What NIS2 is and why it affects you
NIS2 (Directive (EU) 2022/2555) is the European cybersecurity rule that replaces the old NIS directive. Its transposition in Spain significantly expands the number of obligated companies and tightens the requirements: it is no longer just for large corporations or the public sector.
If your business operates in a critical sector or provides services to an obligated entity, NIS2 reaches you. And even if you are not directly obligated, your clients will start demanding security assurances in the supply chain anyway.
Who it actually obligates
NIS2 distinguishes between essential and important sectors. These include, among others:
- Essential: energy, transport, drinking water and wastewater, health, banking, financial market infrastructures, digital infrastructures and public administration.
- Important: postal services, waste management, chemicals, food, manufacture of machinery and electronics, digital providers and ICT services.
- Supply chain: if you supply an obligated entity, your clients will require security evidence from you even if you are not on the list.
The size criterion targets medium and large companies (roughly 50+ employees, or turnover above €10M), but each member state may fine-tune the thresholds in its transposition. When in doubt, the prudent move is to prepare.
What duties it imposes
- Risk management: proportionate technical and organisational measures, not a closed checklist. You must be able to show you analyse and treat risk.
- Incident notification: early warning within 24 hours and formal notification within 72 hours for a significant incident.
- Supply chain security: assess the risk of your suppliers and of your own services towards your clients.
- Management responsibility: senior management is accountable and must be trained in risk management.
- Registration: register the entity and keep its information updated with the competent authority.
NIS2, ENS and ISO 27001 are not the same
ENS applies to the public sector and its suppliers. NIS2 applies to critical sectors and their supply chain. ISO 27001 is a voluntary security management standard. They don’t compete: they complement each other. A good Information Security Management System (ISMS) aligned with ISO 27001 is the most efficient way to provide evidence for both ENS and NIS2.
Technical plan: what you can do now
- Risk analysis: identify assets, realistic threats and business impact.
- Asset inventory: you can’t protect what you don’t know you have.
- MFA and access control: especially for remote access and administration.
- Vulnerability management: inventory, prioritise and patch with a defined process.
- Detection and response: tested backups, documented incident management and notification channels.
- Training: employee awareness and management training in risk.
- Technical testing: a pentest that independently verifies the measures work.
How a pentest fits into NIS2 compliance
NIS2 requires risk management measures and response capability. A pentest documents verifiable technical evidence: it shows you test your security periodically and gives you an auditable remediation plan for an inspection or for your clients.
Pentesting / Penetration testing