The NIS2 Directive is the EU law that requires thousands of companies to strengthen their cybersecurity, backed by fines running into the millions. Formally it is Directive (EU) 2022/2555, in force since January 2023. It extends cybersecurity obligations to essential and important entities in 18 sectors. Spain has still not transposed it, so its obligations will reach companies through the national law, and the Commission has already referred Spain to the Court of Justice of the European Union over the delay. If your company has 50 or more employees or a turnover above 10 million euros and operates in a critical sector, NIS2 affects you. This guide explains who it covers, which measures it requires, which deadlines it sets and what legal risk your management body takes on.
If you need a cybersecurity and NIS2 lawyer in Spain, request a free initial assessment.
NIS2 is Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022. It replaces the first NIS directive of 2016 and came into force on 16 January 2023. Its aim is to raise the minimum level of cybersecurity across the European Union in a harmonised way. To do so it widens the sectors covered, tightens the technical and governance measures and unifies incident reporting deadlines.
NIS1 only covered a small group of operators of essential services identified manually by each country. This produced huge differences between Member States. NIS2 fixes that problem: it defines precisely the sectors affected, creates two categories of entities and builds a deterrent and uniform penalty regime.
Spain has not completed the transposition of NIS2. The EU deadline expired on 17 October 2024 and Spain missed it. On 14 January 2025 the Council of Ministers approved the preliminary draft of the Cybersecurity Coordination and Governance Act, the legislative vehicle for transposing the directive, which creates a National Cybersecurity Centre. The law has still not been published in the Official State Gazette (BOE). And with the Spanish Parliament dissolved since 6 October 2026 because elections have been called, no law can go through until the new chambers are constituted on 23 December.
The delay has consequences. The European Commission sent Spain a reasoned opinion on 7 May 2025 for failing to transpose on time. On 8 July 2026 the Commission took the next step and referred Spain to the Court of Justice of the European Union. It is asking the Court to impose on the State a lump sum and daily penalty payments until transposition is complete. For companies the consequence is different. A directive that has not been transposed binds the State, not private parties, so NIS2 obligations will become enforceable when the Spanish law comes into force. What that law will require, risk management, incident reporting and supplier control, cannot be put in place in a few weeks, and whoever starts on the day of publication will be late.
NIS2 applies to entities in the 18 sectors listed in its Annexes I and II that have 50 or more employees or an annual turnover or balance sheet above 10 million euros. Below that threshold, a company does not become subject to it just by being a supplier to a covered entity, although it may receive contractual requirements from that customer, which has to manage the security of its supply chain.
The sectors covered are split between two annexes. Annex I groups the sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II lists other critical sectors: postal and courier services, waste management, manufacture and distribution of chemicals, production and distribution of food, manufacturing (of medical devices, electronics, machinery or vehicles), digital providers and research. If your activity fits any of these categories and you exceed the size threshold, you are within scope.
The directive divides covered entities into two categories with different levels of supervision and penalties. The difference matters: it determines how the authority oversees you and how much you risk.
| Criterion | Essential entity | Important entity |
|---|---|---|
| Who it usually is | Large companies in Annex I sectors, such as energy, transport, banking, health, water, digital infrastructure or public administration | Medium-sized companies in Annex I and companies in Annex II sectors, such as postal services, waste management, chemicals, food, manufacturing, digital providers or research |
| Supervision | Proactive (inspections and audits on the authority’s own initiative) | Reactive (following evidence or incidents) |
| Maximum fine | 10 million euros or 2 % of worldwide turnover | 7 million euros or 1.4 % of worldwide turnover |
In both cases the higher of the fixed amount and the percentage of turnover applies. Identifying which category you belong to is the first step in any compliance plan, because it changes the level of evidence you will need in an inspection.
Article 21 of NIS2 requires technical and organisational measures proportionate to the risk to protect network and information systems. It does not prescribe specific tools, but capabilities the company must be able to demonstrate. Proportionality is measured according to each organisation’s size, exposure and criticality.
The minimum measures every covered entity must put in place are the following:
A company that already has an ISO 27001 management system covers much of these measures. The usual gaps are three: early notification to the CSIRT, specific training for the management body and deeper supply chain management. Closing those gaps is usually faster than building the system from scratch.
Supply chain security is the new element that generates the most work. NIS2 requires verification, not just a declaration signed by the supplier. In practice this means reviewing and strengthening technology contracts: security clauses, supplier incident notification obligations, audit rights and service levels. If your company supplies a covered entity, you will receive those requirements by contract even if you do not exceed the thresholds yourself.
