Complete NIS2 Compliance Guide for Spanish Companies
NIS2 has still not been transposed in Spain and remains subject to a European Commission infringement procedure. What companies should do in the meantime and how to prepare.

On this page
What NIS2 is and why it matters
Directive (EU) 2022/2555, known as NIS2, replaces the 2016 NIS Directive and substantially widens the scope of obligated entities within the European Union: from a small number of critical-infrastructure operators to a universe spanning energy, transport, banking, health, water, digital infrastructure, waste management, medical device manufacturing, food and digital services, among other sectors [1].
Unlike its predecessor, NIS2 introduces explicit obligations for senior management: governing bodies must formally approve risk-management measures, receive specific training, and may be subject to personal supervisory measures in the event of serious non-compliance (Article 20) [1]. This change turns compliance into a matter of corporate governance, not merely a technical concern for the security department.
The deadline the Directive itself set for Member States to transpose its provisions into national law was 17 October 2024 [1]. That date is key to understanding the rest of this guide, because Spain missed it and, to this day, still has no Spanish national NIS2 law in force.
The real state of transposition in Spain (this is what usually gets confused)
It is common to find articles that assume "NIS2 was already transposed in Spain in 2025." This is not correct and deserves precise correction, because it directly affects which requirements are legally binding today and which are not yet.
What has actually happened, according to official sources:
- According to press sources, the Council of Ministers approved the preliminary draft (anteproyecto) of the Cybersecurity Coordination and Governance Act on 14 January 2025 [5]. A preliminary draft is not a law: it is the starting point of the parliamentary process.
- In 2024 the European Commission opened an infringement procedure against Spain for failing to notify complete transposition within the deadline, alongside other Member States that also failed to transpose on time.
- The exact status of the procedure (including any eventual referral to the CJEU) can be checked directly in the Commission's Infringement Decisions Register (ec.europa.eu/atwork/applying-eu-law) or at ec.europa.eu/commission/presscorner.
- As of this guide, the draft bill continues its progress through the Cortes Generales (Spain's parliament) and has not been published in the BOE (Spain's Official State Gazette) as law.
What does this mean in practice for a Spanish company?
- There is today no Spanish law called "Ley NIS2" that directly imposes the penalties, notification deadlines or entity registration described in this guide. Those figures and deadlines are the ones set by the Directive and are what the Spanish law will foreseeably reproduce once approved, but their direct enforceability against companies depends on the national rule.
- The legal framework in force today remains Real Decreto-ley 12/2018, transposing the original NIS Directive, under which the Centro Criptológico Nacional (CCN, National Cryptologic Centre) and INCIBE continue to exercise supervisory functions over operators of essential services and digital service providers, together with sectoral authorities.
- Waiting for the law to be approved before starting to prepare is the worst possible strategy, for two reasons: the preliminary draft closely mirrors the Directive's provisions (the ten requirements of Article 21, the notification deadlines of Article 23, the liability under Article 20), so preparatory work does not expire; and companies operating in other Member States that have already transposed the rule — or that form part of supply chains for clients subject to NIS2 in other countries — may already be contractually obligated even though there is still no law in Spain.
The institutional design brought by the preliminary draft is also relevant: it creates a Centro Nacional de Ciberseguridad (National Cybersecurity Centre), attached to the Office of the Prime Minister, as the single national point of contact and coordination authority for cybersecurity crises, and distributes sectoral supervision among three oversight authorities linked to the Ministries of the Interior, Defence (through the CCN) and Digital Transformation [4] [5].
Who will be obligated
NIS2 distinguishes between essential entities and important entities. Classification combines three criteria: the sector of activity (Annex I of the Directive for potentially essential entities, Annex II for potentially important ones), the size of the organisation (medium-sized or large enterprise, per the staff-headcount and turnover thresholds of Recommendation 2003/361/EC) and, in some cases, the criticality of the service provided regardless of size [1].
As a general guide:
- High-criticality sectors (Annex I) — energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, ICT service management (B2B), public administration and the space sector — tend to be classified as essential when the company is medium-sized or large.
- Other critical sectors (Annex II) — postal and courier services, waste management, manufacture and distribution of chemicals, production and distribution of food, manufacture of medical devices, electronics, machinery, vehicles, online marketplace providers, search engines and social networks, and research — tend to be classified as important.
- The competent authority may equally designate a small company or micro-enterprise as essential when its service is critical to the operation of a regulated sector (for example, a sole supplier of a critical component).
A point many organisations underestimate: NIS2 does not only bind the directly designated company — it also obliges that company to demand equivalent guarantees from its critical suppliers through the supply-chain security requirement of Article 21. This means companies that do not fall within the direct scope of the rule can still be drawn into meeting NIS2 requirements contractually, as a condition for remaining a supplier to an essential or important entity.
