NIS2 Compliance: Act Before the Regulator Does
EU Network and Information Security Directive 2 compliance: scope assessment, control implementation, incident notification protocols, and board-level security governance.
Does this apply to your business?
Has your company formally assessed whether it qualifies as an essential or important entity under NIS2?
Does your organisation have a tested incident notification protocol capable of meeting the 24-hour early warning deadline?
Has your board formally approved your cybersecurity risk management measures and received the training NIS2 requires?
Have you audited the cybersecurity risks introduced by your critical technology suppliers into your supply chain?
0 of 4 questions answered
Our NIS2 compliance implementation process
Scope assessment and classification
We determine whether your company is an essential or important entity under NIS2 criteria: sector of activity, size thresholds, and service criticality. We also assess supply chain exposure — organisations supplying essential entities may incur compliance obligations.
NIS2 gap analysis
We assess the current state of your cybersecurity controls against the Article 21 requirements: risk management, supply chain security, encryption, authentication, access control, business continuity, and incident management.
Compliance plan implementation
We implement required technical and organisational measures, draft the mandatory policies and procedures, and establish the governance framework with explicit board-level accountability as the directive requires.
Incident notification protocol
We design, document, and test the incident notification protocol for significant incidents: 24-hour early warning, 72-hour initial report, and one-month final report. We coordinate with the legal team on parallel GDPR notifications to the AEPD where personal data is affected.
The challenge
NIS2 dramatically expands the population of organisations required to meet strict cybersecurity obligations — thousands of Spanish companies that have never appeared on the regulatory radar will become essential or important entities. Fines reach EUR 10 million or 2% of global annual turnover. Board members face personal liability for governance failures. Spain's transposition is expected by June 2026, but the time to implement the required controls is now.
Our solution
We assess whether your organisation falls within NIS2's scope, implement the technical and organisational controls required by Article 21, establish the incident notification protocols the directive mandates (24-hour early warning, 72-hour initial report), and document compliance against the full NIS2 framework in preparation for inspection by the Spanish supervisory authority.
NIS2 — Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union — replaces the original NIS Directive and significantly expands the scope of mandatory cybersecurity obligations in the EU. It classifies organisations in 18 critical sectors as "essential entities" or "important entities" and requires them to implement risk management measures (Article 21), report significant incidents to national authorities within 24 hours (early warning) and 72 hours (formal report), and ensure their supply chains meet adequate security standards. In Spain, transposition into national law is expected by June 2026; competent supervisory authorities are INCIBE (Instituto Nacional de Ciberseguridad) for most private entities and CCN (Centro Criptológico Nacional) for public entities and their providers. Fines for essential entities reach EUR 10 million or 2% of global annual turnover.
Our NIS2 compliance team combines legal expertise in technology regulation with technical cybersecurity knowledge, allowing us to address both the legal scope assessment and the practical implementation of the controls the directive requires.
The Most Significant Cybersecurity Regulation in EU History
NIS2 is not an incremental update to the original NIS Directive. It is a fundamental rewrite that transforms cybersecurity from a technical concern into a board-level governance obligation — with personal liability for directors, fines comparable to GDPR, and a scope that reaches across 18 critical sectors and their supply chains. The Spanish transposition expected in June 2026 will bring these obligations into domestic law, but the prudent response is to begin implementation now rather than wait for the law to take formal effect.
Scope: Broader Than Most Companies Expect
The most common source of NIS2 surprises is scope. Companies that do not consider themselves operators of critical infrastructure in the traditional sense — logistics platforms, cloud service providers, food manufacturers, medical device companies — are captured by the directive’s expanded sector list. Supply chain exposure adds another layer: organisations supplying services to essential entities may be required by those entities to demonstrate NIS2-equivalent compliance as a condition of their contracts, well before any Spanish supervisory authority comes calling.
Our scope assessment is a formal legal and technical analysis, not a checklist exercise. It produces a documented conclusion that can be presented to the board, to customers, and to regulators.
