NIS2 replaces the original NIS directive and multiplies the number of sectors and companies affected. Spain's transposition is running behind the original October 2024 deadline, but that doesn't change the fact that the directive is already in force at EU level, and affected companies need to prepare regardless of the exact timeline of the Spanish law.

Is your company obligated?

NIS2 classifies entities into two categories: essential (energy, transport, banking, health, water, digital infrastructure, public administration) and important (postal services, waste management, manufacturing of critical products, digital providers). Size also matters: generally, it applies to medium and large companies (more than 50 employees or over €10M in revenue) in those sectors, though there are exceptions that extend scope to smaller companies providing critical services.

What NIS2 requires in practice

ObligationWhat it involves
Risk managementA formal cybersecurity risk management policy, reviewed periodically
GovernanceSenior management must approve and oversee measures — not simply delegable to IT
Incident notificationEarly warning within 24h, full notification within 72h for significant incidents
Business continuityDocumented recovery and crisis management plans
Supply chainRisk assessment of suppliers and third parties, not just your own systems

The overlap with the AI Act

If your company uses AI systems within infrastructure considered critical under NIS2 (for example, an AI system managing the power grid or transport network traffic), that same system is very likely to also fall under the AI Act's Annex III high-risk category. In that case, NIS2's cybersecurity governance and the data governance required by AI Act Art. 10 become two layers of the same underlying obligation: demonstrating the system is secure and controlled.

Penalties: up to €10 million or 2% of global annual turnover for essential entities, whichever is higher. This isn't a minor directive compared to the AI Act or GDPR.

You can check in under 3 minutes whether your NIS2 risk profile has critical gaps with our free assessment — it includes a dedicated NIS2 cybersecurity module with applicable penalties and resources tailored to your result.

Where to start if you have nothing in place

  • Confirm whether your sector and size place you as an essential or important entity — the exact list varies by national transposition.
  • Appoint a cybersecurity officer with management-level authority, not just a technician without formal authority.
  • Document the incident notification process before one happens — improvising it within 24h is the worst way to meet the deadline.
  • Review contracts with critical suppliers: NIS2 also holds you responsible for the supply chain.