Information security
Your drawings do not leave our control.
Aerospace customers now assess a supplier's cyber posture before they assess its machines. Airbus annexes security requirements to the purchase order. Safran requires a recognised cyber maturity label. NIS2 makes every European prime responsible for the security of its direct suppliers. This page states where ESM stands, including where it is not yet where it intends to be.
Customer data segregation
Each customer's technical data is held in its own controlled space. No customer can see another's definitions, programmes or quality records.
Recognised cyber maturity label
ESM does not hold a cyber maturity label today. The label most European primes refer to is AirCyber, run by BoostAeroSpace for Airbus, Dassault Aviation, Safran and Thales, with bronze, silver and gold levels; it is also one of the three programmes covered by the GITAS–GIFAS memorandum of June 2025.
ISO 27001
ESM is not ISO 27001 certified and does not claim to be. The major European primes do not require it from a machining supplier at our level. We state it rather than let you find out.
The commitments
What a customer can expect from us
These are the commitments we are prepared to sign, and the ones a security annex to a purchase order normally asks for. Where the practice is in place we say so; where it is being built we say that instead.
| Commitment | What it means here | Status |
|---|---|---|
| Classification by default | Any technical data received from a customer is treated as confidential from arrival, whether or not it carries a marking. | In place |
| Segregation | Customer data is isolated from that of other customers, in storage and in access rights. | In place |
| Access on need | Access is granted by role, to the people working on the file, and reviewed when someone changes job or leaves. | In place |
| Incident notification | Notification of the customer without delay on any incident affecting its data, with the facts known at that point rather than a finished investigation. | Committed |
| Flow-down to partners | The same requirements passed in writing to any partner that receives customer data, with prior written authorisation from the customer before any such access. | In place through the purchase conditions |
| Right of audit | The customer, or an auditor it appoints, may audit these arrangements. | Committed |
| Return and destruction | Return or documented destruction of customer data at the end of the contract, on a plan agreed before it starts. | Committed |
Why this page exists
Because the question is now asked before the first order
Directive (EU) 2022/2555, known as NIS2, requires European essential and important entities to manage the security of their supply chain and to take account of the specific vulnerabilities and overall cyber practices of each direct supplier. Every European prime and tier one in aerospace falls under that regime. A supplier outside the Union is not subject to NIS2 directly, but it is squarely inside the assessment its customers are obliged to carry out.
In parallel, Airbus annexes security requirements to its purchase orders, and Safran requires its external providers to hold a recognised cyber maturity label. Aero Excellence, the European industry programme run by ASD with GIFAS, ADS and BDLI, assesses cyber security alongside operational excellence and environment.
So the question is no longer whether a machining subcontractor is concerned. It is whether it can answer.
Send us your security questionnaire.
If your qualification process includes a cyber annex or a supplier security assessment, send it. We complete it honestly, including the lines where the answer is no.