NIS2 Compliance
for Businesses
We help you understand whether NIS2 applies to you, what you need to implement and by when.
NIS2 is already in force,
and your company may be required to comply without knowing it
The Directive (EU) 2022/2555, known as NIS2, came into force on 18 October 2024. It expands the scope of the original NIS Directive and requires more sectors to implement cybersecurity measures, report incidents within very short deadlines and demonstrate compliance to the authorities. Spain is still completing its transposition process, but the obligations already apply in practice because the directive is binding.
The key point: NIS2 does not only affect large companies or “obvious” sectors such as energy or banking. It also reaches medium-sized companies in manufacturing, food, waste management, research, digital services, logistics, healthcare and many more. And if you are a critical supplier to an obligated entity, the obligation reaches you through the supply chain even if you are small.
Does NIS2 apply to me?
Does your company operate in any of the Annex I or Annex II sectors?
Annex I (high criticality): energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT, space and public administration.
Annex II (other critical sectors): postal services, waste management, chemicals, food, manufacturing (medical devices, electronics, machinery, vehicles), digital services and research.
If yes → go to question 2.
Do you have 50 or more employees, or annual turnover of €10M or more?
The threshold is “AND/OR”: exceeding one of the two is enough. If you are part of a larger group, the group’s consolidated workforce counts.
If yes → NIS2 applies to you. Go to the next block. If no → go to question 3.
Are you a critical supplier to an obligated company?
Custom software, cloud services, MSP, document management, ICT services… If your company is part of the critical supply chain of an essential or important entity, NIS2 reaches you even if you do not meet the size thresholds.
If yes → NIS2 applies to you indirectly. Your client will require you to evidence security measures. If no → it does not apply to you today, but review it annually.
“NIS2 DOES NOT ASK IF YOU ARE BIG. IT ASKS IF YOU ARE CRITICAL”
What a properly implemented NIS2 programme requires
Risk governance
Documented identification and assessment of the cybersecurity risks affecting your company, with at least annual review. It also includes supply-chain security: assessment of ICT providers and contractual clauses requiring them to maintain equivalent measures.
Technical measures
Multi-factor authentication for critical access, encryption of sensitive data, vulnerability management, verified backups, access control based on least privilege and an asset inventory. The technical foundations every serious system needs, documented and auditable.
Incident management and continuity
Procedures to detect, contain, report and learn from every incident. Playbooks by incident type, business continuity plan, disaster recovery and regular testing. And crucially: notification within 24 hours, 72 hours and one month to the competent CSIRT.
Training and management accountability
Mandatory training for staff and especially for management. NIS2 makes directors personally accountable: non-compliance may lead to a temporary ban on holding management positions in essential entities.
‘Very professional. We’ve been working together for many years and will continue to do so for many more!’
Companies
that already trust us
Yes, these are some of our clients
Six signs of
a poorly executed NIS2 compliance project
If the work comes down to filling in templates, drafting a policy document and sending you an invoice, they are selling you paperwork, not compliance. How to spot it.
They sell you “NIS2 certification” and call it done
The project is only documentary
They do not address the supply chain
They ignore Article 23 deadlines
There is no training for management
There is no continuous evidence plan
When it makes sense
to address your NIS2 compliance
When your sector appears in Annex I or Annex II
If you operate in energy, transport, healthcare, water, banking, ICT, critical manufacturing, food, waste or digital services and exceed the size thresholds, there is no debate. The obligation is already active. The longer you wait to start, the more risk you accumulate.
When a client starts requiring it
If you are an ICT provider to an essential or important entity, the obligation reaches you by contract before it reaches you through an inspection. Your clients will start asking you for evidence of NIS2 measures. Not having it removes you from their supply chain.
When you already comply with ISO 27001 or ENS
You have already done most of the work without realising it. The gap to NIS2 is much smaller than it seems: we reuse your risk analysis, policies and controls, and complete only what is NIS2-specific —supply chain, notification deadlines and management training.
Before Spain’s transposition activates inspections
Spain is expected to complete final transposition soon. At that point, sector authorities will begin inspections with retroactive effect from October 2024. Starting today gives you margin; starting when the first request arrives is late.
How we work through NIS2 compliance step by step
Initial assessment
- A 30-45 minute call to validate whether NIS2 applies to you, how intensely and what operational risks non-compliance creates. By the end, you have the criteria to decide whether to continue with us or with someone else. No long sales presentation —straight to technical judgement.
Gap analysis
- Technical and documentary review against the 10 points of Article 21. Interviews with IT, management and critical process owners. We deliver a report showing what you already comply with, what is missing and in what order to address it, with estimated effort and a fixed cost.
Compliance roadmap
- A roadmap prioritised by risk and impact, with phases, deadlines, owners and a fixed price per phase. No open-ended hour bundles. You choose the pace: all at once or in stages depending on budget availability.
Implementation
- Deployment of technical measures (MFA, encryption, verified backups, monitoring, SOC where applicable) and documentary measures (policies, playbooks, procedures, supplier contracts, training plan). The same team that performed the gap analysis leads the implementation.
Maintenance and continuous evidence
- Periodic internal audits, risk analysis updates, quarterly reports for management and preparation for supervisory review. NIS2 is not a project; it is a capability that must be sustained.







FAQs
about NIS2
We are small, so it does not affect us, right?
It depends. The general threshold is 50 employees or €10M in turnover, but there are exceptions based on service criticality and supply chain. If you are a critical ICT supplier to an essential entity —hospital, energy company, bank or public administration— NIS2 can reach you even if you are a 15-person company.
We already comply with ISO 27001. Is that enough for NIS2?
It helps a lot, but it is not automatic. ISO 27001 covers an important part of Article 21 —policies, controls, risk analysis— but NIS2 adds its own requirements: Article 23 notification deadlines, mandatory management training and personal accountability. We reuse your ISO work and complete what is missing.
What if we already have ENS?
The Spanish National Security Framework (ENS) shares many measures with NIS2, especially if you have ENS Medium or High. The advantage is huge: most of the gap is already closed. What we review specifically is the supply chain and notification deadlines, which have their own nuances under NIS2.
What happens if I do not comply and nobody inspects me?
The real risk is not a random inspection. It is that a serious incident —ransomware, data breach— triggers an automatic investigation and reveals that you did not have the minimum measures in place. At that point you do not only pay the cost of the incident: you pay the fine + publication of non-compliance + potential management ban. And your obligated clients will terminate the contract due to supply-chain requirements.
How much does NIS2 compliance cost?
It depends on your starting point. An initial assessment is free. A full gap analysis starts at a few thousand euros. Implementation varies enormously depending on your size, sector and current infrastructure: from €5,000-€15,000 for companies with a solid base to larger projects for companies starting from zero. We always provide a fixed price after the gap analysis, not an open-ended hour bundle.
How long does it take to implement NIS2?
A reasonable NIS2 compliance project for an SME takes between 3 and 9 months, depending on the starting level. If you already have ISO 27001 or ENS, it can be much faster. The recommendation is to start now: Spain’s final transposition may activate retroactive inspections.
Does islaNet subcontract NIS2 projects to another company?
No. We handle it from Palma with our own team: certified technicians (ISO 27001 Auditor, CISSP, CISA) and specialised legal consultants. When you hire us, the same team manages the project from assessment to continuous follow-up.
START WITH AN ASSESSMENT FOR
YOUR
COMPANY
A 30-minute call is enough for us to validate whether NIS2 applies to you, how intensely and give you a realistic cost range. If we are a good fit, we prepare a fixed proposal within a few days. If not, we guide you on what to look for.