NIS2 consulting: comply with the EU cybersecurity directive
The NIS2 Directive entered into force in October 2024 and affects thousands of companies in Spain. Fines for non-compliance reach 2% of global annual turnover or €10 million. Do you know whether your company is in scope and what you need to do?
Is your company subject to NIS2?
NIS2 greatly expands the scope compared to NIS1. It no longer affects only classic critical infrastructure. It now includes sectors such as manufacturing, food, distribution, digital services, cloud providers, waste management and many more. If your company operates in one of the 18 regulated sectors and exceeds certain size thresholds, you're probably in scope. And if you're a supplier to an in-scope company, the pressure also reaches you through the supply chain.
What our NIS2 consulting includes
- Applicability analysis: we determine whether your company is in scope of NIS2 and in which category (essential or important)
- Technical gap analysis: we compare your current security posture with the requirements of NIS2 Article 21
- Organizational gap analysis: policies, procedures, incident management, supply chain
- Prioritized compliance plan: what to do, in what order and with what resources
- Documentation: security policies, asset register, incident notification procedures
- Support in the notification process before the relevant supervisory authority
Compliance process
- Applicability analysis: We determine whether your company is in scope, in which sector and under which category (essential or important).
- Full gap analysis: We assess your current situation against the 10 security measure requirements of Article 21.
- Gap report: A document with each identified gap, its risk and its impact in case of non-compliance.
- Action plan: A roadmap with tasks, owners, deadlines and resource estimates for each pending measure.
- Implementation and documentation: We support the implementation of the technical measures and draft the mandatory documentation.
Deliverables
- Applicability analysis report with legal justification
- Technical and organizational gap analysis against NIS2 Article 21
- Prioritized compliance plan with timeline and resources
- Documentation: security policy, incident management, risk analysis
- Support in the notification process before INCIBE/CCN or the supervisory authority
Who is subject to it?
- Medium and large companies in the 18 sectors regulated by NIS2
- Public administrations and public sector entities
- Digital service providers: cloud, CDN, DNS, data centers
- Manufacturing, energy, transport, health and water companies
- Supply chain of essential entities
Frequently asked questions about NIS2
Is NIS2 already in force in Spain?
The directive was due to be transposed into national law before October 2024. Spain is in the process of transposition. Although the specific national law may be pending, the directive already creates obligations for covered entities. The prudent move is to comply now.
What are the penalties for NIS2 non-compliance?
For essential entities: up to €10 million or 2% of global annual turnover, whichever is higher. For important entities: up to €7 million or 1.4% of global turnover.
How does NIS2 differ from the previous NIS1 directive?
NIS2 expands the sectoral scope, increases reporting obligations (notification within 24/72 hours), raises penalties, includes personal liability for management bodies and adds supply chain requirements.
Do we need a pentest to comply with NIS2?
NIS2 requires assessing security risks and applying appropriate technical measures. Penetration testing is one of the most solid ways to meet that obligation in a documented and verifiable way.
How long does it take to comply with NIS2?
It depends on your starting point. Companies with a solid security baseline can complete the process in 3-6 months. Organizations starting from scratch may need 12-18 months for full compliance.