NIS2 in the industrial sector: what the directive requires of factories and OT environments in Spain
What NIS2 requires of manufacturers and plants with OT environments in Spain: affected sectors, notification deadlines, Article 21 measures, and the state of transposition.

On this page
Directive (EU) 2022/2555, known as NIS2, substantially changes the cybersecurity obligations of thousands of industrial companies in Spain. Unlike its predecessor (NIS, from 2016), NIS2 broadens the number of sectors affected, introduces an almost automatic size criterion, and tightens both the minimum required measures and the sanctions regime [7]. For the industrial sector and for operational technology (OT) environments — production lines, SCADA systems, PLC controllers, plant networks — the impact is direct, even though the regulation was not drafted with factory-specific particularities in mind, but rather as a general risk-management framework applicable to "network and information systems."
This article explains what the directive says, where its transposition into Spanish law currently stands, what it means in practice for an industrial plant, and what reasonable steps a company can take while the Spanish law makes its way through the legislative process.
What NIS2 is and why it affects industry
NIS2 is the second generation of European legislation on the security of network and information systems. It replaces the 2016 NIS Directive and aims to raise the common level of cybersecurity across the EU by broadening the number of regulated sectors and harmonising risk-management and incident-notification obligations between Member States [7].
The directive distinguishes two categories of obliged entities:
- Essential entities: high-criticality sectors, listed in Annex I — energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and the space sector [5][7].
- Important entities: additional sectors, listed in Annex II — among them, postal and courier services, waste management, manufacturing and distribution of chemical products, production and distribution of food, the manufacturing of certain products (including medical devices, computer, electronic and optical products, electrical equipment, machinery, motor vehicles and other transport equipment), digital providers and research [5][7].
It is this second group — Annex II's manufacturing entry — that places a significant part of Spain's manufacturing industry, including a large share of the Basque and Navarrese automotive, machinery and components sector, within the scope of NIS2 as an "important entity." In addition, many industrial plants simultaneously belong to the supply chains of essential sectors (energy, water, health), which exposes them contractually even when their main activity is not on the list [3].
The size criterion: the real entry filter
NIS2's major methodological novelty compared with the previous regulation is that it replaces case-by-case designation with an almost automatic quantitative criterion: any entity in the Annex I and II sectors that qualifies as a medium-sized or large enterprise becomes subject to the directive [3][6].
Following the EU's SME definition, the thresholds are:
- Medium-sized enterprise: 50 or more employees, or annual turnover/balance sheet equal to or above €10 million.
- Large enterprise: 250 or more employees, or annual turnover above €50 million and a balance sheet above €43 million [6].
An industrial company below those thresholds falls, in principle, outside NIS2's direct scope, unless it fits one of the defined exceptions (qualified trust service providers, domain registries, public communications networks, public administrations), which apply regardless of size [6]. But size is no guarantee of real exclusion: if that SME is a critical supplier of an essential or important entity — for example, machining parts for a utility company or supplying components to a medical device manufacturer — it is likely to receive contractual security requirements, passed down from the supply-chain management obligation NIS2 imposes on its customer [3][12].
State of transposition in Spain
As of this article (September 2026), Spain has not published in the BOE the law transposing NIS2. The timeline, as it can be reconstructed from public sources, is as follows:
- The directive entered into force in January 2023, with a transposition deadline of 17 October 2024 and an application date of 18 October 2024 [7].
- Spain missed that deadline. According to press sources, the Government approved the draft Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad (preliminary bill on cybersecurity coordination and governance) in January 2025 [1].
- The European Commission opened an infringement procedure against Spain for failure to transpose the directive [1].
- According to press sources, the Commission has kept infringement procedures open against several Member States. The exact status of the Spanish procedure, including any possible referral to the Court of Justice, must be confirmed directly in the Commission's Infringement Decisions Register (ec.europa.eu/atwork/applying-eu-law) or at ec.europa.eu/commission/presscorner [1].
- As of this article, the preliminary bill is still going through parliamentary proceedings in the Cortes Generales (Spain's national parliament) and has not been published in the BOE [1]. The date of final approval and entry into force can be confirmed at boe.es and congreso.es.
Based on the information available about the preliminary bill, the Spanish law should require essential and important entities in critical sectors to implement risk-management measures, notify incidents within the directive's staggered deadlines, and assume responsibility at management-body level. The final text, its exact entry-into-force dates and the division of competences between ministries will only be settled once the law is published; until then, any detail of the preliminary bill may change during parliamentary proceedings. It is advisable to check the BOE once it is published.
