A self-assessment of applicability and maturity against Directive (EU) 2022/2555. First we check whether your company is in scope; then we assess 16 controls mapped to articles 20, 21 and 23. At the end you take away a PDF report with your prioritised gaps.
How late Spain is running on transposing NIS2
Since 17 October 2024, the deadline set in article 41 of Directive (EU) 2022/2555 for Member States to adopt and publish the necessary provisions. On 8 July 2026 the European Commission referred Spain to the Court of Justice of the EU — alongside Ireland, France and the Netherlands — and asked for financial penalties to be imposed.
NIS2 is a directive: it does not apply on its own, it needs a national law to transpose it. But while that law works its way through, the technical content you can be held to is already set out in the European articles and is not going to change in substance. That is why this checklist is built on the Directive, and not on a Spanish draft that can still move.
For the wider context
If you want the full picture before taking the test — what has happened with the transposition, who is in scope, what changes between an essential and an important entity, and the article 23 deadlines — I have written it up properly in NIS2 in Spain 2026: what already binds you.
Legal notice
This tool is an indicative self-assessment for educational purposes. It is not legal advice, nor an official determination of NIS2 scope, which rests exclusively with the competent authorities. The real classification of an entity depends on its specific activity, on sectoral designations and on the final text of the Spanish transposing law, still awaiting publication in the BOE as at the date of this review.
Everything is calculated entirely in your browser: your answers are not sent, not stored and never leave your device. There are no cookies, third-party resources or usage measurement: downloads and your interactions with the tool are not recorded. Regulatory content last reviewed: .
This result is preliminary. The test combines your sector of activity (Annexes I and II of the Directive) with the size of the entity under Recommendation 2003/361/EC, plus the exceptions in article 2.
If your activity fits several, pick the one you provide the most significant service to third parties under.
Initial guidance under articles 2 and 3 of Directive (EU) 2022/2555; this is not an official determination.
16 controls, each mapped to its article. Every level is described for that specific control, so you do not have to interpret a generic scale: pick the one that portrays your real situation. An optimistic diagnosis protects you from neither an incident nor an inspection.
Ordered by regulatory criticality and by distance from the level required. Start at the top.
A diagnosis is only worth something if it turns into a plan. Download the report to share with your board, or write to me and we will go through it together, with no strings attached.
The report is generated in your browser. Nothing is sent to any server.
These are the controls the self-assessment evaluates, grouped by domain and with the article of the Directive each one comes from. You can read them here as a reference, or take the test to score them and take away the report with your prioritised gaps.
Management formally approves the cybersecurity risk management measures and oversees their implementation. NIS2 requires Member States to ensure the management body can be held liable for the entity's infringements in this area.
Members of the management body receive regular training that enables them to identify risks and assess cybersecurity management practices.
There is a documented risk assessment covering the information systems and a security policy derived from it, reviewed on a defined schedule.
An up-to-date inventory of information assets and systems is maintained, with an assigned owner and a classification by criticality.
Whether the measures genuinely work is assessed periodically, through audits, indicators or technical testing, and the findings generate improvement actions.
There is detection capability (event logging, monitoring, alerting) and an incident response procedure with roles, escalation and record-keeping.
There is a defined process, with owners and an identified channel, for issuing the early warning within 24 hours, the notification within 72 hours and the final report within one month; and for informing service recipients where appropriate.
Backups follow a defined policy, are protected against encryption or deletion by an attacker, and their restoration is verified.
There are continuity and crisis management plans with defined RTO and RPO, and they are put to the test through drills.
The risk from suppliers and service providers is assessed, and contracts include security and incident notification requirements.
Security is considered in the acquisition, development and maintenance of systems, with defined requirements and change control.
Vulnerabilities are identified systematically, prioritised by risk and patched within defined deadlines, with a disclosure channel.
The principle of least privilege is applied, accesses are reviewed periodically and MFA is deployed on remote access, privileged accounts and email.
There is a cryptography policy, sensitive information is encrypted in transit and at rest, and secure communication channels are available, including emergency ones.
All staff receive regular training in basic cybersecurity practices, reinforced with practical exercises such as phishing simulations.
Joiners, role changes and above all leavers follow a defined process: a confidentiality agreement, permissions matched to the role, and removal of access and devices on the day they leave.
Each control is rated on a five-level scale — does not exist, informal, documented, implemented, measured and improved — described for that specific control, and it is weighted by its regulatory criticality when the maturity percentage is calculated.