Home Tools NIS2 checklist

Does NIS2 apply to you? Find out in 5 minutes.

A self-assessment of applicability and maturity against Directive (EU) 2022/2555. First we check whether your company is in scope; then we assess 16 controls mapped to articles 20, 21 and 23. At the end you take away a PDF report with your prioritised gaps.

16 controls ≈ 5 minutes PDF report No sign-up No data sent

How late Spain is running on transposing NIS2

—
Days
—
Hours
—
Minutes
—
Seconds

Since 17 October 2024, the deadline set in article 41 of Directive (EU) 2022/2555 for Member States to adopt and publish the necessary provisions. On 8 July 2026 the European Commission referred Spain to the Court of Justice of the EU — alongside Ireland, France and the Netherlands — and asked for financial penalties to be imposed.

Start the self-assessment →

Starting point

Where the law stands today

NIS2 is a directive: it does not apply on its own, it needs a national law to transpose it. But while that law works its way through, the technical content you can be held to is already set out in the European articles and is not going to change in substance. That is why this checklist is built on the Directive, and not on a Spanish draft that can still move.

In force
Directive (EU) 2022/2555 — NIS2 The European framework. Art. 20 (governance and management accountability), art. 21 (risk management measures), art. 23 (notification obligations) and art. 34 (fines of up to €10M or 2 % of worldwide turnover). Read the text on EUR-Lex →
In force
Implementing Regulation (EU) 2024/2690 Sets out the technical and methodological requirements of the art. 21 measures and specifies when an incident is significant, for digital service and digital infrastructure providers. It is the most concrete reference available on «what has to be implemented». Read the text on EUR-Lex →
Before the CJEU
Infringement procedure against Spain — INFR(2024)0270 A reasoned opinion in May 2025 and, on 8 July 2026, referral to the Court of Justice of the EU with a request for financial penalties, more than twenty months after the deadline expired. The practical consequence for companies is that the national framework is still not settled, but the pressure to pass it is at its highest. European Commission press room →
In progress
Draft Cybersecurity Coordination and Governance Act The Spanish transposing law, approved by the Council of Ministers on 14 January 2025 and still unpublished in the BOE. It creates the National Cybersecurity Centre and distributes the supervisory authorities by sector. Check its final publication before taking decisions with legal effects. Department of National Security →
In force until transposition
RDL 12/2018 and RD 43/2021 — the Spanish NIS1 framework These remain the regime applying to operators of essential services and digital service providers already designated. If your company was already in scope, your current obligations come from here. RD 43/2021 in the BOE →
Complementary
Directive (EU) 2022/2557 — CER (critical entities resilience) NIS2's twin on the physical side. Anyone who is a critical entity under CER is automatically in scope of NIS2 as an essential entity, regardless of their size. Read the text on EUR-Lex →

For the wider context

If you want the full picture before taking the test — what has happened with the transposition, who is in scope, what changes between an essential and an important entity, and the article 23 deadlines — I have written it up properly in NIS2 in Spain 2026: what already binds you.

Legal notice

This tool is an indicative self-assessment for educational purposes. It is not legal advice, nor an official determination of NIS2 scope, which rests exclusively with the competent authorities. The real classification of an entity depends on its specific activity, on sectoral designations and on the final text of the Spanish transposing law, still awaiting publication in the BOE as at the date of this review.

Everything is calculated entirely in your browser: your answers are not sent, not stored and never leave your device. There are no cookies, third-party resources or usage measurement: downloads and your interactions with the tool are not recorded. Regulatory content last reviewed: .

Step 1 of 4

Could NIS2 apply to your company?

This result is preliminary. The test combines your sector of activity (Annexes I and II of the Directive) with the size of the entity under Recommendation 2003/361/EC, plus the exceptions in article 2.

If your activity fits several, pick the one you provide the most significant service to third parties under.

Staff in annual work units (AWU)

One AWU is one person working full-time throughout the year; part-time and seasonal work count as fractions.

Annual turnover
Annual balance sheet total

The definition combines staff with turnover or balance sheet total; it does not automatically select the highest criterion.

Partner or linked enterprises
Consecutive accounting periods
Special circumstances (tick any that apply)
Step 2 of 4

Preliminary applicability result

Initial guidance under articles 2 and 3 of Directive (EU) 2022/2555; this is not an official determination.

Step 3 of 4

Maturity checklist

16 controls, each mapped to its article. Every level is described for that specific control, so you do not have to interpret a generic scale: pick the one that portrays your real situation. An optimistic diagnosis protects you from neither an incident nor an inspection.

0 / 16 rated
Step 4 of 4

Your NIS2 maturity diagnosis

0%
Maturity
—

Maturity by domain

Prioritised gaps

Ordered by regulatory criticality and by distance from the level required. Start at the top.

So what now?

A diagnosis is only worth something if it turns into a plan. Download the report to share with your board, or write to me and we will go through it together, with no strings attached.

The report is generated in your browser. Nothing is sent to any server.

The reference

The 16 controls of the checklist

These are the controls the self-assessment evaluates, grouped by domain and with the article of the Directive each one comes from. You can read them here as a reference, or take the test to score them and take away the report with your prioritised gaps.