NIS2 requires significant incidents to be reported to the competent CSIRT in three successive stages. An incident is significant when it causes or is capable of causing severe operational disruption or financial loss, or when it affects third parties by causing considerable material or non-material damage.
In Spain, reports are channelled through the relevant CSIRT: INCIBE-CERT for the private sector, CCN-CERT for the public sector and ESPDEF-CERT for defence. Treating the 24-hour warning as an information formality is a mistake: it is a legal obligation, and failing to meet it can be penalised.
NIS2 shifts responsibility for compliance to the company’s management body. The board or equivalent must approve the risk management measures, oversee their implementation and receive specific cybersecurity training. This responsibility cannot be delegated: execution can be assigned to a CISO or a CTO, but ultimate responsibility stays with management.
The consequences are personal. For serious and repeated infringements, the competent authorities can temporarily suspend managers from their duties. That is why board decisions should be recorded in minutes and evidence of due diligence kept. Without that traceability, proving that you acted correctly is difficult.
The legal risk of poor cybersecurity management is already materialising in the Spanish courts, even without NIS2 transposed. Judgment 136/2025 of the Spanish Supreme Court of 19 February 2025 (Criminal Chamber) upheld a company’s subsidiary civil liability for a breach in its IT system.
The facts are telling. Cybercriminals impersonated the email account of an employee of Gamboa Automoción and sent false payment instructions to another company, which transferred 32,594.75 euros to a fraudulent account. The attacked company had detected a similar incident the day before and did not warn its business partners. The Supreme Court held that a company’s IT systems are an “establishment” for the purposes of Article 120.3 of the Spanish Criminal Code and upheld its subsidiary civil liability for failing to act with due diligence. The damage, therefore, does not come only from an administrative fine, but also from a civil claim by an injured third party.
The NIS2 penalty regime distinguishes by category of entity. Essential entities face fines of up to 10 million euros or 2 % of total worldwide annual turnover, whichever is higher. Important entities, up to 7 million euros or 1.4 %. On top of these figures there are administrative measures such as remediation orders or the temporary suspension of managers.
The risk is not only one of penalties. At the same time, European customers in regulated sectors are building NIS2 clauses into their supplier contracts. A company that cannot show compliance may be left out of tenders and contracts even before it receives a fine.
Preparing for NIS2 should not wait for publication in the BOE, because the technical measures take months to implement. A reasonable roadmap starts with four steps: determining whether the company is covered and in which category, carrying out a gap analysis against Article 21, closing the priority gaps and building the documentary evidence that an inspection will require.
How it fits with other rules is key. Many NIS2 incidents also involve a personal data breach notifiable to the Spanish Data Protection Agency (AEPD) under the GDPR, with its own deadlines. And contractual management of the supply chain connects with technology contracting. If you also manufacture or sell products with software, the Cyber Resilience Act is added on top, requiring exploited vulnerabilities to be reported since 11 September 2026. For a full view of the compliance framework, see our page on cybersecurity and NIS2 legal advice, and see how it relates to other regulatory obligations in our guide to the EU AI Act.
Not yet for companies. The directive has been in force since January 2023 and requires Spain to transpose it, but the deadline expired on 17 October 2024 and the national law has still not been published in the BOE. The Council of Ministers approved the preliminary draft on 14 January 2025, and on 8 July 2026 the Commission decided to refer Spain to the Court of Justice of the European Union over the delay. The obligations will become enforceable when the Spanish law comes into force, which, with the dissolution of the Spanish Parliament in October 2026, cannot go through before the next legislature.
As a general rule, NIS2 applies to entities in the sectors covered with 50 or more employees or a turnover above 10 million euros. A company below the threshold does not become subject to it just by being a supplier to a covered entity, but it may receive contractual requirements from that customer, which must manage the security of its supply chain under Article 21. Certain critical entities are covered regardless of their size.
Essential entities are subject to proactive supervision and fines of up to 10 million euros or 2 % of worldwide turnover. Important entities are subject to reactive supervision and fines of up to 7 million euros or 1.4 %. The category depends on sector and size. In general, large companies in Annex I sectors are essential, and the other entities covered by Annexes I and II are important.
Yes. A single incident can trigger two different reporting obligations: the NIS2 one to the competent CSIRT, in stages of 24 hours, 72 hours and one month, and the GDPR one to the Spanish Data Protection Agency when personal data are compromised, within 72 hours. They are complementary frameworks with different deadlines and authorities.
Does your company fall within the scope of NIS2? Book a free initial assessment and receive a diagnosis of your obligations, the gaps identified and a clear compliance plan.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
