Back to glossary

NIS2

7 min read

NIS2 is Directive (EU) 2022/2555, the European Union’s network and information security directive, which sets baseline cybersecurity and incident reporting duties for essential and important entities across a wide list of sectors. Being a directive, it obliges through each member state’s national transposition rather than directly.

July 29, 2026
Compartir:

How it works

NIS2 replaced the original network and information security directive and widened it substantially, in scope, in sectors and in consequences. Three things determine whether it applies to you: your sector, your size, and whether a member state has designated you specifically.

The directive lists sectors of high criticality and other critical sectors, covering energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, information and communications technology service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of certain products, digital providers and research. Entities are then classified as essential or important, largely by sector and size, and the two classes face the same obligations with different supervision: essential entities are supervised proactively, important entities mainly after something happens.

Article 21 sets the risk management measures, and it reads as a list of security fundamentals rather than a technical standard: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition, development and maintenance, policies to assess the effectiveness of the measures, basic cyber hygiene and training, cryptography, human resources security and access control, and multi-factor or continuous authentication together with secured communications.

Article 23 sets the reporting timetable, and it is the part that most often surprises people: an early warning within twenty-four hours of becoming aware of a significant incident, an incident notification within seventy-two hours, and a final report within one month. Article 20 makes management bodies responsible for approving and overseeing the measures and requires them to be trained, which is the clause that changes who attends the meeting.

What goes wrong

The first failure is scoping by intuition. Organisations conclude they are out of scope because they are not obviously critical infrastructure, when the sector list includes manufacturing, food, waste, postal services and managed service providers. The determination is a legal exercise against the national transposition, and it should be documented once with the reasoning, because supervisors ask how the conclusion was reached.

The second is supply chain. Article 21 requires security in supplier relationships, which means an entity in scope pushes obligations to suppliers who are not themselves in scope. In practice that is how NIS2 spreads across the economy, and it is why organisations that are out of scope still receive questionnaires and contract clauses.

The third is the twenty-four hour clock. It starts when you become aware, and awareness is not a neutral concept: an organisation with no detection capability becomes aware late, which is convenient right up to the point where a supervisor asks how long the intruder had been present. The practical consequence is that a reporting duty implies a detection duty, and it is the reason monitoring investment can be justified in regulatory terms rather than technical ones.

The fourth is treating it as a documentation exercise. The directive requires policies to assess the effectiveness of the measures, which means evidence that controls work, not evidence that controls exist. That is where testing enters: an inventory of controls is not evidence of effectiveness, and a supervisor is entitled to ask for the difference.

NIS2, DORA and the ENS

Spanish organisations frequently fall under more than one of these and are told, by three different suppliers, that each one is the priority. They overlap in substance and differ in law.

NIS2 DORA ENS
Instrument EU directive, transposed nationally EU regulation, directly applicable Spanish royal decree
Who it binds Essential and important entities, many sectors Financial entities and their ICT providers Public sector and its suppliers
Testing required Effectiveness must be assessed Testing programme, and threat-led testing for some entities Testing according to the system’s category
Incident reporting 24 hours, 72 hours, one month Its own timetable, to financial authorities Through the national channel
Governing body duty Explicit, with training Explicit and detailed Through the security policy
Where it bites Supply chain clauses, supervision Third-party ICT risk, resilience testing Certification or declaration by category

The practical guidance for an organisation in more than one: build one control set and map it three ways. The measures overlap heavily, the evidence is largely reusable, and the differences are in reporting channels, timetables and who supervises. Running three separate programmes is the most common and most expensive mistake here. DORA is the strictest on testing, so where it applies it tends to set the bar for the others.

Common mistakes

Assuming you are out of scope without checking the national transposition. The sector list is broader than most people expect, and the determination happens in national law.

Treating it as a paperwork project. Effectiveness has to be assessed, which means measurement.

Ignoring the supply chain clause until a customer sends the questionnaire. By then the answers are contractual commitments made under time pressure.

Planning the reporting timetable without a detection capability. The clock starts at awareness, and awareness requires monitoring.

Leaving the management body out of it. The directive puts the duty on them explicitly, including training, and a supervisor will look for evidence of both.

How to prepare

Determine scope formally, in writing, against the national transposition that applies to you, and record the reasoning. Do the same for each entity in a group, because scope is determined per entity and groups frequently contain both in-scope and out-of-scope companies.

Map Article 21 onto controls you already have. Most organisations with a functioning ISMS are further along than they think, since the measures track familiar ground. An ISO 27001 control set is a reasonable starting map, provided you do not claim the certificate answers the directive by itself.

Fix the incident process against the actual clock. Who decides an incident is significant, who notifies, through which national channel, and what is available within twenty-four hours. Rehearse it, because the first attempt at a twenty-four hour notification during a real incident is not the moment to discover who has the credentials for the reporting portal.

Then generate the effectiveness evidence deliberately: testing, exercises, and a record of what was found and what changed. A penetration test report with a remediation record attached is exactly the kind of artefact this asks for, and it is much easier to produce continuously than retroactively.

Push the requirements to suppliers with the same seriousness as you would want them pushed to you, and keep the evidence you receive, because your own supervision will ask about it.

Where this shows up in an audit

Supervisors and customers ask a consistent set of questions: how scope was determined, what the measures are, how their effectiveness is assessed, what happened in the last incident and how quickly it was reported, and how supplier risk is managed.

The evidence that answers the effectiveness question is testing with a remediation trail: what was tested, when, by whom, what was found, what was fixed, and what the retest showed. We structure reports so that record can be assembled without additional work, because clients otherwise reconstruct it from email months later.

We do not advise on legal scope or on notification duties, and we say so. What we provide is the technical evidence: the test, the findings, the severity reasoning and the retest result, in a form a supervisor or a customer’s audit team can read.

Building the control set and the evidence that goes with it is closely tied to the certification work an information security management system requires, which is where most of the overlapping obligations get satisfied at once.

FAQ

Does NIS2 apply to my company? It depends on your sector, your size and your national transposition, and the sector list is wider than most people assume. It is a legal determination rather than a technical one, and it should be documented with its reasoning rather than assumed.

What are the reporting deadlines? Article 23 sets an early warning within twenty-four hours of awareness, an incident notification within seventy-two hours, and a final report within one month. National transpositions specify the channel and may add detail, so check the one that binds you.

What happens if we do not comply? The directive provides for supervisory measures and administrative fines, with the maximum expressed as the higher of a fixed amount or a percentage of worldwide annual turnover, and a lower band for important entities than for essential ones. The exact figures are set out in Article 34 and in each national transposition.

Is ISO 27001 enough for NIS2? It is a strong foundation and it is not a substitute. The control sets overlap heavily, and the directive adds specific reporting duties, explicit management body accountability and an obligation to assess effectiveness that a certificate alone does not evidence.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.