NIS2 Compliance Cybersecurity

NIS2 in Spain 2026: what already binds you and how to check it in 5 minutes

Quick summary

TL;DR (in case you are reading this with a coffee in hand)

The short version before we get into it:

  • Spain is more than 640 days overdue in transposing NIS2. The deadline expired on 17 October 2024.
  • On 8 July 2026 the European Commission referred Spain to the Court of Justice of the EU, alongside Ireland, France and the Netherlands, and asked for financial penalties.
  • The important part: what is still being decided are the competent authorities and the procedures. The technical measures in Article 21 come from the Directive and will not change in substance.
  • The date of application was set by the Directive: 18 October 2024. The draft law includes transitional provisions for some formalities, but do not count on a broad moratorium for the technical measures.
  • And one that still surprises boards: Article 20 puts the responsibility on management, not on the IT department.

If you want to know where you stand, at the end there is a free 16-control checklist. 👇

Spain is behind on transposing NIS2 by

Days
Hours
Minutes
Seconds

Counting from 17 October 2024, the deadline set in Article 41 of Directive (EU) 2022/2555. The counter runs in your browser, and it does not stop while you read.

As of July 2026, Spain still has not transposed NIS2, and I hear this reasoning almost every week: "once the Spanish law is out, we will get to it". It sounds prudent. Nobody wants to invest in adapting to a text that may still change.

The problem is that it rests on a false premise. NIS2 compliance does not begin when the BOE publishes: the obligations have been written since 2022 in the European text. And something happened this month that makes that fairly clear.

1. What happened this month

On 8 July 2026, the European Commission decided to refer Spain, Ireland, France and the Netherlands to the Court of Justice of the European Union for failing to notify their NIS2 transposition measures. And it did not stop there: it has asked the Court to impose financial penalties.

The path here is the usual one in an infringement procedure, and it is worth seeing in order, because it explains why this is no longer an administrative footnote:

WhenWhat happened
17 October 2024Deadline in Article 41 of the Directive for Member States to adopt and publish their national measures.
14 January 2025The Council of Ministers approves the draft Law on Coordination and Governance of Cybersecurity. It remains unpublished in the BOE.
7 May 2025The Commission issues a reasoned opinion against 19 Member States, Spain among them.
8 July 2026Referral to the CJEU with a request for financial penalties, more than twenty months after the deadline expired.

For your company this reads two ways. The bad one: the national framework is still open, so there are details you cannot know for certain yet. The useful one: the pressure to adopt the law is now at its highest. Anyone waiting to have the BOE in front of them before starting is going to have very little room.

2. What is not going to change

Here is the point that really matters, and the reason waiting does not save you any work. In two lines:

  • The Spanish law will settle the who and the how: authorities, registration, sanctioning procedure.
  • The what — the technical measures and the deadlines — is already fixed in the Directive and cannot be watered down.

NIS2 is a directive: it sets the result to be achieved and leaves each Member State to fit it into its own legal order. What the Spanish law will pin down is essentially:

  • Which authority supervises each sector and who receives the notifications.
  • How and when you register, and what details you must provide.
  • The internal sanctioning regime and the split of powers with the autonomous communities.
  • Possible extensions of scope to entities the Directive does not require to be included.

What will not change is the technical content. The ten families of measures in Article 21, the notification deadlines in Article 23 and the governance duties in Article 20 are in the European text. A Member State may go further, but not lower.

And in case there was any doubt about the level of detail, Implementing Regulation (EU) 2024/2690 already exists, is directly applicable, and breaks down the technical requirements of Article 21 and the criteria for when an incident is significant. It is aimed at digital service and digital infrastructure providers, but as a reference for "what has to be implemented" it is the most concrete thing on the table today.

Keynote

Article 41 of the Directive set 18 October 2024 as the date from which these measures were to apply. Spain's delay has not created a new deadline, and whatever you have not done before, you will be doing with the authority already watching.

So will there be time to adapt?

It is worth being honest about this, because it gets asserted confidently in both directions. The draft law does include three transitional provisions, with their own deadlines for things such as appointing security officers, setting up the National Cybersecurity Centre or drawing up the National Strategy. That is normal: those are pieces that do not exist yet and have to be built.

What nobody can say today is whether there will be a general moratorium for entities to implement the Article 21 measures, or how long it would be. The text is still in passage and may change. What is a fact is that Article 41 of the Directive set 18 October 2024 as the date from which those measures were to apply, and that a Member State's delay does not create rights for those who had to comply. Counting on a generous extension is a bet, not a forecast.

