We run a company in the Turin industrial area manufacturing precision mechanical parts for major automotive suppliers and energy sector producers. We have 68 employees on payroll and we closed last year with 14 million euros in revenue. Last week one of our biggest clients in Italy sent over an extensive security questionnaire stating that we qualify as a critical supplier under the NIS2 directive.
In the letter, they're asking about our cybersecurity measures, incident reporting workflows, and whether we comply with specific technical standards. They implied that failure to do so could result in us being removed from their vendor list. We're a mid-sized manufacturer; we aren't a direct operator of critical infrastructure, but they claim we fall within the regulation's scope via the supply chain.
How and where can we officially verify whether this regulation legally applies directly to us in Italy? What is the competent authority what does the regulatory timeline look like, and are our primary client's demands a direct statutory obligation or a contractual safeguard?