Article 21: What Controls Are Actually Required
The gap analysis against Article 21’s requirements is typically where organisations discover the most work. Most have some form of cybersecurity controls, but NIS2’s requirements go substantially further: a formally documented and board-approved risk management framework, a supply chain security programme with contractual teeth, multi-factor authentication and encryption deployed across all critical systems, and — critically — a tested incident notification protocol that can actually deliver a 24-hour early warning to the supervisory authority, not just in theory.
For organisations simultaneously pursuing ISO 27001 certification, we structure the NIS2 compliance project to maximise overlap between the two frameworks, avoiding duplication of effort while ensuring that the specific NIS2 requirements not covered by the standard — board accountability documentation, incident notification timelines, supply chain clauses — are addressed in full.
The Incident Notification Requirement
NIS2’s incident notification obligations are operationally demanding. An early warning must reach the supervisory authority within 24 hours of detecting a significant incident — before full analysis, before root cause determination, and often before the incident is fully contained. The 72-hour initial report requires more substance, and the one-month final report requires a comprehensive account of impact, cause, and remediation.
For incidents affecting personal data, these timelines run in parallel with the GDPR’s 72-hour notification window to the AEPD. Our data protection and NIS2 teams coordinate these notifications jointly, ensuring that the information provided to different authorities is consistent and that neither deadline is missed in the urgency of the other.
NIS2 and DORA: Sector-Specific Overlap for Financial Entities
For financial institutions — banks, payment institutions, insurance companies, investment firms — the Digital Operational Resilience Act (DORA) applies alongside NIS2. DORA creates a harmonised framework for ICT risk management specifically in the financial sector, with requirements that overlap with NIS2 in certain areas but go substantially further in others: mandatory ICT risk management frameworks, contractual requirements for critical third-party ICT providers, digital operational resilience testing (including threat-led penetration testing for systemically important institutions), and an incident classification and reporting regime with tighter timelines than NIS2.
Where both regimes apply, we coordinate the DORA compliance and NIS2 programmes to avoid duplication while ensuring full coverage of both frameworks. The efficiency gains from integration are significant: a single ICT risk management framework, a unified incident notification protocol, and a consolidated third-party management programme serve both requirements.
Supply Chain Security: The NIS2 Obligation Most Companies Underestimate
Article 21(2)(d) of NIS2 requires affected entities to manage supply chain security — the security of supplier and service-provider relationships. This obligation is more operationally demanding than it appears: it requires organisations to assess the cybersecurity practices of all their critical suppliers, include security requirements in procurement contracts, and monitor supplier compliance on an ongoing basis.
For organisations that rely on cloud infrastructure, SaaS platforms, or outsourced IT services — which means virtually all organisations in scope — this creates a programme of third-party risk management that goes beyond the typical vendor assessment questionnaire. We design supply chain security programmes that are proportionate to the organisation’s supply chain complexity, integrated with their existing procurement processes, and capable of producing the documentation that NIS2 supervisors will expect.
Board Accountability and Director Liability Under NIS2
NIS2 creates direct and personal liability for board-level executives in a way that prior cybersecurity regulation did not. Management bodies of essential and important entities must approve the cybersecurity risk management measures, oversee their implementation, and be held accountable for non-compliance. Crucially, NIS2 allows member states to hold individual board members personally liable for infringements resulting from failures in cybersecurity governance — a significant departure from the position under the original NIS Directive.
This personal liability exposure makes board-level cybersecurity governance a boardroom agenda item rather than an IT department concern. We advise boards of directors on their NIS2 obligations, facilitate board training on cybersecurity governance requirements, and help establish the governance structures — board-level cybersecurity committee or equivalent — that document the organisation’s compliance with this obligation. The intersection with director liability under company law adds a further dimension to the personal risk profile of board members in organisations that are NIS2-obligated.
Real results in NIS2 compliance
We discovered we qualified as an important entity under NIS2 through a supplier's compliance questionnaire — we had not assessed our own status. BMC completed the scope analysis and gap assessment in four weeks. Three months later, we had a board-approved compliance plan, a tested incident notification protocol, and a clear picture of our supply chain risks. We are on track well before the Spanish transposition deadline.
