NIS2 Compliance
for Businesses

Fines of up to €10 million if you fail to comply.

We help you understand whether NIS2 applies to you, what you need to implement and by when.

NIS2 Compliance for Businesses
Image 1
Image 2

NIS2 is already in force,
and your company may be required to comply without knowing it

The Directive (EU) 2022/2555, known as NIS2, came into force on 18 October 2024. It expands the scope of the original NIS Directive and requires more sectors to implement cybersecurity measures, report incidents within very short deadlines and demonstrate compliance to the authorities. Spain is still completing its transposition process, but the obligations already apply in practice because the directive is binding.

The key point: NIS2 does not only affect large companies or “obvious” sectors such as energy or banking. It also reaches medium-sized companies in manufacturing, food, waste management, research, digital services, logistics, healthcare and many more. And if you are a critical supplier to an obligated entity, the obligation reaches you through the supply chain even if you are small.

Does NIS2 apply to me?

Answer these three questions mentally. If the answer to any of them is yes, NIS2 applies to you and you must comply. If you are not sure, we can validate it by phone in 15 minutes.
NIS2 Compliance for Businesses

Does your company operate in any of the Annex I or Annex II sectors?

Annex I (high criticality): energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT, space and public administration.

Annex II (other critical sectors): postal services, waste management, chemicals, food, manufacturing (medical devices, electronics, machinery, vehicles), digital services and research.

If yes → go to question 2.

NIS2 Compliance for Businesses

Do you have 50 or more employees, or annual turnover of €10M or more?

The threshold is “AND/OR”: exceeding one of the two is enough. If you are part of a larger group, the group’s consolidated workforce counts.

If yes → NIS2 applies to you. Go to the next block. If no → go to question 3.

NIS2 Compliance for Businesses

Are you a critical supplier to an obligated company?

Custom software, cloud services, MSP, document management, ICT services… If your company is part of the critical supply chain of an essential or important entity, NIS2 reaches you even if you do not meet the size thresholds.

If yes → NIS2 applies to you indirectly. Your client will require you to evidence security measures. If no → it does not apply to you today, but review it annually.

“NIS2 DOES NOT ASK IF YOU ARE BIG. IT ASKS IF YOU ARE CRITICAL”

What a properly implemented NIS2 programme requires

Article 21 of the directive sets out 10 areas of measures. We group them into the four major pillars your company must have covered.

Risk governance

Documented identification and assessment of the cybersecurity risks affecting your company, with at least annual review. It also includes supply-chain security: assessment of ICT providers and contractual clauses requiring them to maintain equivalent measures.

Technical measures

Multi-factor authentication for critical access, encryption of sensitive data, vulnerability management, verified backups, access control based on least privilege and an asset inventory. The technical foundations every serious system needs, documented and auditable.

Incident management and continuity

Procedures to detect, contain, report and learn from every incident. Playbooks by incident type, business continuity plan, disaster recovery and regular testing. And crucially: notification within 24 hours, 72 hours and one month to the competent CSIRT.

Training and management accountability

Mandatory training for staff and especially for management. NIS2 makes directors personally accountable: non-compliance may lead to a temporary ban on holding management positions in essential entities.

‘Very professional. We’ve been working together for many years and will continue to do so for many more!’

Marina Frau.

Companies
that already trust us

Yes, these are some of our clients

L'Arancina
Nautinort
Lionsgate Capital
Gallery Red
Rouge
Montis Advisors
Rosello
Cristalería Amanecer
Bufete Frau
Vectobal
esRadio Baleares
L'Arancina
Nautinort
Lionsgate Capital
Gallery Red
Rouge
Montis Advisors
Rosello
Cristalería Amanecer
Bufete Frau
Vectobal
esRadio Baleares

Six signs of
a poorly executed NIS2
compliance project

If the work comes down to filling in templates, drafting a policy document and sending you an invoice, they are selling you paperwork, not compliance. How to spot it.

They sell you “NIS2 certification” and call it done

NIS2 is not certified like ISO 27001. It is a continuous compliance directive, not a badge. Anyone selling you “NIS2 certification” either does not know what they are talking about or is directly misleading you.

