Cybersecurity for SMEs in Spain: where to start without a large-enterprise budget
A practical, source-backed guide for a Spanish SME to prioritise cybersecurity without a large-enterprise budget.

On this page
Many Spanish SMEs assume that cybersecurity is a luxury reserved for large corporations with dedicated IT departments. The reality is the opposite: SMEs are a frequent target precisely because they tend to have fewer controls in place, and a ransomware incident or data leak can compromise business continuity without there being any financial margin to absorb the blow. The good news is that most of the real improvement in security does not depend on budget size, but on properly applying a small number of measures, in the right order.
This guide is not meant to sell you technology. It aims to give you a realistic map: what Spanish and European regulation requires (or will require), what you can do right now with free or low-cost resources, and at what point it makes sense to bring in specialised outside help.
The regulatory context: what applies today and what is on the way
NIS2: in force at European level, pending national law in Spain
Directive (EU) 2022/2555, known as NIS2, sets out risk-management and incident-notification obligations for "essential" and "important" entities across 18 critical sectors: energy, transport, banking, health, digital infrastructure, public administration, water management and others [1]. The transposition deadline for Member States expired on 17 October 2024.
Spain did not meet that deadline. According to press sources, the Council of Ministers approved the draft bill on 14 January 2025. At the time of writing, the text was still going through parliamentary process and had not been published in the BOE (Spain's Official State Gazette). As of this writing, the European Commission maintains an open infringement procedure against Spain for incomplete transposition of the NIS2 Directive; the exact status of the procedure (including any possible referral to the CJEU) can be checked directly on the Commission's Infringement Decisions Register (ec.europa.eu/atwork/applying-eu-law) or at ec.europa.eu/commission/presscorner.
This has an important practical implication that many SMEs are unaware of: the European directive is already in force and produces effects even though the Spanish law has not yet been passed. If your company falls within scope — by sector, by size, or as a critical supplier to an essential or important entity — the substantive risk-management and incident-notification obligations do not wait for Congress to finish processing the national text. The exact scope for each SME will depend on the final text and on your specific contractual situation; if you're unsure whether it applies to you, it is reasonable to seek specific advice and check your particular case against the text that is ultimately passed.
ENS: mandatory if you work with the public sector, a useful reference if you don't
The Esquema Nacional de Seguridad (ENS, National Security Framework), regulated by Real Decreto 311/2022 (Royal Decree 311/2022), published in the BOE on 4 May 2022 and in force since 5 May 2022, is mandatory for the entire public sector and for companies that provide services or supply technology to public administrations [3]. The decree classifies systems into three categories — basic, medium and high — according to the impact an incident would have on the confidentiality, integrity, availability, authenticity and traceability of information (Annex I), and requires security measures graduated according to that category (Annex II) [3].
If your SME does not contract with public administration, the ENS does not directly bind you. But if you aim to bid for contracts with public bodies, or if a public-sector client requires accreditation, you will need to certify at the category that corresponds to your systems, with mandatory audits every two years for the medium and high categories [3].
GDPR: the obligation you almost certainly already have
If your company processes the personal data of customers, employees or suppliers — which is practically universal — the General Data Protection Regulation already requires you to implement security measures "appropriate to the risk" and to notify security breaches to the Agencia Española de Protección de Datos (Spanish Data Protection Agency) within a set deadline. This obligation is neither future nor conditional: it has been in force since 2018 and is the minimum legal baseline any SME starts from, regardless of whether NIS2 or the ENS applies to it.
Where to start: priorities on a limited budget
You don't need to tackle everything at once. The order matters more than the number of measures.
1. Basic inventory: what you have and where it is
You can't protect what you don't know you have. Before buying anything, spend a few hours listing: devices (computers, servers, corporate mobiles), critical applications (accounting, CRM, email), and where sensitive information lives (customer data, payroll, contracts). This costs no money, only time, and is the foundation for everything else.
2. Multi-factor authentication (MFA) for email and remote access
Most successful breaches start with a stolen or reused password. Turning on two-step verification for corporate email, remote access (VPN, remote desktop) and administrator accounts is free in practically every platform (Microsoft 365, Google Workspace) and drastically reduces the risk of unauthorised access even if a password is leaked.
3. Regular, tested backups
A backup that has never been restored is not a backup, it's an assumption. INCIBE notes that most SMEs that have strengthened their security have done so by applying basic measures, including regular backups with verified restoration [5]. The standard recommendation is to keep at least one copy disconnected from the network (offline) or with a separate cloud provider, precisely so that ransomware that encrypts your systems cannot also encrypt the backup.