The five pillars of obligations
1. Cybersecurity risk management (Article 21)
Article 21 requires ten minimum categories of technical, operational and organisational measures: policies on risk analysis and information system security, incident handling, business continuity and crisis management, supply-chain security (including aspects relating to the security of the relationships between each entity and its direct suppliers or service providers), security in the acquisition, development and maintenance of systems, policies to assess the effectiveness of risk-management measures, basic cyber hygiene and training, cryptography and encryption, human resources security, access-control and asset-management policies, and the use of multi-factor or continuous authentication solutions [1].
For entities also subject to Commission Implementing Regulation (EU) 2024/2690 — DNS providers, top-level-domain name registries, cloud computing service providers, data-centre providers, content-delivery network providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers — there are additional technical and methodological requirements, detailed in its thirteen-section Annex [7]. ENISA published in June 2025 a non-binding technical implementation guide that translates that regulation into practical controls, with examples of auditable evidence [6].
The supply chain tends to be the costliest point to resolve in practice: it requires inventorying critical suppliers, assessing their security posture (questionnaires, audits, contractually required certifications) and keeping that assessment up to date, rather than treating it as a one-off exercise.
2. Incident notification (Article 23)
The deadlines set by the Directive are strict and staggered [1]:
- 24 hours from becoming aware of a significant incident: an early warning to the CSIRT or competent authority, indicating whether unlawful or cross-border origin is suspected.
- 72 hours: formal notification with an initial assessment of the incident, its severity and impact, and any available indicators of compromise.
- 1 month: a final report with a detailed description, probable root cause, mitigation measures applied and, where relevant, cross-border impact.
Meeting these deadlines requires a detection-and-escalation process already designed before the incident occurs: trying to build it during the crisis is the most frequent cause of missing the 24-hour deadline.
3. Governance and management accountability (Article 20)
The governing bodies of essential and important entities must approve the cybersecurity risk-management measures adopted by the organisation, oversee their implementation, and receive periodic training enabling them to identify risks and assess cybersecurity risk-management practices and their impact on the entity's services [1]. The Directive allows Member States to establish that members of the governing body may be held liable for the entity's failure to comply with its obligations.
This has an immediate practical consequence for any CISO or compliance officer: board training must be documented (date, content, attendees, assessment) because it will be the evidence requested during an inspection or a claim.
4. Registration and supervision
Essential entities will be subject to an ex-ante supervision regime, with proactive inspections and audits by the competent authority, while important entities will be subject to an ex-post supervision regime, triggered after an incident, a complaint or an indication of non-compliance [1]. The specific procedure for registering entities in Spain — deadlines, forms, receiving authority — will be set by Spanish law once approved; until then, the Directive's text remains the reference criterion.
5. Penalty regime
Article 34 of the Directive sets the maximum amounts that Member States must be able to impose [1]:
- Essential entities: up to €10,000,000 or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher.
- Important entities: up to €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher.
These are the figures the Directive requires to be transposed into national law; it will be Spanish law, once approved, that formally incorporates them into the Spanish legal system with the corresponding procedural detail.
Relationship with the Esquema Nacional de Seguridad (ENS)
Many Spanish companies — especially those providing services to public administration — already live alongside the Esquema Nacional de Seguridad (ENS, National Security Framework), governed by Real Decreto 311/2022, of 3 May (BOE-A-2022-7191) [3]. The ENS classifies systems into three categories — basic, medium and high — based on the impact an incident would have on confidentiality, integrity, traceability, authenticity, availability and other security dimensions, and requires a catalogue of measures proportional to that category.
The ENS and NIS2 overlap significantly — risk management, access control, business continuity, training — but they are not interchangeable. The ENS is designed for public-sector systems and their suppliers; NIS2 directly obligates private companies in critical sectors, with requirements the ENS does not cover to the same level of detail, such as hourly incident-notification deadlines or the explicit personal liability of senior management. A company that already complies with the ENS at medium or high category arrives at the NIS2 exercise with an advantage, but cannot assume it is "already covered."
Roadmap: what to do in the next 90-180 days
Given that Spanish law is not yet in force but its approval could occur at any point in the parliamentary process, the recommended approach is not to "wait," but to move forward in parallel:
- Determine your exposure: analyse whether your activity fits within Annexes I or II of the Directive and whether your size (per the SME thresholds) places you as a potential essential or important entity. Document the analysis, even though formal registration in Spain does not yet exist.
- Run a gap analysis against the ten measures of Article 21, not against a generic standard. If you already hold ISO 27001 or ENS certification, use the existing mapping as a starting point, not a complete answer.
- Design — and rehearse — the incident-notification process with the 24h/72h/1-month deadlines as reference, including who decides that an incident is "significant" and how the timeline is documented.
- Bring a formal approval session for risk-management measures to the board or management committee, with minutes and a training record. This responds directly to Article 20 and is the evidence most likely to be requested first during an inspection.
- Start assessing critical suppliers under the supply-chain security criterion: there is no need to wait for the Spanish regulation to start requesting security evidence from suppliers whose failure would leave you exposed.
