We are a logistics software and data integration company with 22 employees based in Lille, France. We provide an order-tracking module to one of the leading retail and transport chains in France. Yesterday, we received an official letter from our client's procurement and risk management department. The letter stated that, under the European Union's NIS2 directive, we are in scope directly or as a critical supplier, and therefore we will very soon be subject to a comprehensive cybersecurity audit and mandatory certification processes.
The form they attached includes requirements that would require hundreds of thousands of euros in investment ranging from a 24/7 security operations center to digital forensics procedures. Our annual turnover is around 1.8 million EUR. As far as I know, this directive excluded small businesses.
What actually is NIS2, and can it legally be applied directly to a business like ours? Or is our major client trying to offload its own legal responsibilities onto us through the supply chain? How should we clarify the situation before panicking and buying expensive consulting services?