NIS2 Directive: Cybersecurity Obligations for Mid-Size Companies in Spain 2026
If your company employs more than 50 people or turns over more than €10 million and operates in one of the 18 sectors covered by NIS2, you face binding cybersecurity obligations that came into force in Spain from January 2025. This guide explains precisely what the directive requires, what sanctions apply, and how to document compliance without overwhelming your IT team — with practical help from IgeraLegal.
NIS2 DIRECTIVE: Directive (EU) 2022/2555, known as NIS2, supersedes NIS1 (2016). Transposed in Spain via Royal Decree-law amending Law 8/2011, NIS2 mandates 10 minimum cybersecurity measures, requires significant incident notification within 24 hours, and makes company management personally accountable for compliance. It brings more than 5,000 new companies in Spain into scope that were not covered by NIS1.
5,000+
"New companies brought into scope in Spain by NIS2 that were not covered by NIS1 — particularly in critical manufacturing, telecoms, B2B ICT services and waste management. The majority have not yet begun the compliance process."
— INCIBE estimate, National Cybersecurity Report 2025
Which companies does NIS2 apply to in Spain?
NIS2 distinguishes two categories of entities, each with different thresholds and sanctions:
Essential entities (Annex I): Energy (electricity, gas, oil, district heating), transport (air, rail, maritime, road), banking, financial market infrastructure, healthcare, drinking water, wastewater and digital infrastructure (IXPs, DNS, TLD registries, cloud data centres, communications networks). Also all Public Administrations.
Important entities (Annex II): Postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, critical manufacturing (medical devices, electrical equipment, machinery, motor vehicles), digital service providers (online marketplaces, search engines, social networks), and research.
The size threshold is an OR condition — not AND: exceeding either threshold (more than 50 employees or more than €10 million turnover) is sufficient to be in scope, provided the company also operates in a covered sector.
| Category | Size threshold | Maximum sanction |
|---|---|---|
| Essential entity | >250 employees OR >€50M turnover | €10M or 2% global turnover |
| Important entity | >50 employees OR >€10M turnover | €7M or 1.4% global turnover |
| Personal management liability | Both categories | Personal fines + temporary disqualification |
What are the 10 mandatory cybersecurity measures under Article 21?
Article 21 of NIS2 sets out ten minimum measures that every in-scope entity must implement and document:
Risk management and security policies
Periodic risk assessment (at least annual), a security policy approved by management, and documented allocation of cybersecurity responsibilities.
Incident management
Documented procedures for detecting, classifying, containing and recovering from cybersecurity incidents. Includes an up-to-date incident response plan.
Business continuity and disaster recovery
Tested Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP). Verified backups with defined RTO and RPO.
Supply chain security
Cybersecurity assessment of critical suppliers and partners. Inclusion of security clauses in contracts with IT providers and cloud service vendors.
Security in system acquisition and development
Security by design for new software and system projects. Penetration testing and code reviews for critical applications.
Periodic effectiveness assessments
Annual internal or external audits. Security KPIs monitored and reported to management.
Cyber hygiene and staff training
Cybersecurity training for all staff at least once a year. Role-specific awareness for employees with privileged access.
Cryptography and encryption
Documented cryptography policy. Encryption of data in transit and at rest for sensitive information. Certificate and key lifecycle management.
Access control and HR security
Principle of least privilege. Identity lifecycle management (onboarding, role changes, offboarding). Background checks for roles with critical access.
Multi-factor authentication (MFA) and secure communications
MFA mandatory for remote access, VPNs, system administration and critical applications. Encrypted communications for sensitive information exchange.
Not sure which measures you already have in place?
IgeraLegal generates a NIS2 gap analysis with your current compliance level and a prioritised action plan. Try it free for 14 days.
Try IgeraLegal free — no card requiredWhat incident notification deadlines does NIS2 require?
NIS2 establishes a three-phase escalating notification regime. Significant incidents must be reported to INCIBE (private sector) or CCN-CERT (Public Administrations) as follows:
NIS2 incident notification timeline
- 24 hours — Early warning: Notification that a significant incident has occurred. Initial description of the incident type and whether an intentional or cross-border attack is suspected. Full analysis is not yet required.
- 72 hours — Incident notification: Initial assessment of the incident, indicators of compromise (IoCs), affected systems, estimated impact and containment measures adopted.
- 1 month — Final report: Full forensic analysis, root cause identified, complete scope of impact, corrective measures implemented and preventive measures to avoid recurrence.
An incident is "significant" if it causes material disruption to service delivery, substantial financial losses for the affected entity, or if it has affected — or has the potential to affect — other natural or legal persons causing considerable material or non-material damage. The definition is deliberately broad to encourage notification.
