients—to manage cybersecurity risks throughout their supply chain. The 18-page checklist sent by your client is their effort to secure compliance with the Spanish Esquema Nacional de Seguridad (ENS) and CCN-CERT guidelines.

The primary bodies supervising this framework in Spain are CNPIC for critical operators and INCIBE for general businesses. At this stage, instead of panicking and committing to exorbitant third-party certifications, your best move is to address the core cyber hygiene requirements outlined in your client's audit sheet.

You should prioritize three concrete actions: roll out multi-factor authentication across all corporate access points, run and document offline backup restoration tests for your critical operational systems, and draft an internal incident response procedure ensuring you can formally notify the client within 24 hours of a breach. Documenting these steps will allow you to pass their vendor risk assessment without issue.

DDefneMember
Job title
SOC Analyst
Organization type
a company within a holding
Joined
Feb 2024
Message
146
#3

The biggest technical hurdle on that questionnaire is usually network segmentation and access control. If you supply parts or remote maintenance to an energy distributor, you must prove that your OT production network is completely isolated from the standard office LAN and public-facing servers.

İİbrahim A***ExpertCommunity member
Joined
May 2024
Message
1
#4

First thing tomorrow, sit down with the form and split it into three buckets: what you already do, what you can fix in two weeks with simple config tweaks, and what requires CapEx. Fill out and return the first two right away, and provide a clear timeline for the rest. That approach is usually more than enough to protect the contract.

ÖÖmerMember
Job title
Financial Analyst
Joined
Dec 2023
Message
126
#5

Last month, a logistics client of ours in Barcelona sent us a similar document. An external consultant quoted 12,000 EUR for the audit. We sat down with the client's security lead and realized all they actually wanted was basic cyber awareness training for staff and mandatory password managers; we sorted it out internally for 600 EUR.

EElif T***Member
Job title
Human Resources Manager
Sector
Freight
Organization type
120-person company
Joined
Sep 2024
Message
265
#6

Even if you are legally exempt, a corporate client's procurement spec might as well be the law; fail to meet the requirements and you're out of the tender.

DDeniz D***Member
Job title
Agency Founder
Sector
Security services
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
122
#7

Does the document you received only ask for a self-assessment questionnaire or do they require an independent third-party audit report or Esquema Nacional de Seguridad (ENS) compliance certificate? That single detail will completely change your budget.

CCeren A***Expert
Job title
Brand Manager
Organization type
chain store
Joined
Aug 2023
Message
154
#8

Even though NIS2 transposition into national law hasn't even fully settled in Spain yet, big corps are dumping boilerplate audit forms onto every single vendor. It's just a knee-jerk reaction to cover their own backs by squeezing small businesses; you can actually negotiate most of those items.

MMelis E***Expert
Job title
Quality control inspector
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Mar 2023
Message
50
#9

The 3 critical security areas you need to address immediately are: 1) Mandatory multi-factor authentication on all remote connections and email, 2) Encrypted, air-gapped backup routines, 3) A written offboarding procedure to instantly revoke access rights when vendor personnel leave.

AAyşegülMember
Job title
Boutique hotel
Organization type
workshop
Joined
Aug 2024
Message
86
#10

It gets exhausting when small shops of 30-40 people like us get treated like were running a nuclear power plant. I mean but once you get these procedures in place, it actually turns into a huge selling point against your competitors, look at it that way.

OOsman U***Member
Job title
Secretary
Sector
Food wholesale
Organization type
cooperative
Joined
Dec 2024
Message
312
#11

I completely agree. An untested backup is not a backup.

Everything goes well for the first three months; problems arise in the fourth. If you post the result here, it will help others too.

ÖÖzgür Y***Member
Job title
IT Manager
Sector
Chemistry
Organization type
boutique agency
Joined
Nov 2023
Message
5

Doki · Mobile app · 2025

#12

we've heard this a lot, but it never happened like that for us. any unwrittten clause becomes a point of disagreement later as both sides remember it differently.

proven by experience.

KKader B***Expert
Job title
Social media manager
Sector
Sports and fitness
Organization type
boutique agency
Joined
Nov 2024
Message
56
#13

Timely topic.

YYusuf Y***Member
Job title
Social media manager
Sector
Real estate
Organization type
a company within a holding
Joined
Sep 2024
Message
79
#14

To get into the details: Most time waste accumulates in tasks waiting for approval.

Of course it varies if your situation is different.

İİlknur Y***MemberCommunity member
Joined
Sep 2025
Message
2
#15

This is exactly what we experienced. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Of course, it varies if your situation is different.

DDilara T***Member
Job title
Social media manager
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2024
Message
333
#16

Correct. Taking measures without an inventory leaves doors you haven't seen open.

If you post the result here, it will help others too.

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
#17

Let me speak from the other side; I'm on the supplier side. If 2FA is on, a stolen password alone is useless.

This is my opinion, I'm not claiming it's absolute truth.

PPolat M***MemberCommunity member
Joined
Nov 2025
Message
69
#18

Let me speak from the other side; I'm on the supplier side. An automated scan report is not the same as a penetration test.

If you post the result here, it will help others too.

UUfuk B***MemberCommunity member
Joined
Sep 2024
Message
114
#19

This approach has a cost which isn't discussed... People defend habits, not processes. Resistance comes from there.

Just leaving this note, it might be useful.

KKadir Z***Member
Job title
Production Manager
Sector
Packaging
Organization type
300-person organization
Joined
Apr 2023
Message
123

Doki · Penetration test · 2025

#20

There is something to watch out for. Don't hesitate to ask; those who don't ask always pay more.

If I were you Id go this route.

Reply