4. Updates and patching
Keeping operating systems, browsers and applications up to date closes known vulnerabilities that attackers exploit in an automated way [5]. Turning on automatic updates wherever possible is the lowest-effort, highest-return measure available.
5. Basic phishing awareness training
Fraudulent email remains the most common entry point. You don't need a sophisticated training programme: a brief session explaining how to spot suspicious senders, manipulated links and urgent transfer requests (CEO fraud) significantly reduces the risk, and it's free if delivered using INCIBE materials.
6. Password policy and a password manager
Unique, strong passwords per service, managed with a password manager (there are free and low-cost options), prevent the reuse that turns a minor leak into a widespread compromise.
7. A minimal incident-response procedure
You don't need a 40-page plan. You need to know, before it happens, who to call, what to isolate first and what not to do (such as paying a ransom without advice). Having this decided in advance saves the most costly hours of any incident: the first ones.
Free resources that already exist and many SMEs are unaware of
Spain has public infrastructure designed specifically for businesses without an in-house technical team:
- INCIBE's guides for businesses: security policy templates, self-assessment tools, awareness kits and sector-specific guides (e-commerce, tourism), designed for non-technical managers [5].
- INCIBE's cybersecurity decalogue: ten concrete recommendations for improving your level of protection without investing in new technology [6].
- 017 Cybersecurity Helpline: a free, confidential service staffed by a multidisciplinary team, available by phone (017), WhatsApp (900 116 117) and Telegram (@INCIBE017), every day of the year from 8:00 to 23:00, with technical, legal and incident-management advice for businesses and professionals [7] [8].
None of these resources require contracting anything. They are the reasonable starting point before considering any spend.
When it makes sense to bring in outside help
The measures above cover the most basic and avoidable risk. There is a point, however, at which continuous monitoring, response to an ongoing incident, or preparation for a certification (ISO 27001, ENS) exceeds what a small internal team can sustain without exclusive dedication. Typical signs that this point has arrived:
- A client or a public tender requires a specific certification or ENS level.
- You handle especially sensitive data (health, financial, minors) where the cost of an incident would be disproportionate.
- You are part of the supply chain of an entity that is clearly within NIS2's scope, and that entity is starting to demand contractual security requirements from you.
- You have already suffered an incident and need to understand what happened and close the door the attackers came through (forensic analysis, pentest).
In those cases, the reasonable alternative is not to build an in-house department from scratch, but to contract one-off or recurring services (offensive security audits, outsourced monitoring, regulatory compliance consultancy) sized to the actual risk, instead of taking on the fixed cost of an internal team that most SMEs cannot sustain.
Frequently asked questions
Is an SME obliged to comply with the NIS2 directive? It depends on sector and size; see the full answer in the FAQ section at the start of this document.
Do I need the ENS if I don't work with public administration? It is not directly mandatory, but it is if you are seeking public contracts or a public-sector client requires it.
Where do I start without a budget? MFA, tested backups, updates and basic phishing training: the four free or near-free measures with the greatest impact.
What do I do in the event of an incident with no internal team? Isolate without switching off, don't pay without advice, and call INCIBE's 017.
When do I bring in outside help? When the contractual obligation, the risk, or the need for certification exceeds what your internal team can sustain on an ongoing basis.
Statements about regulation reflect the legal text in force at the time of writing (September 2026); the draft Cybersecurity Coordination and Governance Act was going through parliamentary process at that time, and its status should be checked against later publications.
Sources
- Directiva (UE) 2022/2555 (NIS2) — texto consolidado
- European Commission — Referral of Spain to the Court of Justice for NIS2 non-transposition
- BOE — Real Decreto 311/2022, de 3 de mayo, Esquema Nacional de Seguridad
- Departamento de Seguridad Nacional — Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad
- INCIBE — Guías para empresas
- INCIBE — Decálogo de ciberseguridad para mejorar el nivel de protección de tu empresa
- INCIBE — Línea de Ayuda en Ciberseguridad 017
- La Moncloa — Nota de prensa sobre el teléfono 017
Does NIS2 apply to you?
Self-check your NIS2 scope (essential/important/out) and which directive domains you already cover, in 2 minutes.
Was this article useful?
Hodeitek
Equipo Hodeitek
Hodeitek's cybersecurity, regulatory compliance and AI consulting team.
Need help with this?
Schedule a free consultation with our team and see how to apply it to your organization.
Schedule free consultation