What sanctions does NIS2 impose in Spain?
NIS2 sanctions are substantially higher than those under NIS1 and are combined with personal liability for management — a significant departure from previous cybersecurity legislation:
Essential entities: Up to €10 million or 2% of total global annual turnover for the preceding financial year, whichever is higher. The most serious infringements (failure to implement security measures, failure to notify incidents) attract the maximum sanction.
Important entities: Up to €7 million or 1.4% of total global annual turnover, whichever is higher.
Management liability: NIS2 empowers supervisory authorities to impose sanctions directly on directors and the CEO of essential entities for compliance failures. This includes personal fines and temporary disqualification from holding management positions. This is the first time a European cybersecurity directive has established explicit personal accountability at board level.
How IgeraLegal handles NIS2 compliance queries
Compliance officer's question:
"Our industrial component manufacturing company has 80 employees. Are we subject to NIS2?"
IgeraLegal answers:
"Yes. With 80 employees you exceed the 50-employee threshold, and industrial component manufacturing falls within the 'critical manufacturing' category in Annex II of the NIS2 Directive. You are an important entity (not essential, unless you also exceed €50M in turnover). You are obligated to implement the 10 measures under Art. 21, notify incidents within 24h/72h/1 month, and submit to INCIBE supervision. The maximum applicable sanction is €7M or 1.4% of global turnover. IgeraLegal can generate your gap analysis and compliance roadmap now."
Summary: NIS2 in Spain 2026
- Applies to companies with >50 employees OR >€10M turnover in 18 sectors (OR condition)
- 10 mandatory cybersecurity measures under Art. 21 NIS2
- Incident notification: 24h (early warning) + 72h (notification) + 1 month (final report)
- Sanctions: up to €10M or 2% global turnover for essential entities
- Personal management and C-suite liability — a NIS2 first
- Supervisor in Spain: INCIBE (private sector), CCN-CERT (Public Administrations)
- IgeraLegal acts as a compliance assistant: answers queries, generates checklists, helps document policies
Frequently asked questions about NIS2
Is NIS2 already in force in Spain?
Yes. The transposition deadline for member states was 17 October 2024. Spain transposed NIS2 via Royal Decree-law, entering into force in January 2025. Affected companies have been required to comply since that date, although active INCIBE supervision is being phased in progressively throughout 2025-2026.
How do I know if my company is an essential or important entity?
The distinction depends on your sector and size. Entities in Annex I sectors (energy, transport, banking, healthcare, water, digital infrastructure) are essential if they exceed 250 employees or €50M turnover — or if INCIBE designates them as essential regardless of size due to sectoral criticality. Entities in Annex II sectors are important if they exceed 50 employees or €10M. Certain entities — such as qualified trust service providers and TLD registries — are essential regardless of size.
What happens if my company fails to comply with NIS2?
INCIBE can impose administrative sanctions, require corrective measures within fixed deadlines, order security audits at the company's expense, and in serious cases suspend service delivery. For essential entities, INCIBE can also propose the temporary disqualification of directors from management roles.
Does NIS2 apply to SMEs?
Generally, microenterprises (fewer than 10 employees and less than €2M turnover) are excluded. Small companies (10-49 employees or €2-10M) are also generally excluded, with some sector-specific exceptions. However, any company in the supply chain of an in-scope entity may receive contractual cybersecurity requirements derived from that entity's supply chain management obligations (measure number 4). IgeraLegal can help you assess your indirect exposure.
How much does NIS2 compliance cost?
It depends on your starting point. A company with a reasonable existing security baseline (managed antivirus, backups, MFA on key systems) typically needs 3-6 months of work and an investment of €15,000-€50,000 for a mid-size important entity. A company with almost no existing measures may need double that. What is certain is that the cost of non-compliance — up to €7 million in sanctions — far exceeds the cost of compliance. IgeraLegal helps you prioritise the highest-impact measures first.
Where do in-scope companies register under NIS2?
In-scope entities must register with INCIBE via the NIS compliance portal. Registration includes information on sector, size, security contact details and, for essential entities, additional data on the critical infrastructure managed. The registration deadline was October 2024 — companies that have not yet registered are in breach from day one. IgeraLegal can prepare the documentation needed for your INCIBE registration.
Last updated: June 2026 | Source: Directive (EU) 2022/2555; Spanish NIS2 transposition Royal Decree-law; ENISA NIS2 Implementation Guide; INCIBE | Author: IgeraSolutions editorial team | IgeraLegal — try free for 14 days.