NIS2 Compliance: Act Before the Regulator Does
EU Network and Information Security Directive 2 compliance: scope assessment, control implementation, incident notification protocols, and board-level security governance.
Does this apply to your business?
Has your company formally assessed whether it qualifies as an essential or important entity under NIS2?
Does your organisation have a tested incident notification protocol capable of meeting the 24-hour early warning deadline?
Has your board formally approved your cybersecurity risk management measures and received the training NIS2 requires?
Have you audited the cybersecurity risks introduced by your critical technology suppliers into your supply chain?
0 of 4 questions answered
Our NIS2 compliance implementation process
Scope assessment and classification
We determine whether your company is an essential or important entity under NIS2 criteria: sector of activity, size thresholds, and service criticality. We also assess supply chain exposure — organisations supplying essential entities may incur compliance obligations.
NIS2 gap analysis
We assess the current state of your cybersecurity controls against the Article 21 requirements: risk management, supply chain security, encryption, authentication, access control, business continuity, and incident management.
Compliance plan implementation
We implement required technical and organisational measures, draft the mandatory policies and procedures, and establish the governance framework with explicit board-level accountability as the directive requires.
Incident notification protocol
We design, document, and test the incident notification protocol for significant incidents: 24-hour early warning, 72-hour initial report, and one-month final report. We coordinate with the legal team on parallel GDPR notifications to the AEPD where personal data is affected.
The challenge
NIS2 dramatically expands the population of organisations required to meet strict cybersecurity obligations — thousands of Spanish companies that have never appeared on the regulatory radar will become essential or important entities. Fines reach EUR 10 million or 2% of global annual turnover. Board members face personal liability for governance failures. Spain's transposition is expected by June 2026, but the time to implement the required controls is now.
Our solution
We assess whether your organisation falls within NIS2's scope, implement the technical and organisational controls required by Article 21, establish the incident notification protocols the directive mandates (24-hour early warning, 72-hour initial report), and document compliance against the full NIS2 framework in preparation for inspection by the Spanish supervisory authority.
NIS2 — Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union — replaces the original NIS Directive and significantly expands the scope of mandatory cybersecurity obligations in the EU. It classifies organisations in 18 critical sectors as "essential entities" or "important entities" and requires them to implement risk management measures (Article 21), report significant incidents to national authorities within 24 hours (early warning) and 72 hours (formal report), and ensure their supply chains meet adequate security standards. In Spain, transposition into national law is expected by June 2026; competent supervisory authorities are INCIBE (Instituto Nacional de Ciberseguridad) for most private entities and CCN (Centro Criptológico Nacional) for public entities and their providers. Fines for essential entities reach EUR 10 million or 2% of global annual turnover.
Our NIS2 compliance team combines legal expertise in technology regulation with technical cybersecurity knowledge, allowing us to address both the legal scope assessment and the practical implementation of the controls the directive requires.
The Most Significant Cybersecurity Regulation in EU History
NIS2 is not an incremental update to the original NIS Directive. It is a fundamental rewrite that transforms cybersecurity from a technical concern into a board-level governance obligation — with personal liability for directors, fines comparable to GDPR, and a scope that reaches across 18 critical sectors and their supply chains. The Spanish transposition expected in June 2026 will bring these obligations into domestic law, but the prudent response is to begin implementation now rather than wait for the law to take formal effect.
Scope: Broader Than Most Companies Expect
The most common source of NIS2 surprises is scope. Companies that do not consider themselves operators of critical infrastructure in the traditional sense — logistics platforms, cloud service providers, food manufacturers, medical device companies — are captured by the directive’s expanded sector list. Supply chain exposure adds another layer: organisations supplying services to essential entities may be required by those entities to demonstrate NIS2-equivalent compliance as a condition of their contracts, well before any Spanish supervisory authority comes calling.
Our scope assessment is a formal legal and technical analysis, not a checklist exercise. It produces a documented conclusion that can be presented to the board, to customers, and to regulators.
Article 21: What Controls Are Actually Required
The gap analysis against Article 21’s requirements is typically where organisations discover the most work. Most have some form of cybersecurity controls, but NIS2’s requirements go substantially further: a formally documented and board-approved risk management framework, a supply chain security programme with contractual teeth, multi-factor authentication and encryption deployed across all critical systems, and — critically — a tested incident notification protocol that can actually deliver a 24-hour early warning to the supervisory authority, not just in theory.