3. Are you in scope? Three questions

Scope is decided by combining sector and size, with a handful of exceptions that skip size entirely. Here is the whole path at a glance:

Is my company in scope of NIS2?
  1. Do you operate in a sector listed in Annex I or II of the Directive?

    NoOutside the general rule. Skip to step 3: the exceptions do not look at sector in the same way.
    YesContinue to step 2.
  2. Using the aggregated data and relevant periods, are you a small enterprise: fewer than 50 AWU and turnover up to €10M or balance sheet total up to €10M?

    YesOutside the general rule by size. Check step 3.
    NoCheck whether you are medium-sized: fewer than 250 AWU and turnover up to €50M or balance sheet total up to €43M. If you do not meet those limits either, you are a large enterprise.
  3. Does any Article 2(2) exception apply to you?

    YesDNS, TLD registries, qualified trust services, CER critical entities, previously designated operators or central administration → possibly essential. Electronic communications → size distinguishes essential from important. Sole provider, significant impact or regional/local administration → designation review.
    NoThe result of step 2 stands.
Essential entityProactive supervision. Up to €10M or 2 % of worldwide turnover.
Important entitySame obligations, ex-post supervision. Up to €7M or 1.4 %.
Not in scopeBut if you supply any of the above, their requirements reach you by contract.

And now, step by step.

First: is your sector in the annexes?

Annex I lists the sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management between businesses (MSPs and MSSPs), public administration and space.

Annex II adds other critical sectors: postal and courier services, waste management, chemicals, food, manufacture of medical devices, of computer, electronic and optical products, of electrical equipment, of machinery, of motor vehicles and of other transport equipment, digital providers and research.

Two that are often overlooked: ICT service management between businesses — if you are an MSP or MSSP, you are in Annex I — and manufacturing, which pulls in a great deal of industry that never saw itself as critical infrastructure.

Second: what size are you?

The thresholds are those of Recommendation 2003/361/EC. Staff headcount is the main criterion and is combined with one financial alternative: turnover or balance sheet total. You cannot simply select the highest figure.

CategoryStaff in AWUAnnual turnoverAnnual balance sheetHow it applies
Smallfewer than 50up to €10Mup to €10MStaff plus at least one of the two financial ceilings
Medium-sizedfewer than 250up to €50Mup to €43MThe same combination, provided it is not already small
LargeDoes not meet the limits aboveWithin the general rule; essential if it operates in Annex I

The calculation does not always use the company's standalone figures: data from partner or linked enterprises must be aggregated under Article 6 of the Annex. A category change also takes effect only when the ceilings are exceeded or no longer exceeded over two consecutive accounting periods. A newly established enterprise with no approved accounts uses a bona fide estimate for the financial year.

Third: does an exception apply?

Article 2(2) brings certain entities into scope regardless of size. In these cases, economic data do not decide whether the entity is in scope; for electronic communications providers, they still help distinguish an essential entity from an important one:

  • Providers of DNS services, top-level domain name registries and qualified trust service providers.
  • Providers of public electronic communications networks or services.
  • Entities that are the sole provider in the Member State of a service essential for a critical societal or economic activity.
  • Those whose disruption would have a significant impact on public safety, public security or public health.
  • Critical entities designated under the CER Directive (EU) 2022/2557, and operators of essential services already designated under the Spanish RD 43/2021.
  • Entities of the central public administration.

Sole-provider and significant-impact cases require identification by the competent authority. Whether regional and local administrations are included will depend on Spanish law. In those circumstances the correct result is therefore a designation review, not a request for economic data that cannot settle the issue.

If you still have doubts after all that — which is the normal outcome, because the combinations are many — that is exactly the job the self-assessment I have published does: it collects the sector, size and exception details and gives you an indicative classification with the article that supports it.

4. Essential or important: what really changes

This is the most frequent misunderstanding I come across. Many people assume that being "important" rather than "essential" lowers the obligations. It does not.

Essential entityImportant entity
Article 21 measuresThe sameThe same
Article 23 notificationThe sameThe same
Article 20 governanceThe sameThe same
SupervisionProactive: inspections, security audits, requests for information without anything having happenedEx-post: only where there is evidence of non-compliance or an incident
Maximum fineUp to €10M or 2 % of worldwide annual turnoverUp to €7M or 1.4 % of worldwide annual turnover

In plain terms: what you have to do is identical. What changes is how likely it is that someone comes to check, and what it costs you if you have not done it. "Important" is not a lighter version; it is the same requirement with less scrutiny.

