What NIS2 is, and what changed
Directive (EU) 2022/2555 replaces the first network and information systems security directive. Its big change is scope: where the original NIS covered a handful of essential service operators, NIS2 reaches thousands of medium and large entities across eighteen sectors. For many organisations that never considered themselves critical infrastructure, NIS2 is their first codified cybersecurity obligation.
Unlike the GDPR, it does not protect personal data: it protects the resilience of services. In practice the two overlap, because a single incident can trigger reporting under both, with different deadlines and different recipients.
Who it applies to
Two criteria that have to hold at once:
Sector. Among others: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacture of medical devices, computers and vehicles, digital providers and research.
Size. As a general rule, from 50 employees or €10 million in turnover. Entities are classified as essential or important, with different supervisory regimes and different maximum penalties.
There is a third group that does not appear in the directive and is in practice the largest: suppliers. A company outside the direct scope ends up inside it contractually, because its in-scope customer has to control the security of its supply chain.
The obligations, in four blocks
1. Risk management measures
Risk analysis and security policy, incident handling, business continuity and backups, supply chain security, security in acquisition and development, policies to assess effectiveness, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication.
2. Incident reporting in three steps
| Deadline | What is sent |
|---|---|
| 24 hours | Early warning: a significant incident has been detected |
| 72 hours | Notification with an initial assessment of severity, impact and indicators of compromise |
| 1 month | Final report with cause, measures applied and scope |
The 24-hour deadline is a legal obligation, not an informational courtesy, and missing it carries enforcement consequences.
3. Accountability of the management body
This is the article that changes the conversation. The management body has to approve the risk management measures, oversee their implementation and answer for failures. It also has to receive specific cybersecurity training, with an obligation to offer similar training to employees.
Put another way: cybersecurity stops being something that can be delegated to the IT department. And because accountability requires demonstrable diligence, you need minutes and evidence that the board reviewed, questioned and decided.
4. Supervision and penalties
Essential entities are subject to proactive supervision; important ones to reactive supervision after an incident or an indication. The penalties set out in the directive reach €10 million or 2% of worldwide turnover for essential entities, with a lower ceiling for important ones.
Where Spanish transposition stands
Precision matters here, because a lot of wrong information circulates.
Spain was due to transpose NIS2 by 17 October 2024 and did not. The European Commission opened infringement proceedings and issued a reasoned opinion in May 2025.
The main legislative vehicle is the Cybersecurity Coordination and Governance Act, whose draft bill the Council of Ministers approved on 14 January 2025. It creates the National Cybersecurity Centre as the national authority and splits sectoral supervision between the Interior, Defence and Digital Transformation ministries. As of September 2026 it is still in passage and has not been published in the BOE.
In the meantime, Royal Decree-Law 7/2025 partially transposed the directive. The practical consequence for a Spanish company is uncomfortable but clear: there is no complete national text to point at yet, the directive still sets the European floor, and the requirements arrive anyway through contracts from customers who are already demanding them.
Waiting for the law is the most expensive strategy. The Article 21 measures are not going to change substantially with transposition, and they are six to twelve months of work.