The absence of a national law does not suspend the directive's validity at EU level, nor does it exempt from risk those companies that also operate in other Member States where NIS2 is already directly applicable. For a Spanish industrial company with subsidiaries, customers or suppliers in other EU countries, it is reasonable to anticipate compliance rather than wait for publication in the BOE.
What NIS2 requires in practice: the ten measures of Article 21
Article 21 of the directive requires essential and important entities to adopt technical, operational and organisational measures that are "appropriate and proportionate" to manage the cybersecurity risks of their network and information systems, following an "all-hazards approach" [7][12]. The directive lists ten minimum areas to be covered [12]:
- Policies on risk analysis and information system security.
- Incident handling.
- Business continuity, including backup management and disaster recovery, and crisis management.
- Supply-chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.
- Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of risk-management measures.
- Basic cyber hygiene practices and cybersecurity training.
- Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
- Human resources security, access control policies and asset management.
- The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate [12].
None of these ten measures is drafted specifically in "OT" or "IT" terms: the directive regulates "network and information systems" in general, and it is up to each entity to work out how to apply them to its actual combination of systems, which in an industrial plant includes both the corporate network and the process-control network [7]. That is where the main practical difficulty lies: measures proven first in IT (frequent patching, MFA on every access, segmentation, centralised identities) clash with the typical constraints of OT — equipment with 15-20 year lifecycles, systems that cannot host security agents, maintenance windows limited by production schedules, and industrial protocols (Modbus, Profinet, OPC) without native authentication.
The particularity of OT environments
NIS2 does not create a separate legal regime for operational technology: the same Article 21 criterion applies to all systems that support the entity's activity [7]. What changes is how it is implemented. Some common industry workstreams for bringing Article 21's ten measures to the plant floor:
- Inventory and classification of OT assets: without knowing which PLCs, HMIs, historians or IT-OT gateways exist and which firmware they run, neither risk analysis (measure 1) nor vulnerability management (measure 5) is possible.
- IT/OT network segmentation: separating the plant network from the corporate network and the internet, with industrial demilitarised zones (DMZs), is the most commonly cited technical baseline in the Centro Criptológico Nacional's (CCN, Spain's National Cryptologic Centre) reference guides on SCADA [8][9].
- Management of remote access to the plant: maintenance providers and integrators commonly access control systems; measures 9 and 10 require reviewing this access with the same rigour applied to corporate access.
- Operational continuity: measure 3 in an industrial environment implies plans that address the safe shutdown of production lines in the event of an incident, not just server restoration.
- Industrial supply-chain security: measure 4 requires assessing the risk posed by machinery integrators, OEM manufacturers and SCADA/MES software providers, which is sensitive given the volume of third-party remote access involved in industrial maintenance.
The Centro Criptológico Nacional (CCN) has for years published specific technical guides on industrial control systems and SCADA (the CCN-STIC-480 series), which cover architecture, segmentation and management good practices for these environments and are a reasonable technical starting point regardless of the state of legal transposition [8][9].
Incident notification: the deadlines that change day-to-day operations
One of NIS2's highest-impact operational changes is the regime for notifying significant incidents, set out in Article 23, which introduces three successive milestones [7][10]:
- Early warning, within a maximum of 24 hours of the entity becoming aware of the incident, indicating whether it is suspected of being caused by unlawful or malicious action and whether it is likely to have a cross-border effect [10].
- Incident notification, within a maximum of 72 hours, with an initial assessment of its severity and impact and, where available, indicators of compromise [10].
- Final report, within one month of the previous notification, with a detailed analysis of causes, impact and measures taken, with interim reports possibly required [10].
For an industrial plant, this means having already defined, before an incident occurs, who decides that something is "significant," who drafts the 24-hour warning and which authority it is sent to. Improvising that workflow during a ransomware-driven production stoppage is not feasible within those deadlines.
Relationship with the Esquema Nacional de Seguridad (ENS)
In Spain, the Esquema Nacional de Seguridad (ENS, Spain's National Security Framework), regulated by Royal Decree 311/2022, is the closest pre-existing regulatory reference to NIS2. The ENS is mandatory for public administrations and for those who provide services to them, and voluntary for the rest of the private sector, although increasingly required contractually [2][4]. The 2022 reform of the ENS explicitly sought to align its measures with those NIS2 would later consolidate, and it organises its controls into three categories (basic, medium, high) according to impact on confidentiality, integrity, availability, authenticity and traceability, with 73 measures spread across the organisational, operational and protection frameworks of Annex II [2][4].