5. The three Article 23 deadlines you cannot improvise

If I had to point at the obligation most companies will breach without noticing, it is this one. On a significant incident, Article 23 sets three milestones:

  1. 24 hours — early warning. It is enough to indicate whether the incident is suspected of being caused by unlawful or malicious acts and whether it could have cross-border impact.
  2. 72 hours — notification with an initial assessment: severity, impact and indicators of compromise.
  3. One month — final report: detailed description, type of threat, root cause, mitigation measures applied and cross-border effects.

You must also inform the recipients of your services where the incident may affect them, and the authority may request intermediate reports.

The detail almost everyone misses: the 24 hours run from becoming aware of the incident. If your detection capability amounts to someone calling to say something is not working, the clock starts late and you have no data to report either. Without event logging and a written flow with named owners and deputies, those 24 hours get used up deciding who makes the call.

6. The ten Article 21 blocks, in plain language

Article 21(2) lists ten families of minimum measures, which must be proportionate to the risk and to the size of the entity. Without the official-journal register:

  1. Risk analysis and information security policy — the starting point for everything else.
  2. Incident handling — detect, respond and keep a record.
  3. Business continuity — backups, disaster recovery and crisis management.
  4. Supply chain security — assess your direct suppliers and take it to the contract.
  5. Secure acquisition and development — including vulnerability handling and disclosure.
  6. Assessing effectiveness — checking that the measures actually work, not that they exist.
  7. Cyber hygiene and training — for the whole workforce.
  8. Cryptography and encryption — with a policy behind it, not at each person's discretion.
  9. Human resources security, access control and asset management — this is where the inventory and, above all, leavers belong.
  10. Multi-factor authentication and secure communications — including emergency channels.

Look at block 9, where I find the most gaps and which gets the fewest headlines: accounts belonging to people who no longer work at the company. It is a near-guaranteed finding in any audit, it costs little to fix and it is a textbook way in.

7. The part that falls to your board

Article 20 is the one that generates the most uncomfortable conversations, and it is worth reading carefully because it gets cited a lot and understood little.

It says two things. First: the management body approves the risk-management measures, oversees their implementation and is responsible for the entity's compliance. Second: its members must receive regular training sufficient to identify risks and assess cybersecurity risk-management practices.

On responsibility it is worth being precise rather than selling fear: the Article 34 fines fall on the entity, not on the director. What the Directive adds is that management answers for the measures being adopted and overseen, and that Article 32(6) allows authorities to request a temporary ban on exercising managerial functions in essential entities. How that plays out in Spain will depend on the transposition law.

Put differently: what a board is asked for is not to understand technology. It is to do four perfectly reasonable things:

  • Formally approve the policy and the measures, minuted. Not an email saying fine.
  • Assign responsibilities to named people, not to a department.
  • Make security a standing item on the committee agenda, with indicators that get reviewed.
  • Get trained once a year, with an attendance record.
Keynote

Nothing a board is asked for requires budget. It requires calendar time. It is by far the fastest part of the whole framework to fix, and the first thing anyone looks at when something goes wrong.

8. Where to start if you are behind

If you are starting from scratch, this is the order I would follow by effort-to-impact ratio. It is not the order of the articles: it is the order that reduces risk soonest.

  1. MFA on everything facing the internet — remote access, privileged accounts and email. Best return of the whole list, and usually a matter of days.
  2. One isolated or immutable backup, and proof that it restores. A backup that has never been restored is not a backup: it is an intention.
  3. The notification flow in writing, with owners, deputies, templates and the channel identified. It is cheap, and without it the Article 23 deadlines are unreachable.
  4. The asset inventory with owner and criticality. Without it no risk analysis is reliable and you do not know what you are protecting.
  5. The board minute approving the policy and appointing an owner. One meeting.

Those five points do not make you NIS2 compliant, to be clear. But they close the gaps incidents actually come through, and they leave a record of diligence, which is the first thing anyone looks for when something goes wrong.

9. Check it yourself in 5 minutes

Rather than leaving you with a to-do list and nothing else, I have published the checklist I use with my clients. It is free and open:

  • Scope test under Articles 2 and 3: sector, size and exceptions, with an indicative classification and the article behind it.
  • 16 controls mapped to Articles 20, 21 and 23, each with its five levels described for that specific control, so you do not have to interpret a generic scale.
  • Maturity diagnosis by domain and gaps prioritised by regulatory criticality.
  • PDF report to take to your board.

And the deal, which to me is the important part: no sign-up, no email wall and no cookies. All the calculation and the PDF are generated in your browser; your answers never leave your device because there is no server to receive them. You can verify it with developer tools open: the only things downloaded come from my own domain — a font and the library that composes the PDF — and neither carries a single piece of your data.

