forumNew topic

NIS2 regulation: They told us we fall under it, how can I verify this in Italy?

FFurkan Y***MemberCommunity member
Joined
Jan 2024
Message
11
#1

We run a company in the Turin industrial area manufacturing precision mechanical parts for major automotive suppliers and energy sector producers. We have 68 employees on payroll and we closed last year with 14 million euros in revenue. Last week one of our biggest clients in Italy sent over an extensive security questionnaire stating that we qualify as a critical supplier under the NIS2 directive.

In the letter, they're asking about our cybersecurity measures, incident reporting workflows, and whether we comply with specific technical standards. They implied that failure to do so could result in us being removed from their vendor list. We're a mid-sized manufacturer; we aren't a direct operator of critical infrastructure, but they claim we fall within the regulation's scope via the supply chain.

How and where can we officially verify whether this regulation legally applies directly to us in Italy? What is the competent authority what does the regulatory timeline look like, and are our primary client's demands a direct statutory obligation or a contractual safeguard?

MMehmet I***MemberCommunity member
Joined
May 2024
Message
3
Most Helpful#2

Short answer: To verify direct statutory applicability of the NIS2 directive in Italy, you need to check your business criteria through the official portal set up by the national cybersecurity authority, the Agenzia per la Cybersicurezza Nazionale (ACN). Even if you qualify as a medium-sized enterprise and aren't directly mandated by law, your primary client still holds the right to require this level of security as a contractual prerequisite.

Under Italy's transposing national legislation, essential and important entities are classified based on headcount and turnover thresholds. As a general rule, companies with at least 50 employees and over 10 million euros in turnover that operate in the covered annex sectors fall within scope. To check whether you are directly subject, go through the self-assessment or registration flow on the ACN portal using your tax code and business activity code (ATECO).

The critical distinction here is this: even if you are not directly regulated by law, the NIS2 directive legally obligates essential entities to audit the cybersecurity of their own supply chains. If your client operates in a critical sector like energy, the law forces them to demand these standards from you to mitigate their own risk. Therefore, your situation is not a direct administrative mandate from the state, but rather a contractual security requirement you must fulfill to keep doing business with them.

ZZerrin T***Member
Job title
Export manager
Sector
Law
Organization type
boutique agency
Joined
Mar 2024
Message
3
#3

Before rushing into hiring expensive consultants, go through the checklist sent by your client with your IT team. Typically they're looking for MFA, routine backups, endpoint protection, and encryption. That's just standard baseline security hygiene anyway, and most of it can be sorted out on a reasonable budget.

EEsra U***MemberCommunity member
Joined
Feb 2026
Message
160
#4

The biggest focus areas for suppliers under NIS2 are access management and incident response plans. They'll likely expect you to have a mechanism in place to detect and report any breach on your network within 24 hours. If your shop-floor CNC machines share the same local network as your office PCs, getting network segmentation in place should be your very first step.

TTuğçe U***Expert
Job title
Production planning
Sector
Electrical-electronics
Organization type
40-person manufacturing company
Joined
Jan 2023
Message
174
#5

We're a parts supplier with 55 employees and around 11 million euros in revenue. Our main client in Italy demanded a similar audit six months ago. Getting external help to bring our systems up to standard cost us about 18,000 euros and took three months of work, but it saved us from losing the master agreement.

JJülide V***Member
Job title
Digital marketing specialist
Sector
Chemistry
Organization type
sole proprietorship
Joined
Jul 2023
Message
320
#6

Big corporate clients are panicking over NIS2 right now and trying to offload their own legal liabilities onto subcontractors. Not every item on that form they sent you is necessarily mandatory by law. The Italian decree states that suppliers must be evaluated based on the principle of proportionality. Try to negotiate by proposing alternative security measures for requirements that exceed your capacity.

EEfe Y***Member
Job title
Site Manager
Sector
Leather
Organization type
boutique agency
Joined
Jul 2025
Message
367
#7

acn put out a survey-style guide on their official site, u put in your ateco code and it tells u straight up if you're in scope... like but if the client is pushing for it, that code doesn't really matter tbh if they don't want to they just won't renew the contract.

TTuğçe Y***Member
Job title
Quality Assurance Manager
Sector
Food wholesale
Organization type
regional distributor
Joined
Mar 2022
Message
329
#8

With 68 employees and a revenue of 14 million euros, your company clearly falls into the medium-sized enterprise category. Entities supplying critical parts to the energy sector are expected to comply indirectly with supply chain security regulations, even if they fall outside direct scope. We advise you to complete the form thoroughly and ensure your corporate records are readily accessible.

AAleyna E***MemberCommunity member
Joined
Aug 2024
Message
80
#9

Here are the steps you should take right now: 1) Confirm your official scope on the ACN portal using your ATECO code, 2) List the missing items from the client survey by priority and draft a budget, 3) Instead of outright rejecting the client's request, buy some time by presenting a six-month roadmap outlining your planned security improvements.

ŞŞerife K***Expert
Job title
System administrator
Sector
Machinery manufacturing
Organization type
workshop
Joined
May 2023
Message
154
#10

We went through something similar two years ago with a German manufacturer during a quality certification process. It felt completely unnecessary and overwhelming at first, but once we implemented those changes and tightened internal security, we not only prevented internal data loss but also used it as a strong credential when bidding for other large corporations.

AAlper K***MemberCommunity member
Joined
Jun 2024
Message
366
#11

Youre right. Most incidents start with a leaked password, not a vulnerability.

If its your first time, start small; scaling comes later. anyway thats all sorry if I went on too long.

GGamze K***MemberCommunity member
Joined
Oct 2022
Message
3
#12

You're right.

KKübra K***VeteranCommunity member
Joined
Oct 2025
Message
59
#13

Correct in theory, but it doesn't work that way in practice. Payment information changes are never verified through the channel they came from.

I'm also curious if anyone does it differently.

LLevent A***MemberCommunity member
Joined
Feb 2022
Message
7
#14

Here's how it went for us. When you try to change everything at once, nothing settles.

An automated scan report is not the same as a penetration test. If you post the result here, it will help others too.

UUğur G***Member
Job title
General coordinator
Sector
Sports and fitness
Organization type
20-person company
Joined
Oct 2023
Message
11
#15

Heres how it went for us. like if 2FA is on, a stolen password alone is useless.

Good luck with that.

AAhmet N***Expert
Job title
Store associate
Sector
Construction
Organization type
a company within a holding
Joined
Jul 2022
Message
153
#16

I went through the same thing.

MMurat Y***Member
Job title
Customer service representative
Sector
Jewelry
Organization type
a company within a holding
Joined
Jun 2025
Message
397

Doki · Brand identity · 2023

#17

Let me share my experience. Most incidents start with a leaked password not a vulnerability.

Just leaving this note it might be useful.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#18

For the record: the most common mistake in this area is relying on a single preventive measure. Go layer by layer — if one fails, the other stops it.

ÖÖmer D***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Aug 2024
Message
341
#19

I cant fully agree with this. I mean most incidents start with a leaked password not a vulnerability.

TTuğçe B***MemberCommunity member
Joined
Oct 2025
Message
100
#20

I think it's hard to be that definitive about nis2 regulation. When you try to change everything at once nothing settles.

That's all, sorry if I went on too long.

Reply