NIS2 Directive: new cybersecurity duties for companies
Regulation

NIS2 Directive: new cybersecurity duties for companies

BY TECNOCIM INNOVA   PUBLISHED ON 3 MAY 2026

Fines of up to €10 million or 2% of global turnover. The NIS2 Directive (Directive 2022/2555) imposes the most demanding cybersecurity obligations in the history of the EU, widening the scope from 7 to 18 sectors and covering every medium-sized and large company in them.

Spain is more than 16 months late with transposition. The draft Ley de Coordinación y Gobernanza de la Ciberseguridad, the Spanish cybersecurity governance bill, was approved by the Council of Ministers in January 2025, but it is still awaiting parliamentary passage. The European Commission has already sent Spain a reasoned opinion over the delay (May 2025). In the meantime, many obligations under the directive apply directly.

What is the NIS2 Directive and why does it matter to your company?

NIS2 replaces the earlier NIS Directive (2016) and raises the cybersecurity bar sharply for European companies and organisations. The main changes are:

The directive responds to a rising threat: cyberattacks on European companies have multiplied, and digital dependence means an incident at one company can hit its whole value chain.

Which companies does NIS2 affect? Sectors and thresholds

NIS2 sorts sectors into two categories and companies into two levels of obligation:

Highly critical sectors (Annex I)

Other critical sectors (Annex II)

Size thresholds

TypeEmployeesAnnual turnover
Medium-sized company (minimum)50 or more€10M or more
Large company250 or more€50M or more

Companies below these thresholds fall, in principle, outside the direct scope of NIS2. Member states can nevertheless designate smaller entities if they consider them critical to their sector.

Does your company belong to one of these 18 sectors? Our specialist consultancy team can assess your exposure to NIS2.

Main obligations: what NIS2 requires

Risk management measures

Entities in scope must put in place technical, operational and organisational measures proportionate to the risk. The directive sets out a minimum of ten areas:

Incident notification

When a significant incident occurs, the company must follow a staged process:

StageDeadlineContent
Early warning24 hours from becoming awareInitial notice to the relevant CSIRT
Formal notification72 hoursAssessment of severity, impact and likely cause
Final report1 monthFull analysis, mitigation measures taken

An incident is "significant" when it causes serious operational disruption to the service or affects — or could affect — other individuals or organisations, causing considerable harm.

Liability of senior management

NIS2 introduces personal liability for management bodies. Directors of essential entities must approve the cybersecurity measures, oversee their implementation and receive specific training. Failure to do so can lead to a temporary ban on holding management positions.

Penalties for non-compliance: up to €10 million

The penalty regime distinguishes between the two types of entity:

Type of entityMaximum fineAlternative
Essential€10,000,000or 2% of annual global turnover (whichever is higher)
Important€7,000,000or 1.4% of annual global turnover (whichever is higher)

As well as the fines, the authorities can:

These penalties are on a par with the GDPR and represent a huge step up from the original NIS, which left the penalty regime almost entirely to each member state.

The state of NIS2 in Spain: transposition still pending

The transposition deadline expired on 17 October 2024. Spain missed it. Where things stand:

The Spanish act will create the Centro Nacional de Ciberseguridad, the national cybersecurity centre, and assign powers to the CCN (Centro Criptológico Nacional), INCIBE and the cybersecurity coordination office of the Ministry of the Interior.

Until transposition is complete, companies should assume that many obligations under the directive have direct effect, especially those on incident notification and minimum security measures. Prudence says prepare now rather than wait for the national law.

Do you want to get ahead of the requirements? Contact our team to design your NIS2 cybersecurity roadmap.

How to prepare: steps and funding available

Adaptation plan in 5 steps

  1. Work out whether your company is in scope: check the sector (18 sectors) and the size (≥50 employees or >€10M)
  2. Classify your entity: essential or important, by sector and size
  3. Run a risk analysis: assess your current cybersecurity against the 10 areas in the directive
  4. Implement the technical and organisational measures: security policies, incident management, business continuity, supply chain security
  5. Set up the notification protocol: prepare the procedures to meet the 24h/72h/1 month deadlines

Funding to pay for the transition

Investment in cybersecurity can be supported by Spanish funding programmes that are currently open:

At Tecnocim Innova we can help you assess your exposure to NIS2, design an adaptation plan and connect it with the public grants available in Spain to fund the investment.

Contact us for an initial review with no obligation.

Related service

Request a free assessment

Free assessment for companies with revenue above €500,000

Get grant and tax deduction updates by email

Calls, deadlines and regulatory changes, once a month.

Get our latest updates

We respect your privacy. No spam.

NIS2NIS2 directivecybersecurity for companiesEuropean cybersecurity directive
PreviousMandatory e-invoicing in Spain: deadlines and requirements
NextTorres Quevedo: hire researchers with a CDTI grant

Related articles

Financiado por la Unión Europea - Gobierno de España, Ministerio de Industria y Turismo - Plan de Recuperación, Transformación y Resiliencia - EOI Escuela de Organización Industrial
Programa Activa Industria 4.0Industria Conectada 4.0