The tool itself is in Spanish, since it is built around the Spanish transposition context, but the controls and the article references are the European ones.

Open the NIS2 checklist

Frequently asked questions

Does NIS2 affect small businesses?

As a general rule, small enterprises are outside scope: they must have fewer than 50 AWU and, in addition, annual turnover of no more than €10M or an annual balance sheet total of no more than €10M. The calculation considers partner or linked enterprises and, normally, two consecutive accounting periods; newly established enterprises use a bona fide estimate. Even so, a small enterprise may be in scope under the Article 2(2) exceptions —for example, if it provides DNS or qualified trust services— and may receive its clients' supply-chain obligations through contracts.

What is the difference between NIS2 and DORA?

DORA is Regulation (EU) 2022/2554, applicable to the financial sector since 17 January 2025. NIS2 is cross-sectoral. The key is Article 4 of NIS2: where a sector-specific Union act imposes at least equivalent requirements, that one applies instead of Articles 21 and 23. In plain terms: a financial entity subject to DORA complies through DORA and does not duplicate the regime. The exact fit should be confirmed once the Spanish law is out.

How does it relate to the Spanish ENS?

The Esquema Nacional de Seguridad (RD 311/2022) applies to the Spanish public sector and to those providing it with ICT services. It is a separate framework, with a different origin, but it overlaps substantially on technical content: if you are already aligned with the ENS, much of Article 21 is done and you can reuse evidence. Not equivalent, mind: the ENS lacks the Article 20 governance duties and the Article 23 deadlines.

What happens if I do not register with the competent authority?

Article 3(4) requires entities in scope to submit their details and notify any changes. It is a standalone obligation: it is breached simply by not registering, without any incident having to occur. And it has an underestimated practical effect: authorities build their lists of entities from those registrations. In Spain, the specific procedure and deadline will come from the transposition law.

I am a supplier to a company in scope. Does it affect me?

Not directly, if you are not in the annexes and do not meet the thresholds. In practice, yes. Article 21(2)(d) requires your in-scope clients to manage the security of their supply chain, so their requirements will reach you by contract: security clauses, obligations to report incidents on short deadlines and questionnaires before anything is awarded to you. I am already seeing it in tenders.

I have ISO 27001. Is that enough?

It is an excellent base and saves you a good part of the Article 21 journey, but it is not equivalent. The three gaps I always find: the Article 20 governance duties, with approval and oversight by the management body — something I often work on as an outsourced CISO; the Article 23 deadlines, far tighter than a management system usually contemplates; and registration with the authority. Certification helps demonstrate diligence; it does not replace compliance.

When will the Spanish law enter into force?

There is no certain date, and be sceptical of anyone who gives you one. The draft was approved in January 2025 and is still unpublished. The CJEU referral increases the pressure a great deal, but until it is in the BOE, it is not law. The text approved by the Council of Ministers includes three transitional provisions with deadlines for certain obligations, although their final scope may change during parliamentary passage. Always verify actual publication before taking decisions with legal effect.

Are the fines on the company or on the director?

The Article 34 ones, on the entity: up to €10M or 2 % of worldwide turnover for essential entities, €7M or 1.4 % for important ones. What touches individuals is different: Article 20(1) makes management responsible for compliance with the measures, and Article 32(6) allows a temporary ban on exercising managerial functions in essential entities to be requested. The real reach in Spain will depend on the transposition.


If you take away one idea, let it be this: Spain's delay is not your deadline. It is theirs. The measures you will have to have in place have been written since 2022, and when the law arrives there will be no adaptation window worth counting on. The 640-odd days of delay are 640 days that could have been put to use.

By the way, if you are interested in how the European compliance frameworks are being wired to each other, I wrote a few days ago about the AI Digital Omnibus and its hook into cybersecurity. It is about the same thing: no longer treating each regulation as an isolated project.

Any questions, I am here. No smoke.

Sources

Directive (EU) 2022/2555 (NIS2), consolidated text on EUR-Lex · Implementing Regulation (EU) 2024/2690, EUR-Lex · Infringement procedure and referral to the CJEU of 8 July 2026, European Commission press corner · Draft Law on Coordination and Governance of Cybersecurity, Department of National Security.

← All articles
Does NIS2 apply to you? Check it in 5 minutes

Keep reading

In scope?

Would you rather go through it together?

If you have done the checklist and do not know where to start, or you are unsure whether your company is in scope, tell me where you stand. I reply personally, no smoke and no strings attached.

Let's talk about your case