In summary: NIS2 is the European cybersecurity directive that binds large and "essential" entities. But there's a trap for SMBs: those large companies are legally required to secure their suppliers too. If you supply to an automotive or aerospace firm, a shipyard, or a major food processor in Galicia, sooner or later they'll ask for proof that your house is locked down. Here's what they can demand and how to prepare without dismantling your company.

What NIS2 is and why it sounds like someone else's problem

Let me start at the beginning, because otherwise this looks like legal chaos. NIS2 is Directive (EU) 2022/2555, the European regulation requiring certain companies to have serious cybersecurity: risk management plans, incident reporting, staff training, and the rest. Spain transposed it into law in late 2024 (Royal Decree 1029/2024).

The problem is when you read the law it looks aimed at network operators, banks, and multinationals. And it's true: your SMB won't get a NIS2 inspection just for being an SMB. The directive applies to so-called "essential" and "important" entities, which are usually mid-size and large.

But here's where most industrial SMBs in Galicia fall asleep. The law doesn't directly name you. It names your customer. And your customer, to comply, will legally require you to comply by contract.

The supply chain trap

This is the part that really matters and that almost nobody discusses at coffee in the industrial park.

NIS2 requires essential and important entities to manage supply chain risks. Put plainly: if a large company depends on you to manufacture, supply, or deliver a service, your security failure is their security failure. So the law tells them, quite literally, to account for "relationships with suppliers and service providers" when they protect their networks.

What does that mean in practice? The procurement department of your big customer will ask you to fill out a form (or an interminable questionnaire) where you certify you have certain cybersecurity measures. It's not a suggestion: if you don't provide it, you don't get the bid. Period.

Here's a real example from around here. An automotive supplier in Galicia that's been supplying a large plant for years gets an email from the customer: "Attached cybersecurity questionnaire, must be completed by September 30 to maintain vendor status." The company had an accounting computer with unpatched Windows and the same USB drive for everything. They'd never heard of NIS2. But it had just landed on them through the back door.

24 h The affected entity has to notify a serious incident (NIS2)
€10M Maximum fine or 2% of annual global turnover
4 sectors Use cases for Galicia's Industrial Data Space: automotive, shipbuilding, food, and IT

It affects you if you manufacture or supply in Galicia

Galicia has an industrial base heavily dependent on large customers: automotive (the Vigo cluster and its supplier network), shipbuilding (shipyards and their chains), food (preserved fish, dairy, meat processing for distributors and brands), and IT. These are precisely the four sectors that the Galician Industrial Data Space is using to demonstrate real cases of cross-company collaboration.

If your company is part of any of those chains, the risk of being asked "about cybersecurity" one day is high. And you don't have to be large: supply chains break at the weakest link, and the big players know it.

We also have the AMTEGA Industrial Cybersecurity Normative Guide (April 2026), which already warns of this same thing: NIS2 expands the scope to sectors that didn't look before, and shines light on convergence between IT (office systems) and OT (operational technology: PLCs, controllers, production lines). If you have a PLC connected to the network that hasn't been patched in years, that's your hot spot.

What your customer can ask you for (and how not to panic)

They won't ask you to turn into a nuclear security facility. Usually it's a questionnaire and some basic measures. Here's what typically comes up:

If your customer is large and you're a small link, the most likely ask is the questionnaire and maybe a basic certificate. Don't panic: most of this is common sense and getting organized, not a €50,000 consulting bill.

"NIS2 won't fine you for being an SMB. But your customer can stop buying from you if you don't give them confidence. Cybersecurity has become a condition of sale, not a whim of the IT department."

Cybersecurity team, BigLobster

Mistakes that lock you out of a bid

We've seen these repeat. If you want to keep winning large-customer tenders, avoid these:

Thinking "it doesn't apply to me because I'm small"

We've said it, but I'll say it again: it applies to you by contract. The law won't fine you, but the buyer will shut you out.

Having no idea what equipment you have connected

The first question on any form is "inventory your assets." If you don't know, you can't answer. One afternoon of inventory beats a thousand promises.

Having a backup but never testing it

Restoring a backup is the only way to know it exists. Test it once a year, even on an old machine.

Mixing your office network with your production network

If ransomware on the reception desk reaches the production-line PLC, you stop production. Separating them is cheap and saves you enormous headaches.

How to start without spending a fortune

You don't need to hire an army. Here's the roadmap we follow with industrial SMBs that ask for help:

That covers 80% of what a mid-size customer will ask. The rest (certifications, audits) depends on who you supply to. And if you want a solid foundation, check out our guide to industrial cybersecurity for SMBs, which covers the OT (plant) side with more detail.

Frequently asked questions

Does NIS2 apply directly to my SMB?

Unless you're an essential or important entity by size or sector, no. The law doesn't name you directly. But if you supply someone who is obligated, the requirement will reach you by contract. That's why it's smart to prepare anyway.

What if I don't comply with what my customer asks?

It depends on each customer, but usually they remove you from the vendor register or don't admit you to the bid. It's not a legal fine: it's losing the order. In sectors like automotive or shipbuilding, that can be a big chunk of your revenue.

How much does it cost to prepare?

For a small SMB, basic measures (MFA, backup, inventory, incident plan) cost more in time than in money. If you already have decent equipment, the cost is low. Where the price jumps is if you need to get certified or audited for a demanding customer, but that's case by case.

Are NIS2 and the Cyber Resilience Act the same?

No. NIS2 requires companies (and their supply chains) to manage risk. The Cyber Resilience Act requires products with software (from a PLC to an IP camera) to be secure from the factory. They're complementary: one looks at the company, the other at the device. If you make connected machinery, both apply to you.

Where can I get help in Galicia?

AMTEGA and Igape have guides and support, and the Galician Industrial Data Space works real cases in automotive, shipbuilding, food, and IT. For the practical part of your company (inventory, backup, network separation), any local consulting firm or we ourselves can help you get it ready before the questionnaire arrives.

Want to be ready next time they ask?

We help you get your industrial SMB set up with the basic cybersecurity measures your customers will demand: inventory, tested backup, network separation, and paperwork ready for the bid. No smoke, no €50,000 consulting bill.

Let's talk →