European Directive

NIS2 · Cybersecurity Directive

The regulation that expands the scope of cybersecurity in the EU and strengthens the accountability and oversight of management bodies over cybersecurity risk management.

Directive entry into force: January 2023 Transposition deadline (missed by Spain): October 17, 2024 Fines: up to €10M or 2% of global turnover (essential entities)

What is NIS2?

The NIS2 Directive (Network and Information Security 2) is the second version of the first EU-wide cybersecurity regulation. It replaces the old 2016 NIS Directive and dramatically expands its scope.

The goal is to create a common level of cybersecurity across the EU, protect critical sectors and ensure operational resilience against cyberattacks.

Key change: NIS2 requires management bodies to approve and oversee risk management measures. The exact penalty regime and scope of management liability will depend on the Spanish transposition, still in progress.

Who does it apply to?

NIS2 expands the perimeter of obligated companies. It now includes:

  • Essential sectors: Energy, transport, banking, financial market infrastructure, healthcare, drinking water, public administration, space, telecommunications.
  • Important sectors: Postal services, waste management, manufacturing of critical products, food production, information technology, digital services.
  • Digital service providers (Annex II): Search engines, cloud services, e-commerce platforms, social networks — classified as important entities, not as a separate third category.

Size criterion: Applies to medium and large companies (more than 50 employees or €10M in annual turnover) in the mentioned sectors, according to the medium-sized enterprise criterion of Commission Recommendation 2003/361/EC.

Key deadlines

  • January 2023: Entry into force of Directive (EU) 2022/2555 at the European level.
  • October 17, 2024: EU deadline for each Member State to transpose it into national law. Spain did not meet it.
  • January 2025: The Council of Ministers approved the Draft Law on Cybersecurity Coordination and Governance, which will transpose NIS2 in Spain. Still in parliamentary process.
  • May 2025: The European Commission sent Spain a reasoned opinion for the delay, as part of an infringement procedure.
Important: although the Spanish transposition continues its process, organizations potentially within its scope can prepare ahead of time using the requirements set out in the NIS2 Directive as a reference.

Consequences of non-compliance

  • Essential entities: Fines of up to €10 million or 2% of global annual turnover.
  • Important entities: Fines of up to €7 million or 1.4% of global annual turnover.
  • Management body accountability: Approval and oversight of risk management measures, with a specific penalty regime subject to national transposition.
  • Reputational damage: penalties are subject to limited publicity under each Member State's regime; NIS2 does not generally declare them public.

What does NIS2 require?

Companies must implement a set of organizational and technical measures, including:

  • Governance: Boards of Directors must oversee and approve cybersecurity measures.
  • Risk analysis: Periodic risk assessments across the supply chain.
  • Incident response plan: Clear protocols for detecting, containing and reporting incidents: early warning within 24h, notification within 72h and a final report within 1 month.
  • Resilience testing: Crisis management, continuity and periodic assessment of measure effectiveness. Tabletop exercises are a recommended practice to demonstrate that effectiveness, not an obligation explicitly named by the regulation.
  • Continuous training: Awareness and training programs for all staff.
  • Supply chain security: Risk assessment of IT and OT providers.

How can I help you with NIS2?

NIS2 GAP Audit

We analyze your current situation, identify gaps and deliver a prioritized action plan with deadlines and owners.

View service →

Management System Implementation

We design and implement all measures required by NIS2, including policies, procedures and response plans.

View service →

Tabletop Exercises

We design and lead simulations with your Management Committee to prepare the response to critical incidents.

View service →

Do you need to prepare your company for NIS2?

Request an assessment meeting →

20–30 minutes · No commitment · We review context, need and next steps.