NIS2 Directive fines and penalties in Spain (2025)
By the QuantumSec team
The NIS2 Directive is not just another bureaucratic requirement. It carries a sanctioning regime that, in the most serious cases, can mean fines of up to 10 million euros or 2% of global annual turnover. This guide explains who can be sanctioned, how fines are calculated and what steps you can take right now to reduce your exposure.
Who does NIS2 apply to?
NIS2 significantly extends the scope of its predecessor. It applies to entities in critical sectors — energy, transport, banking, financial market infrastructure, healthcare, water, digital infrastructure, public administration, space — and in important sectors — postal services, waste management, manufacturing, food, digital providers.
The most relevant change from NIS1: size matters. It applies to medium-sized companies (>50 employees or >€10M turnover) and large companies in the sectors mentioned. But some entities — regardless of size — are included if they are critical providers of infrastructure or qualified trust services.
If you're unsure whether your company falls within scope, the first step is to run the correct scoping analysis.
NIS2 fines: how much they can cost you
NIS2 sets two levels of sanctions depending on the type of entity:
Essential entities (critical sectors):
• Fines of up to €10,000,000 or 2% of total global annual turnover from the previous financial year, whichever is higher.
Important entities (important sectors):
• Fines of up to €7,000,000 or 1.4% of total global annual turnover from the previous financial year, whichever is higher.
These figures are the maximum limits — not a fixed amount — and supervisory authorities have discretion to calculate the specific sanction based on severity, recurrence, impact and the entity's cooperation.
In Spain, supervisory functions are assigned to the CCN (public sector), the Secretary of State for Telecommunications and Digital Infrastructure, and the CNMC, depending on the sector.
Beyond the fine: personal liability for executives
This is the aspect that most surprises boards of directors: NIS2 explicitly introduces personal liability for management bodies.
Articles 20 and 32 of NIS2 require management bodies to approve and oversee cybersecurity risk management measures. In cases of serious non-compliance, responsible executives can face temporary bans from holding management functions — similar to what already exists in financial regulation.
This makes cybersecurity a matter of personal liability for the CEO and CISO, not just an IT department problem.
Specific NIS2 obligations you must meet
To avoid sanctions, NIS2 requires technical and organisational measures proportionate to the risks. The most important ones:
- Information security policies and risk management.
- Incident management: detection, response and notification within 72 hours to the competent authority (early warning within 24 hours).
- Business continuity: contingency plans and crisis management.
- Supply chain security: assessing and managing the risks of your technology providers.
- Multi-factor authentication (MFA) and encrypted communications.
- Cybersecurity training and awareness for staff.
- Regular penetration testing and security assessments.
How to reduce your exposure right now
NIS2 compliance isn't a one-off project: it's an ongoing programme. But there are concrete steps you can start this week:
1. Determine if you're in scope: sector, size and whether you're a provider of critical services.
2. Run a gap analysis: compare your current situation against NIS2 requirements. Identify the most relevant gaps.
3. Implement basic technical measures: MFA, encryption, security logs, patch management.
4. Document your security policies and your incident notification procedure.
5. Run a penetration test: independent technical assessment is one of the strongest pieces of evidence in a regulatory inspection.
6. Train your leadership team: they need to be aware of their responsibilities and the sanctioning regime.
FAQ
When does NIS2 come into force in Spain?
NIS2 should have been transposed into Spanish law before 17 October 2024. Spain is in the process of transposition, behind the European deadline. However, the transposition delay doesn't eliminate regulatory exposure: the Directive has direct effect in many of its aspects and companies should act now.
What happens if my company suffered a cyberattack and didn't notify it within 72 hours?
Failure to notify within the deadline is a specific infringement under NIS2, sanctionable independently of the incident itself. The obligation is to notify the competent authority within 72 hours (with early warning within 24 hours) even if the full analysis isn't finished. Regulatory silence after a serious incident makes the situation worse and can lead to additional sanctions.
Does NIS2 affect SMBs?
Micro-enterprises (<10 employees, <€2M turnover) and small companies (<50 employees, <€10M turnover) are generally excluded, unless they operate in essential sectors or are critical infrastructure providers. If your SMB is a technology provider to a large company subject to NIS2, you'll likely need to demonstrate your compliance as part of the supply chain.
Does penetration testing help with NIS2 compliance?
Yes. NIS2 requires "periodic assessments of the effectiveness of risk management measures". An independent pentest is the strongest technical evidence you can present in a regulatory audit. Documenting that you run regular penetration tests and act on the findings demonstrates an active security programme, not just a statement of intent.