Moviwa

What does NIS2 require, and where does Spain stand?

8 min read · Reviewed in September 2026

In short

The NIS2 Directive requires essential and important entities across eighteen sectors to manage cybersecurity risk, control their supply chain and report incidents within 24 and 72 hours. Its most uncomfortable change is one of governance: accountability sits with the management body. In Spain, transposition is still incomplete.

What NIS2 is, and what changed

Directive (EU) 2022/2555 replaces the first network and information systems security directive. Its big change is scope: where the original NIS covered a handful of essential service operators, NIS2 reaches thousands of medium and large entities across eighteen sectors. For many organisations that never considered themselves critical infrastructure, NIS2 is their first codified cybersecurity obligation.

Unlike the GDPR, it does not protect personal data: it protects the resilience of services. In practice the two overlap, because a single incident can trigger reporting under both, with different deadlines and different recipients.

Who it applies to

Two criteria that have to hold at once:

Sector. Among others: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacture of medical devices, computers and vehicles, digital providers and research.

Size. As a general rule, from 50 employees or €10 million in turnover. Entities are classified as essential or important, with different supervisory regimes and different maximum penalties.

There is a third group that does not appear in the directive and is in practice the largest: suppliers. A company outside the direct scope ends up inside it contractually, because its in-scope customer has to control the security of its supply chain.

The obligations, in four blocks

1. Risk management measures

Risk analysis and security policy, incident handling, business continuity and backups, supply chain security, security in acquisition and development, policies to assess effectiveness, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication.

2. Incident reporting in three steps

DeadlineWhat is sent
24 hoursEarly warning: a significant incident has been detected
72 hoursNotification with an initial assessment of severity, impact and indicators of compromise
1 monthFinal report with cause, measures applied and scope

The 24-hour deadline is a legal obligation, not an informational courtesy, and missing it carries enforcement consequences.

3. Accountability of the management body

This is the article that changes the conversation. The management body has to approve the risk management measures, oversee their implementation and answer for failures. It also has to receive specific cybersecurity training, with an obligation to offer similar training to employees.

Put another way: cybersecurity stops being something that can be delegated to the IT department. And because accountability requires demonstrable diligence, you need minutes and evidence that the board reviewed, questioned and decided.

4. Supervision and penalties

Essential entities are subject to proactive supervision; important ones to reactive supervision after an incident or an indication. The penalties set out in the directive reach €10 million or 2% of worldwide turnover for essential entities, with a lower ceiling for important ones.

Where Spanish transposition stands

Precision matters here, because a lot of wrong information circulates.

Spain was due to transpose NIS2 by 17 October 2024 and did not. The European Commission opened infringement proceedings and issued a reasoned opinion in May 2025.

The main legislative vehicle is the Cybersecurity Coordination and Governance Act, whose draft bill the Council of Ministers approved on 14 January 2025. It creates the National Cybersecurity Centre as the national authority and splits sectoral supervision between the Interior, Defence and Digital Transformation ministries. As of September 2026 it is still in passage and has not been published in the BOE.

In the meantime, Royal Decree-Law 7/2025 partially transposed the directive. The practical consequence for a Spanish company is uncomfortable but clear: there is no complete national text to point at yet, the directive still sets the European floor, and the requirements arrive anyway through contracts from customers who are already demanding them.

Waiting for the law is the most expensive strategy. The Article 21 measures are not going to change substantially with transposition, and they are six to twelve months of work.

How does Moviwa help?

An AI tool a team adopts on its own is, in NIS2 terms, an unassessed supplier with access to the organisation's information. That is precisely the supply chain risk the directive requires you to control, and the one no supplier inventory captures, because nobody signed anything.

  • Discovery of unassessed AI tools. Moviwa shows which services are operating inside the organisation without having been through any supplier assessment. It is the largest blind spot in most supply chains today.

  • Alerts and traceability for the 24-hour deadline. Immediate notification of a relevant risk event, with the history needed to support an early warning with data rather than guesswork.

  • An exposure dashboard for the board. Risk level by area and how it moves, in the format a governance decision gets documented in. It is the due diligence evidence that management body accountability requires.

  • Control applied, not declared. Policies execute in the employee's browser, which is where the risk happens. A control that only lives in a document does not survive the first review.

See inside the platform

Checklist: six steps that do not depend on the Spanish law

  1. 1

    Work out whether it applies to you, by sector and size, and also by contract: check what your most demanding customer is already asking for.

  2. 2

    Inventory your suppliers, including the ones nobody formally contracted. SaaS and AI tools adopted by teams are the usual gap.

  3. 3

    Build the reporting procedure with owners, channels and templates, and rehearse it. Twenty-four hours is not long enough to improvise.

  4. 4

    Train the management body and keep the evidence.

  5. 5

    Keep minutes. Personal accountability is defended with a trail of decisions, not with good faith.

  6. 6

    Do not rely on the contract clause alone. NIS2 requires verification, not a declaration signed by the supplier.

Frequently asked questions

Is NIS2 already binding in Spain?
The directive is in force at European level and partially transposed through Royal Decree-Law 7/2025. The Cybersecurity Coordination and Governance Act, which completes transposition, is still in passage and has not been published in the BOE. In parallel, many obligations already arrive contractually from in-scope customers.
Does it apply to me as a supplier to an in-scope company?
Frequently yes, by contract. The in-scope entity has to control the security of its supply chain, and it does so by pushing requirements downstream.
How does NIS2 relate to the ENS?
They overlap and coexist. The ENS, Spain's National Security Framework, is mandatory for the Spanish public sector and its suppliers; NIS2 adds reporting, governance and sectoral supervision obligations.
What has shadow AI got to do with NIS2?
It is pure supply chain risk: a third party processing the organisation's information with no assessment, no contract and no access control.
Is board training genuinely mandatory?
Yes, and it is reviewable. It is one of the few obligations that gets checked by asking for a document.

Official sources

Your supply chain includes tools nobody contracted

The supplier inventory captures what went through procurement. NIS2 asks about everything that processes the organisation's information, and that is where the AI nobody approved shows up.

No commitment · 15 minutes · No card

Related frameworks

Moviwa implements the technical and organisational controls these frameworks require, and produces the evidence to demonstrate them. Moviwa is not certified against these standards and does not certify your organisation: compliance remains your company's responsibility.

This content is informational and does not constitute legal advice. For decisions about your organisation's compliance, consult your legal adviser.