Skip to Content

Information security

Your drawings do not leave our control.

Aerospace customers now assess a supplier's cyber posture before they assess its machines. Airbus annexes security requirements to the purchase order. Safran requires a recognised cyber maturity label. NIS2 makes every European prime responsible for the security of its direct suppliers. This page states where ESM stands, including where it is not yet where it intends to be.

In place

Customer data segregation

Each customer's technical data is held in its own controlled space. No customer can see another's definitions, programmes or quality records.

In progress

Recognised cyber maturity label

ESM does not hold a cyber maturity label today. The label most European primes refer to is AirCyber, run by BoostAeroSpace for Airbus, Dassault Aviation, Safran and Thales, with bronze, silver and gold levels; it is also one of the three programmes covered by the GITAS–GIFAS memorandum of June 2025.

Not held

ISO 27001

ESM is not ISO 27001 certified and does not claim to be. The major European primes do not require it from a machining supplier at our level. We state it rather than let you find out.

The commitments

What a customer can expect from us

These are the commitments we are prepared to sign, and the ones a security annex to a purchase order normally asks for. Where the practice is in place we say so; where it is being built we say that instead.

CommitmentWhat it means hereStatus
Classification by defaultAny technical data received from a customer is treated as confidential from arrival, whether or not it carries a marking.In place
SegregationCustomer data is isolated from that of other customers, in storage and in access rights.In place
Access on needAccess is granted by role, to the people working on the file, and reviewed when someone changes job or leaves.In place
Incident notificationNotification of the customer without delay on any incident affecting its data, with the facts known at that point rather than a finished investigation.Committed
Flow-down to partnersThe same requirements passed in writing to any partner that receives customer data, with prior written authorisation from the customer before any such access.In place through the purchase conditions
Right of auditThe customer, or an auditor it appoints, may audit these arrangements.Committed
Return and destructionReturn or documented destruction of customer data at the end of the contract, on a plan agreed before it starts.Committed

Why this page exists

Because the question is now asked before the first order

Directive (EU) 2022/2555, known as NIS2, requires European essential and important entities to manage the security of their supply chain and to take account of the specific vulnerabilities and overall cyber practices of each direct supplier. Every European prime and tier one in aerospace falls under that regime. A supplier outside the Union is not subject to NIS2 directly, but it is squarely inside the assessment its customers are obliged to carry out.

In parallel, Airbus annexes security requirements to its purchase orders, and Safran requires its external providers to hold a recognised cyber maturity label. Aero Excellence, the European industry programme run by ASD with GIFAS, ADS and BDLI, assesses cyber security alongside operational excellence and environment.

So the question is no longer whether a machining subcontractor is concerned. It is whether it can answer.

Send us your security questionnaire.

If your qualification process includes a cyber annex or a supplier security assessment, send it. We complete it honestly, including the lines where the answer is no.