NIS2, or why your customer's customer is asking
Read this if a European integrator has suddenly sent you a security questionnaire.
The NIS2 Directive treats electricity as an essential sector. Utilities, DSOs and large integrators inside the EU are legally obliged to manage cybersecurity risk across their supply chain, which they discharge by pushing requirements down their contracts to component suppliers. Most manufacturers outside Europe meet NIS2 not as a filing obligation of their own, but as a procurement wall: the questionnaire that arrives before the purchase order, and the clause that follows it.
Incident reporting runs on a tight clock, with an early warning due within 24 hours of a significant incident. A supplier who cannot support that timeline is a supplier the integrator has to explain to its regulator.
Directive (EU) 2022/2555 · eur-lex.europa.eu/eli/dir/2022/2555/oj