Regulation
NIS2 Directive: new cybersecurity duties for companies
Fines of up to €10 million or 2% of global turnover. The NIS2 Directive (Directive 2022/2555) imposes the most demanding cybersecurity obligations in the history of the EU, widening the scope from 7 to 18 sectors and covering every medium-sized and large company in them.
Spain is more than 16 months late with transposition. The draft Ley de Coordinación y Gobernanza de la Ciberseguridad, the Spanish cybersecurity governance bill, was approved by the Council of Ministers in January 2025, but it is still awaiting parliamentary passage. The European Commission has already sent Spain a reasoned opinion over the delay (May 2025). In the meantime, many obligations under the directive apply directly.
What is the NIS2 Directive and why does it matter to your company?
NIS2 replaces the earlier NIS Directive (2016) and raises the cybersecurity bar sharply for European companies and organisations. The main changes are:
- More sectors: from 7 to 18 sectors in scope
- More companies: every medium-sized and large company in those sectors, not only critical operators
- More obligations: specific technical and organisational measures, with strict notification deadlines
- Bigger penalties: fines on a par with the GDPR, with personal liability for senior management
The directive responds to a rising threat: cyberattacks on European companies have multiplied, and digital dependence means an incident at one company can hit its whole value chain.
Which companies does NIS2 affect? Sectors and thresholds
NIS2 sorts sectors into two categories and companies into two levels of obligation:
Highly critical sectors (Annex I)
- Energy (electricity, oil, gas, hydrogen, district heating)
- Transport (air, rail, maritime, road)
- Banking and financial market infrastructure
- Health
- Drinking water and waste water
- Digital infrastructure (DNS, IXP, cloud, data centres)
- ICT service management (B2B)
- Public administration
- Space
Other critical sectors (Annex II)
- Postal and courier services
- Waste management
- Manufacture and distribution of chemicals
- Production and distribution of food
- Manufacturing (medical devices, electronics, machinery, vehicles)
- Digital service providers (marketplaces, search engines, social networks)
- Research
Size thresholds
| Type | Employees | Annual turnover |
|---|---|---|
| Medium-sized company (minimum) | 50 or more | €10M or more |
| Large company | 250 or more | €50M or more |
Companies below these thresholds fall, in principle, outside the direct scope of NIS2. Member states can nevertheless designate smaller entities if they consider them critical to their sector.
Does your company belong to one of these 18 sectors? Our specialist consultancy team can assess your exposure to NIS2.
Main obligations: what NIS2 requires
Risk management measures
Entities in scope must put in place technical, operational and organisational measures proportionate to the risk. The directive sets out a minimum of ten areas:
- Information security policies and risk analysis
- Security incident management
- Business continuity and crisis management
- Supply chain security
- Security in the acquisition and development of systems
- Assessment of how effective the measures are
- Cyber hygiene practices and staff training
- Cryptography and encryption policies
- Human resources security and access control
- Multi-factor authentication and secure communications
Incident notification
When a significant incident occurs, the company must follow a staged process:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours from becoming aware | Initial notice to the relevant CSIRT |
| Formal notification | 72 hours | Assessment of severity, impact and likely cause |
| Final report | 1 month | Full analysis, mitigation measures taken |
An incident is "significant" when it causes serious operational disruption to the service or affects — or could affect — other individuals or organisations, causing considerable harm.
Liability of senior management
NIS2 introduces personal liability for management bodies. Directors of essential entities must approve the cybersecurity measures, oversee their implementation and receive specific training. Failure to do so can lead to a temporary ban on holding management positions.
Penalties for non-compliance: up to €10 million
The penalty regime distinguishes between the two types of entity:
| Type of entity | Maximum fine | Alternative |
|---|---|---|
| Essential | €10,000,000 | or 2% of annual global turnover (whichever is higher) |
| Important | €7,000,000 | or 1.4% of annual global turnover (whichever is higher) |
As well as the fines, the authorities can:
- Order publication of the breach
- Suspend certifications or authorisations
- Temporarily ban the exercise of management functions (essential entities only)
These penalties are on a par with the GDPR and represent a huge step up from the original NIS, which left the penalty regime almost entirely to each member state.
The state of NIS2 in Spain: transposition still pending
The transposition deadline expired on 17 October 2024. Spain missed it. Where things stand:
- January 2025: the Council of Ministers approved the draft Ley de Coordinación y Gobernanza de la Ciberseguridad
- May 2025: the European Commission sent Spain a reasoned opinion over the delay
- May 2026: the text is still waiting to be debated in the Cortes, the Spanish parliament
The Spanish act will create the Centro Nacional de Ciberseguridad, the national cybersecurity centre, and assign powers to the CCN (Centro Criptológico Nacional), INCIBE and the cybersecurity coordination office of the Ministry of the Interior.
Until transposition is complete, companies should assume that many obligations under the directive have direct effect, especially those on incident notification and minimum security measures. Prudence says prepare now rather than wait for the national law.
Do you want to get ahead of the requirements? Contact our team to design your NIS2 cybersecurity roadmap.
How to prepare: steps and funding available
Adaptation plan in 5 steps
- Work out whether your company is in scope: check the sector (18 sectors) and the size (≥50 employees or >€10M)
- Classify your entity: essential or important, by sector and size
- Run a risk analysis: assess your current cybersecurity against the 10 areas in the directive
- Implement the technical and organisational measures: security policies, incident management, business continuity, supply chain security
- Set up the notification protocol: prepare the procedures to meet the 24h/72h/1 month deadlines
Funding to pay for the transition
Investment in cybersecurity can be supported by Spanish funding programmes that are currently open:
- Kit Consulting: includes a basic cybersecurity package (€6,000) with risk assessment, security policies and a training plan
- Kit Digital: the cybersecurity for companies category covers protection and detection tools
- Tax deductions: investment in security software and systems can qualify for deductions for technological innovation
At Tecnocim Innova we can help you assess your exposure to NIS2, design an adaptation plan and connect it with the public grants available in Spain to fund the investment.
Contact us for an initial review with no obligation.
Related service
Free assessment for companies with revenue above €500,000
Get grant and tax deduction updates by email
Calls, deadlines and regulatory changes, once a month.
Related articles
Regulation
Regulation