The project is only documentary

Policies, procedures, manuals. Everything written down, nothing technically implemented. In the first inspection —or the first incident— paperwork will not save you: authorities look for real operational evidence, not signed documents.

They do not address the supply chain

Article 21 requires you to assess the security of your ICT suppliers. A compliance project that does not touch contracts with critical providers is incomplete by definition. And it is one of the areas most closely inspected.

They ignore Article 23 deadlines

Notifying incidents within 24 hours, 72 hours and one month is impossible without continuous monitoring. If the project does not include real detection capability —your own or managed SOC— compliance breaks at the first scare.

There is no training for management

Article 20 specifically requires senior management training. Many projects only train technical staff. When the authority asks what the CEO knows about risk, the answer must be documented.

There is no continuous evidence plan

If compliance ends with the delivery of a dossier and there are no periodic internal audits, risk updates or reports to management, compliance expires within months. And the authorities know it.

When it makes sense
to address your NIS2 compliance

01

When your sector appears in Annex I or Annex II

If you operate in energy, transport, healthcare, water, banking, ICT, critical manufacturing, food, waste or digital services and exceed the size thresholds, there is no debate. The obligation is already active. The longer you wait to start, the more risk you accumulate.

02

When a client starts requiring it

If you are an ICT provider to an essential or important entity, the obligation reaches you by contract before it reaches you through an inspection. Your clients will start asking you for evidence of NIS2 measures. Not having it removes you from their supply chain.

03

When you already comply with ISO 27001 or ENS

You have already done most of the work without realising it. The gap to NIS2 is much smaller than it seems: we reuse your risk analysis, policies and controls, and complete only what is NIS2-specific —supply chain, notification deadlines and management training.

04

Before Spain’s transposition activates inspections

Spain is expected to complete final transposition soon. At that point, sector authorities will begin inspections with retroactive effect from October 2024. Starting today gives you margin; starting when the first request arrives is late.

How we work through NIS2 compliance step by step

NIS2 Compliance for Businesses
ONE
1

Initial assessment

TWO
2

Gap analysis

THREE
3

Compliance roadmap

FOUR
4

Implementation

FIVE
5

Maintenance and continuous evidence

FAQs
about NIS2

It depends. The general threshold is 50 employees or €10M in turnover, but there are exceptions based on service criticality and supply chain. If you are a critical ICT supplier to an essential entity —hospital, energy company, bank or public administration— NIS2 can reach you even if you are a 15-person company.

It helps a lot, but it is not automatic. ISO 27001 covers an important part of Article 21 —policies, controls, risk analysis— but NIS2 adds its own requirements: Article 23 notification deadlines, mandatory management training and personal accountability. We reuse your ISO work and complete what is missing.

The Spanish National Security Framework (ENS) shares many measures with NIS2, especially if you have ENS Medium or High. The advantage is huge: most of the gap is already closed. What we review specifically is the supply chain and notification deadlines, which have their own nuances under NIS2.

The real risk is not a random inspection. It is that a serious incident —ransomware, data breach— triggers an automatic investigation and reveals that you did not have the minimum measures in place. At that point you do not only pay the cost of the incident: you pay the fine + publication of non-compliance + potential management ban. And your obligated clients will terminate the contract due to supply-chain requirements.

It depends on your starting point. An initial assessment is free. A full gap analysis starts at a few thousand euros. Implementation varies enormously depending on your size, sector and current infrastructure: from €5,000-€15,000 for companies with a solid base to larger projects for companies starting from zero. We always provide a fixed price after the gap analysis, not an open-ended hour bundle.

A reasonable NIS2 compliance project for an SME takes between 3 and 9 months, depending on the starting level. If you already have ISO 27001 or ENS, it can be much faster. The recommendation is to start now: Spain’s final transposition may activate retroactive inspections.

No. We handle it from Palma with our own team: certified technicians (ISO 27001 Auditor, CISSP, CISA) and specialised legal consultants. When you hire us, the same team manages the project from assessment to continuous follow-up.

A 30-minute call is enough for us to validate whether NIS2 applies to you, how intensely and give you a realistic cost range. If we are a good fit, we prepare a fixed proposal within a few days. If not, we guide you on what to look for.