Governance, risk and oversight

  1. 01

    Management body accountability

    Art. 20.1

    Management formally approves the cybersecurity risk management measures and oversees their implementation. NIS2 requires Member States to ensure the management body can be held liable for the entity's infringements in this area.

  2. 02

    Specific training for management

    Art. 20.2

    Members of the management body receive regular training that enables them to identify risks and assess cybersecurity management practices.

  3. 03

    Risk assessment and security policy

    Art. 21.2.a

    There is a documented risk assessment covering the information systems and a security policy derived from it, reviewed on a defined schedule.

  4. 04

    Asset inventory and classification

    Art. 21.2.i

    An up-to-date inventory of information assets and systems is maintained, with an assigned owner and a classification by criticality.

  5. 05

    Assessing the effectiveness of the measures

    Art. 21.2.f

    Whether the measures genuinely work is assessed periodically, through audits, indicators or technical testing, and the findings generate improvement actions.

Detection, response and notification

  1. 06

    Incident detection and management

    Art. 21.2.b

    There is detection capability (event logging, monitoring, alerting) and an incident response procedure with roles, escalation and record-keeping.

  2. 07

    Notification process: 24h / 72h / one month

    Art. 23

    There is a defined process, with owners and an identified channel, for issuing the early warning within 24 hours, the notification within 72 hours and the final report within one month; and for informing service recipients where appropriate.

Continuity and resilience

  1. 08

    Backups and recovery

    Art. 21.2.c

    Backups follow a defined policy, are protected against encryption or deletion by an attacker, and their restoration is verified.

  2. 09

    Business continuity and crisis management

    Art. 21.2.c

    There are continuity and crisis management plans with defined RTO and RPO, and they are put to the test through drills.

Supply chain and development

  1. 10

    Supply chain security

    Art. 21.2.d

    The risk from suppliers and service providers is assessed, and contracts include security and incident notification requirements.

  2. 11

    Secure acquisition and development

    Art. 21.2.e

    Security is considered in the acquisition, development and maintenance of systems, with defined requirements and change control.

  3. 12

    Vulnerability and patch management

    Art. 21.2.e

    Vulnerabilities are identified systematically, prioritised by risk and patched within defined deadlines, with a disclosure channel.

Technical protection

  1. 13

    Access control and multi-factor authentication

    Art. 21.2.i, j

    The principle of least privilege is applied, accesses are reviewed periodically and MFA is deployed on remote access, privileged accounts and email.

  2. 14

    Encryption and secure communications

    Art. 21.2.h, j

    There is a cryptography policy, sensitive information is encrypted in transit and at rest, and secure communication channels are available, including emergency ones.

People

  1. 15

    Cyber hygiene and staff awareness

    Art. 21.2.g

    All staff receive regular training in basic cybersecurity practices, reinforced with practical exercises such as phishing simulations.

  2. 16

    Joiners, leavers and personnel security

    Art. 21.2.i

    Joiners, role changes and above all leavers follow a defined process: a confidentiality agreement, permissions matched to the role, and removal of access and devices on the day they leave.

Each control is rated on a five-level scale — does not exist, informal, documented, implemented, measured and improved — described for that specific control, and it is weighted by its regulatory criticality when the maturity percentage is calculated.

Common questions

Frequently asked questions about NIS2

Scope
Which companies does NIS2 apply to in Spain? As a general rule, small enterprises are outside scope: those with fewer than 50 AWU and annual turnover of no more than €10M or an annual balance sheet total of no more than €10M. If those conditions are not met together, the entity must be checked against the medium-sized enterprise definition. Partner or linked enterprises and the last two closed accounting periods must also be considered. Certain entities are in scope regardless of size, including DNS service providers, top-level domain name registries, qualified trust service providers and sole providers of an essential service.
Status
Has NIS2 been transposed in Spain? Not yet. The draft act was approved by the Council of Ministers on 14 January 2025 and is still unpublished in the BOE. On 8 July 2026 the European Commission referred Spain to the Court of Justice of the EU over it. Waiting for the law before starting is a miscalculation: the date of application set by the Directive was 18 October 2024, and Spain's delay has not created a new deadline. The draft contemplates transitional provisions for certain formalities, but their final scope will only be known once the text is passed.
Deadlines
What are the deadlines for notifying an incident? Article 23 sets three milestones: an early warning within 24 hours of becoming aware of the significant incident, a notification with an initial assessment within 72 hours, and a final report within one month. It is the hardest obligation to improvise: with no written process and no detection capability, the 24 hours run out just deciding who makes the call.
Categories
What is the difference between an essential and an important entity? The obligations of articles 20, 21 and 23 are identical. What changes is the supervision — proactive for essential entities, ex post for important ones — and the ceiling on fines: up to €10M or 2 % of worldwide turnover against €7M or 1.4 %.
Privacy
Does this tool store my answers? No. All the calculation and the PDF generation happen in your browser. There is no sign-up, no cookies and no answers sent. You can check it with the developer tools open: the only things downloaded are from my own domain — a font and the library that composes the PDF — and neither carries a single piece of your data.