Experienced team with local insight and international reach
What our NIS2 compliance service includes
NIS2 Scope Assessment
Legal and technical analysis to determine whether the organisation is an essential or important entity, including the impact of supply chain relationships with already-classified entities.
Gap Analysis and Compliance Plan
Assessment of current cybersecurity controls against the Article 21 requirements, with a risk-prioritised remediation plan and realistic implementation timeline.
Governance Framework and Board Accountability
Implementation of the cybersecurity governance framework required by NIS2, including board training, documented governance accountability, and management review processes.
Incident Notification Protocol
Design, implementation, and tabletop testing of the NIS2 incident notification protocol: 24-hour early warning, 72-hour initial report, and one-month final report to the supervisory authority.
Supply Chain Security Management
Critical supplier risk assessment, security clause integration in procurement contracts, and a continuous monitoring programme for supply chain cybersecurity risks.
Results that speak for themselves
Commercial debt portfolio recovery
92% portfolio recovery in 4 months, with out-of-court settlements in 78% of cases.
Comprehensive employment defense for industrial multinational
100% favorable outcomes: 5 advantageous conciliation agreements and 3 fully upheld court rulings.
GDPR compliance programme for a hospital group: from investigation to full compliance
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Reference guides
Post-Brexit: your British company operating in Spain with the right structure
post-Brexit advisory for UK companies operating in Spain: entity structuring, customs and VAT, work permits for British nationals, UK-Spain tax treaty optimisation and data protection compliance.
View guideComprehensive legal services for businesses
Comprehensive legal advisory for businesses: commercial, employment, contracts, regulatory compliance, and dispute resolution. A dedicated legal team to protect your company.
View guideBuy property in Spain with confidence — and without the horror stories
Buying property in Spain as a non-resident involves legal checks, tax obligations, and title risks that many buyers discover too late. BMC protects your investment from offer to deed.
View guideThe collective agreement that governs your workforce: understand it and negotiate from strength
How collective agreements work in Spain: hierarchy of agreements, company-level vs sector agreements, ultra-actividad, inaplicacion (opt-out), and negotiation strategy for employers after the 2021 labour reform.
View guideYour commercial lease agreement: get the clauses right before you sign
Expert legal guidance on commercial lease agreements in Spain under the LAU: key clauses, rent reviews, subleasing, termination rights, VAT implications and tenant and landlord protections.
View guideCorporate lawyer for construction: protect your contracts and your rights
Corporate legal advisory for construction companies and developers in Spain: construction contracts, UTEs, joint ventures, interim valuation disputes, claims for defects, and debt recovery.
View guideAnalysis and perspectives
Frequently asked questions about NIS2 compliance in Spain
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
NIS2 Compliance
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Cybersecurity Audit
Security posture assessment, compliance audits (ENS, ISO 27001, NIS2), vulnerability assessment, penetration testing management, and third-party risk evaluation.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másDORA Compliance (Digital Operational Resilience)
Full implementation of the DORA framework (Regulation 2022/2554) for financial entities: ICT risk management, incident reporting, resilience testing, and ICT third-party risk.
Saber másCybersecurity Incident Response
Incident response plans, tabletop exercises, breach containment, forensic investigation coordination, and regulatory notifications to AEPD and NIS2 supervisory authorities.
Saber másISO 27001 Certification
Information Security Management System implementation and ISO 27001:2022 certification: from gap analysis and Statement of Applicability through the certification audit.
Saber másVirtual CISO
Outsourced Chief Information Security Officer for SMEs: strategic cybersecurity leadership, governance, and regulatory compliance without the cost of a full-time executive.
Saber másKey terms
CISO (Chief Information Security Officer)
A Chief Information Security Officer (CISO) is the senior executive responsible for an…
Read definitionDORA (Digital Operational Resilience Act)
DORA (Regulation EU 2022/2554) is the EU's regulatory framework requiring financial sector entities…
Read definitionISO 27001 (Information Security Management System)
ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems…
Read definitionNIS2 Directive
The Network and Information Security Directive 2 (NIS2 — Directive 2022/2555/EU) is the EU's updated…
Read definitionRansomware & Cyber Threats
A type of malicious software that encrypts an organisation's files or systems and demands a ransom…
Read definition