For an industrial company that already provides services to a public administration or to an entity certified at ENS medium category — a common threshold in contracts with hospitals, town councils or public enterprises — much of that set of 73 measures overlaps in spirit with Article 21's ten NIS2 measures: risk management, continuity, access control, incident management. ENS certification is not automatically equivalent to NIS2 compliance — they are different standards, with different scopes of application and designation procedures — but it does narrow the gap and provides reusable documentary evidence.
Sanctions: what's at stake
NIS2's sanctions regime again distinguishes between essential and important entities [7][11]:
- Essential entities: fines of up to €10 million or 2% of worldwide annual turnover for the preceding financial year, whichever is higher.
- Important entities: fines of up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
These amounts are set by the European directive. The exact text the Spanish law will adopt, including any additional sanctions or the liability regime for management bodies, will depend on the final wording approved and must be verified against the BOE once the transposition law is published.
Practical steps while waiting for the Spanish law
With transposition still pending, an industrial company can make progress without waiting for the BOE:
- Determine whether it falls within NIS2's scope: check the activity code against Annex II (medical devices, computer/electronic products, machinery, vehicles, chemicals, food) and calculate whether it exceeds the size thresholds (50 employees or €10M turnover) [3][6].
- Inventory IT and OT assets: without an up-to-date map of systems — PLCs, HMIs, historians, IT-OT gateways, third-party remote access — a serious risk analysis cannot be carried out.
- Review network segmentation between plant floor and office: this is the technical measure with the highest immediate return in industrial environments, and the most frequently cited in the CCN-STIC guides on SCADA [8][9].
- Design the incident-notification workflow: define in advance who decides, who drafts and who is notified within the 24h/72h/1-month deadlines [10].
- Assess the OT supply chain: catalogue machinery integrators, SCADA/MES software providers and their level of remote access, and incorporate security clauses into contracts.
- Monitor the parliamentary process: the Spanish law may introduce deadlines or registers different from those currently only anticipated from the preliminary bill [1]; any plan should be reviewed once the final text is published.
Frequently asked questions
Is my factory bound by NIS2 even if it doesn't manufacture the products listed explicitly? It depends on the activity code and the company's size, not the specific product. It's worth checking Annex II, point 5 (manufacturing) of Directive 2022/2555 and cross-checking it against Spanish regulation once published. As of this publication, the exact status of the national entity register could not be confirmed against a live official source; it can be checked at boe.es and congreso.es.
Is an industrial SME with fewer than 50 employees outside NIS2's scope? Generally yes, if it does not exceed 50 employees or €10 million in turnover or balance sheet and does not fall under a defined exception [3][6]. However, it may still become subject via contract if it supplies an essential or important entity.
What's the difference between NIS2 and ENS for a private industrial company? The ENS is mandatory for the public sector and voluntary for the private sector, although increasingly required by contract [2][4]. NIS2 directly binds private essential and important entities by sector and size; certifying one does not automatically replace the other.
Do OT/SCADA systems have a different obligation from IT systems under NIS2? There is no separate legal regime: Article 21 requires managing the risk of network and information systems as a whole, including OT when it forms part of those systems [7]. The difficulty is one of implementation, not law; technical guides such as CCN-STIC-480 on SCADA exist to help [8][9].
What happens if my company misses the incident notification deadlines? It can result in fines of up to €10 million or 2% of worldwide turnover (essential entities) or up to €7 million or 1.4% (important entities), under Directive (EU) 2022/2555 (NIS2) [7][11]. The exact amounts Spain will apply in its transposition legislation depend on the final text of the law and must be verified against the BOE once published.
When does NIS2 take effect in Spain if the law still hasn't been published? The directive has been in force at EU level since October 2024 [7]; Spain missed the transposition deadline. According to press sources, the European Commission has kept an infringement procedure open against Spain; the exact status of the procedure (including any possible referral to the Court of Justice) must be confirmed directly in the Commission's Infringement Decisions Register (ec.europa.eu/atwork/applying-eu-law) or at ec.europa.eu/commission/presscorner [1]. The Spanish law still has not been published in the BOE [1]. Check the final publication date at boe.es before applying this information.
