How to comply with the NIS2 Directive: a practical guide

By the QuantumSec team

The NIS2 Directive (Network and Information Security 2) took effect in October 2024 and requires thousands of companies in Spain to implement technical and organizational cybersecurity measures. If you're not sure whether it applies to you or where to start, this guide has the answers.

First step: does NIS2 apply to you?

NIS2 covers companies in 18 regulated sectors that exceed certain size thresholds (medium and large enterprises). Sectors include energy, transport, health, water, digital infrastructure, ICT, manufacturing, food and postal services, among others. If your company operates in one of these sectors, the first step is confirming whether you're an "essential entity" or an "important entity", since obligations and penalties differ.

The ten requirements of Article 21

Article 21 of NIS2 defines the mandatory security measures: (1) risk management, (2) incident response, (3) business continuity, (4) supply chain security, (5) secure acquisition and development, (6) vulnerability management, (7) training and awareness, (8) cryptography, (9) access control and authentication, and (10) communications security.

Incident notification: the deadlines you can't ignore

NIS2 imposes strict deadlines for notifying significant incidents to the supervisory authority: an early warning within 24 hours, a full notification within 72 hours, and a final report within 30 days. Missing these deadlines can compound the penalties.

Accountability of management bodies

One of the most significant changes under NIS2 is that management bodies can be held personally liable if they fail to implement the required measures. This includes boards of directors, executive boards and anyone with management functions.

Where to start: the gap analysis

The first practical step is a gap analysis comparing your current situation against NIS2 requirements. The result gives you a clear map of what you have, what's missing and what's a priority. It's the foundation of any serious compliance plan.

FAQ

Is NIS2 already mandatory in Spain even though the directive hasn't been transposed yet?

The directive creates obligations from the date it took effect (October 2024), even though the specific national law may still be pending. In any case, the regulatory trend is clear, and complying now is the prudent decision to avoid retroactive penalties.

Are SMBs required to comply with NIS2?

NIS2 mainly applies to medium and large companies (more than 50 employees or over €10M in turnover). However, microenterprises and SMBs providing services in the regulated sectors can be included in specific cases.