For organisations simultaneously pursuing ISO 27001 certification, we structure the NIS2 compliance project to maximise overlap between the two frameworks, avoiding duplication of effort while ensuring that the specific NIS2 requirements not covered by the standard — board accountability documentation, incident notification timelines, supply chain clauses — are addressed in full.
The Incident Notification Requirement
NIS2’s incident notification obligations are operationally demanding. An early warning must reach the supervisory authority within 24 hours of detecting a significant incident — before full analysis, before root cause determination, and often before the incident is fully contained. The 72-hour initial report requires more substance, and the one-month final report requires a comprehensive account of impact, cause, and remediation.
For incidents affecting personal data, these timelines run in parallel with the GDPR’s 72-hour notification window to the AEPD. Our data protection and NIS2 teams coordinate these notifications jointly, ensuring that the information provided to different authorities is consistent and that neither deadline is missed in the urgency of the other.
Real results in NIS2 compliance
We discovered we qualified as an important entity under NIS2 through a supplier's compliance questionnaire — we had not assessed our own status. BMC completed the scope analysis and gap assessment in four weeks. Three months later, we had a board-approved compliance plan, a tested incident notification protocol, and a clear picture of our supply chain risks. We are on track well before the Spanish transposition deadline.
Experienced team with local insight and international reach
What our NIS2 compliance service includes
NIS2 Scope Assessment
Legal and technical analysis to determine whether the organisation is an essential or important entity, including the impact of supply chain relationships with already-classified entities.
Gap Analysis and Compliance Plan
Assessment of current cybersecurity controls against the Article 21 requirements, with a risk-prioritised remediation plan and realistic implementation timeline.
Governance Framework and Board Accountability
Implementation of the cybersecurity governance framework required by NIS2, including board training, documented governance accountability, and management review processes.
Incident Notification Protocol
Design, implementation, and tabletop testing of the NIS2 incident notification protocol: 24-hour early warning, 72-hour initial report, and one-month final report to the supervisory authority.
Supply Chain Security Management
Critical supplier risk assessment, security clause integration in procurement contracts, and a continuous monitoring programme for supply chain cybersecurity risks.
Results that speak for themselves
Commercial debt portfolio recovery
92% portfolio recovery in 4 months, with out-of-court settlements in 78% of cases.
Comprehensive employment defense for industrial multinational
100% favorable outcomes: 5 advantageous conciliation agreements and 3 fully upheld court rulings.
GDPR compliance programme for a hospital group: from investigation to full compliance
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Analysis and perspectives
Frequently asked questions about NIS2 compliance in Spain
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
NIS2 Compliance
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Cybersecurity Audit
Security posture assessment, compliance audits (ENS, ISO 27001, NIS2), vulnerability assessment, penetration testing management, and third-party risk evaluation.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másDORA Compliance (Digital Operational Resilience)
Full implementation of the DORA framework (Regulation 2022/2554) for financial entities: ICT risk management, incident reporting, resilience testing, and ICT third-party risk.
Saber másCybersecurity Incident Response
Incident response plans, tabletop exercises, breach containment, forensic investigation coordination, and regulatory notifications to AEPD and NIS2 supervisory authorities.
Saber másISO 27001 Certification
Information Security Management System implementation and ISO 27001:2022 certification: from gap analysis and Statement of Applicability through the certification audit.
Saber másVirtual CISO
Outsourced Chief Information Security Officer for SMEs: strategic cybersecurity leadership, governance, and regulatory compliance without the cost of a full-time executive.
Saber másKey terms
CISO (Chief Information Security Officer)
A Chief Information Security Officer (CISO) is the senior executive responsible for an…
Read definitionDORA (Digital Operational Resilience Act)
DORA (Regulation EU 2022/2554) is the EU's regulatory framework requiring financial sector entities…
Read definitionISO 27001 (Information Security Management System)
ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems…
Read definitionNIS2 Directive
The Network and Information Security Directive 2 (NIS2 — Directive 2022/2555/EU) is the EU's updated…
Read definitionRansomware & Cyber Threats
A type of malicious software that encrypts an organisation's files or systems and demands a ransom…
Read definition