Sources
- NIS2 sigue sin publicarse en el BOE en julio de 2026 — https://ciberseguridad.creandopatria.com/noticia/nis2-sigue-sin-publicarse-en-el-boe-en-julio-de-2026-espana-encara-la-recta-final-antes-de-la-aplicacion-plena-prevista-para-octubre-2
- Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad (BOE-A-2022-7191) — https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191
- NIS2: entidades esenciales e importantes, sectores y umbrales — https://www.legiscope.com/blog/nis2-entidades-esenciales-importantes.html
- NIS2 en España y ENS: aplicación de la Directiva 2022/2555 — https://www.audidat.com/blog/esquema-nacional-de-seguridad/directiva-nis2-espana-aplicacion-relacion-ens/
- Centro Criptológico Nacional (CCN-CNI) — Directiva NIS2 — https://www.ccn.cni.es/es/normativa/directiva-nis2
- ¿Qué tamaño de empresa está obligada por NIS2? — https://www.audidat.com/blog/ciberseguridad/nis2/tamano-empresa-obligada-nis2-directiva-2022-2555/
- Directiva (UE) 2022/2555 (NIS2), texto consolidado — EUR-Lex — https://eur-lex.europa.eu/eli/dir/2022/2555/oj?locale=es
- CCN-CERT — Guía de seguridad sobre sistemas de control industrial (ICS) — https://www.ccn-cert.cni.es/es/soluciones-seguridad/elena.html?view=article&id=1229:guia-de-seguridad-sobre-sistemas-de-control-industrial-ics&catid=23
- CCN-STIC-480 — Seguridad en sistemas SCADA — https://www.ccn-cert.cni.es/es/guias-de-acceso-publico-ccn-stic/205-ccn-stic-480-seguridad-en-sistemas-scada/file.html
- Artículo 23 NIS2 — Obligaciones de notificación — https://rgpd.com/nis2-directive/chapter-4-cybersecurity-risk-management-measures-and-reporting-obligations/article-23-reporting-obligations/
- NIS2 España 2026: transposición, entidades esenciales, plazos y sanciones — https://www.legiscope.com/blog/nis2-espana-transposicion.html
- Artículo 21 NIS2 — Medidas de gestión del riesgo de ciberseguridad — https://nis2resources.eu/directive-2022-2555-nis2/article-21/
Note: the state of NIS2's transposition in Spain and the final sanction amounts depend on an ongoing legislative process as of this article's publication date and must be confirmed against the definitive text of the Spanish law once published in the BOE.
Sources
- [1] NIS2 sigue sin publicarse en el BOE en julio de 2026 — https://ciberseguridad.creandopatria.com/noticia/nis2-sigue-sin-publicarse-en-el-boe-en-julio-de-2026-espana-encara-la-recta-final-antes-de-la-aplicacion-plena-prevista-para-octubre-2
- [2] Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad (BOE-A-2022-7191) — https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191
- [3] Directiva NIS2: entidades esenciales e importantes, sectores y umbrales — https://www.legiscope.com/blog/nis2-entidades-esenciales-importantes.html
- [4] NIS2 en España y ENS: aplicación de la Directiva 2022/2555 — https://www.audidat.com/blog/esquema-nacional-de-seguridad/directiva-nis2-espana-aplicacion-relacion-ens/
- [5] Centro Criptológico Nacional (CCN-CNI) — Directiva NIS2 — https://www.ccn.cni.es/es/normativa/directiva-nis2
- [6] ¿Qué tamaño de empresa está obligada por NIS2? — https://www.audidat.com/blog/ciberseguridad/nis2/tamano-empresa-obligada-nis2-directiva-2022-2555/
- [7] Directiva (UE) 2022/2555 (NIS2), texto consolidado — EUR-Lex — https://eur-lex.europa.eu/eli/dir/2022/2555/oj?locale=es
- [8] CCN-CERT — Guía de seguridad sobre sistemas de control industrial (ICS) — https://www.ccn-cert.cni.es/es/soluciones-seguridad/elena.html?view=article&id=1229:guia-de-seguridad-sobre-sistemas-de-control-industrial-ics&catid=23
- [9] CCN-STIC-480 — Seguridad en sistemas SCADA — https://www.ccn-cert.cni.es/es/guias-de-acceso-publico-ccn-stic/205-ccn-stic-480-seguridad-en-sistemas-scada/file.html
- [10] Artículo 23 NIS2 — Obligaciones de notificación — https://rgpd.com/nis2-directive/chapter-4-cybersecurity-risk-management-measures-and-reporting-obligations/article-23-reporting-obligations/
- [11] NIS2 España 2026: transposición, entidades esenciales, plazos y sanciones — https://www.legiscope.com/blog/nis2-espana-transposicion.html
- [12] Artículo 21 NIS2 — Medidas de gestión del riesgo de ciberseguridad — https://nis2resources.eu/directive-2022-2555-nis2/article-21/
Does NIS2 apply to you?
Self-check your NIS2 scope (essential/important/out) and which directive domains you already cover, in 2 minutes.
Was this article useful?
Hodeitek
Equipo Hodeitek
Hodeitek's cybersecurity, regulatory compliance and AI consulting team.
Need help with this?
Schedule a free consultation with our team and see how to apply it to your organization.
Schedule free consultation