- Follow the parliamentary progress of the Cybersecurity Coordination and Governance Bill [4] [5]: the adaptation deadlines set by the transitional provision of the final law will determine the real deadline for registration and full application of the measures. As of this guide, the final entry-into-force date and transitional regime remain pending publication in the BOE.
Common mistakes
- Assuming a law has been transposed when it does not yet exist. This is the most widespread error in content published about NIS2 in Spain throughout 2025 and 2026, and it leads to underestimating the real regulatory uncertainty and setting incorrect internal deadlines.
- Treating NIS2 as a simple extension of ISO 27001. They overlap in a large part of the technical controls, but NIS2 requires elements ISO 27001 does not cover to the same level of detail: depth of supply-chain assessment, notification deadlines measured in hours, and explicit approval evidence from the governing body.
- Ignoring suppliers that look "non-critical" at first glance. A SaaS payroll provider or a video-surveillance integrator can be the most likely entry point into an essential entity's network, precisely because it does not receive the same scrutiny as the "obvious" suppliers.
- Failing to document board training. Article 20 requires specific training for directors; without minutes, an attendance record and content, there is no evidence to show during an inspection.
- Waiting for Spanish law before starting. The preliminary draft closely mirrors the Directive's provisions; preparatory work done today is not lost once the rule enters into force.
Frequently asked questions
Is NIS2 already in force as law in Spain? No. As of this guide, Spain has not completed transposition. According to press sources, the preliminary draft was approved by the Council of Ministers on 14 January 2025; it is still going through the parliamentary process. As of this writing, the European Commission maintains an open infringement procedure against Spain for failing to notify complete transposition. The exact status of the procedure (including any eventual referral to the CJEU) can be checked directly in the Commission's Infringement Decisions Register (ec.europa.eu/atwork/applying-eu-law) or at ec.europa.eu/commission/presscorner [5].
If there is no Spanish law, do I need to do anything now? Yes. Real Decreto-ley 12/2018 remains in force, companies with operations in other Member States may already be obligated there, and the Spanish preliminary draft directly reuses preparatory work done against the Directive.
What is the difference between NIS2 and the ENS? The ENS (RD 311/2022) governs public-sector systems and their suppliers under three security categories; NIS2 directly obligates private companies in critical sectors with additional requirements such as incident notification within hourly deadlines and personal liability of management [3] [1].
How do I know if my company is an essential or important entity? It depends on the sector (Annexes I and II of the Directive) and on size per the EU's SME thresholds; the authority may also designate small companies with a critical role as essential [1].
What happens if I fail to notify an incident on time? The Directive sets penalties of up to €10M or 2% of global turnover for essential entities, and up to €7M or 1.4% for important entities; Spanish law will transpose these figures once it enters into force [1].
Does ISO 27001 satisfy NIS2 compliance? It helps, but does not replace it: it covers a good part of the ten measures in Article 21, but not the notification deadlines, the depth required in the supply chain, or the evidence of approval by the governing body.
Conclusion
NIS2 is not optional, and despite Spain's legislative delay, it would not be prudent to treat it as something that can be postponed. The fact that Spain has not yet transposed the Directive — and is therefore subject to a European Commission infringement procedure (whose exact status should be confirmed in the Commission's Infringement Decisions Register or at ec.europa.eu/commission/presscorner) — does not remove the risk: it shifts it into a zone of uncertainty in which companies that have already prepared against the text of the Directive will reach the entry into force of Spanish law with a defensible position, while those waiting for "the law to exist" before starting will face foreseeably short adaptation deadlines and a gap-analysis effort that should have begun months or years earlier.
This guide will be revised when the final text of the Cybersecurity Coordination and Governance Act is published in the BOE. Penalty figures, notification deadlines and entity classification criteria correspond to the text of Directive (EU) 2022/2555 and may vary in the final Spanish regulatory development.
Sources
- https://eur-lex.europa.eu/eli/dir/2022/2555/2022-12-27/eng
- https://ec.europa.eu/commission/presscorner/
- https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191
- https://www.dsn.gob.es/en/node/24160
- https://www.interior.gob.es/opencms/es/detalle/articulo/El-Consejo-de-Ministros-aprueba-el-anteproyecto-de-Ley-de-Coordinacion-y-Gobernanza-de-la-Ciberseguridad
- https://www.enisa.europa.eu/sites/default/files/2025-06/ENISA_Technical_implementation_guidance_on_cybersecurity_risk_management_measures_version_1.0.pdf
- https://eur-lex.europa.eu/legal-content/EN/PIN/?uri=CELEX:32024R2690
Does NIS2 apply to you?
Self-check your NIS2 scope (essential/important/out) and which directive domains you already cover, in 2 minutes.
Was this article useful?
Gorka Gonzalo
Founder & CEO
Founded Hodeitek in 2023 and runs the company. A cybersecurity and AI expert, he sets the technical and product direction of HodeiShield and personally leads the most critical engagements.
Need help with this?
Schedule a free consultation with our team and see how to apply it to your organization.
Schedule free consultation