Since October 2024, the European Union launched the NIS2 directive (Network and Information Security 2), a regulation that significantly strengthens cybersecurity requirements for thousands of companies across the bloc. In Spain, its transposition has been completed and since July 2026 inspection and sanctions are already fully in force. Who is really affected? What do you have to do if you run an SME? We tell you in a clear and practical way.
What is the NIS2 directive?
NIS2 is the evolution of the first NIS directive from 2016. Its aim is to raise the overall level of cybersecurity in the European Union in response to the exponential increase in cyberattacks. While the original NIS focused on critical sectors such as energy, transport or banking, NIS2 extends its scope to sectors considered «essential» and «digital»: cloud services, digital service providers, public administrations, waste management, food, manufacturing, and a long list of others.
Who does it affect in Spain?
The big news is that NIS2 no longer only affects large corporations. It applies to any company with more than 50 employees or with a turnover above 10 million euros in sectors considered critical or important. This leaves micro-enterprises out, but includes a large part of the Spanish business fabric, made up mostly of SMEs.In addition, any company providing digital services (cloud, online marketplaces, search engines, social networks) is subject to it regardless of its size.
Main obligations
- Risk management: Companies must implement technical and organizational measures proportionate to the risk. This includes encryption, multi-factor authentication, ongoing employee training and incident response plans.
- Incident notification: Incidents with significant impact must be notified to the relevant CSIRT within a maximum of 24 hours (early warning) and a detailed report within 72 hours.
- Supply chain: Companies must assess the security of their suppliers and partners. Outsourcing and washing your hands of it is no longer acceptable.
- Executive liability: Boards of directors and executives are personally responsible for compliance. The «I don’t understand IT» excuse is over.
Sanctions
Sanctions can reach 2% of global annual turnover or 10 million euros, whichever is higher, for essential sectors. For important sectors, the cap is 1.4% or 7 million. In addition, executives can face personal legal liability.
What happens if I do nothing?
Non-compliance does not only bring fines. It represents a real risk of suffering a cyberattack with devastating consequences for a business: data loss, business shutdown, reputational damage and loss of customers. According to INCIBE data, 43% of cyberattacks in Spain target SMEs, and the average recovery cost is around 35,000 euros.
Practical steps to comply with NIS2
- Carry out a risk audit: Identify your critical digital assets, the potential threats and the impact of an incident.
- Strengthen your basic security: Multi-factor authentication on all access points, encrypted backups, automatic software updates.
- Train your team: Human error is still the main entry point for cyberattacks.
- Set up an incident response plan: Define who does what and how communication works when something happens.
- Document everything: The directive requires that you be able to demonstrate compliance with records and evidence.
- Review your suppliers: Make sure your cloud, hosting or software partners also comply with security standards.
Conclusion
NIS2 is not a fad or just another bureaucratic formality. It is a paradigm shift in how we understand cybersecurity in Europe. For Spanish SMEs it represents a challenge, but also an opportunity: raising the level of digital protection of your business not only keeps you out of trouble with fines, but also makes you more competitive and reliable in the eyes of customers and partners.If you need help assessing whether your company is affected by NIS2 or want to implement the necessary measures, at Atril IT we advise SMEs and the self-employed on cybersecurity and regulatory compliance. Contact us with no obligation.






