NIS2 for technical teams · Compliance and incidents | SIXE
Compliance NIS2
DIRECTIVE (EU) 2022/2555 · APPLICABLE SINCE OCT 2024

NIS2 for technical teams

Technical consulting on the European cybersecurity directive. We audit your compliance against Article 21 and prepare you for the competent authority's inspection.

NIS2 applies to medium and large entities (≥50 employees or ≥€10M turnover) in 18 essential and important sectors. Responsibility sits with senior management and fines reach €10M or 2% of worldwide turnover.

01 · What it is

What NIS2 is.

Directive (EU) 2022/2555 is the second European law on the security of network and information systems. It replaces the 2016 NIS1 and has been applicable across all Member States since 18 October 2024, with or without national transposition. In Spain, the draft Law on Coordination and Governance of Cybersecurity is still going through Parliament; the obligations are already enforceable and the European Commission has opened infringement proceedings.

Its logic: it identifies 18 critical sectors (Annexes I and II), classifies entities as essential or important, and imposes the same set of technical and governance measures on both. The difference between essential and important lies in the supervisory regime and the maximum sanctions, not in the technical obligations.

It binds the entity, but also its management body: directors approve the measures, receive cybersecurity training and can be temporarily banned from managerial functions in the event of serious non-compliance.

02 · Who it applies to and since when

Four milestones on the NIS2 calendar.

The Directive is already enforceable. These are the milestones that mark when each obligation kicks in, and where Spain currently stands.

16 Jan 2023

Entry into force

Directive (EU) 2022/2555 enters into force, 20 days after publication in the OJ. From here on, the transposition clock is running.

17 Oct 2024

End of transposition

Deadline for Member States to bring NIS2 into national law. The Commission has opened infringement proceedings against those that missed it.

18 Oct 2024

Applicable across the EU

Article 21 measures, Article 23 notification and Article 34 sanctions are enforceable from this day, with or without national law.

Spain · pending

Cybersecurity Law

The draft Bill is still in Parliament. National law will clarify details but will not lower the European obligations.

Who is bound. NIS2 covers medium and large entities (≥50 employees or ≥€10M turnover) in 18 sectors. Essential (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space. Important (Annex II): postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research. Technical obligations are identical; only the supervisory regime and maximum sanctions differ.

03 · How we work

Three technical phases up to inspection day.

The same package we apply to the other frameworks, with a certified lead auditor on every phase. Built on your systems, your policies and your team, not on a template.

1
Assessment

Applicability and maturity

We confirm whether your entity is in NIS2 scope (sector + size), whether you are essential or important, and how mature you currently are against Article 21. An honest baseline.

2
Gap analysis

What's missing against Article 21

Each of the ten Article 21 measures assessed against your processes and infrastructure. Findings prioritised by risk and effort, with a roadmap your team can actually execute.

3
Pre-audit

Inspection dry-run

A lead auditor walks through the measures, the evidence and the incident-reporting procedure using the same criteria the competent authority will apply. Non-conformities surface now, not on inspection day.

SIXE is a technical consultancy. Legal interpretation of the Directive and of the forthcoming Spanish law belongs to your in-house legal team or to a specialised law firm. We take on the technical and operational side: applicability, Article 21 controls, evidence and incident notification. NIS2 is not a certifiable standard — the supervisor is the competent authority (INCIBE-CERT or CCN-CERT in Spain, or the authority designated by the future law).

04 · Article 21

The ten Article 21 measures.

NIS2 requires appropriate and proportionate technical, operational and organisational measures. Article 21 spells out ten minimum areas every entity in scope must cover and be able to prove during an inspection.

Art. 21.2(a) · Risk

Risk analysis and security policy

Regular cybersecurity risk analysis and an information security policy approved by management, reviewed after incidents or major changes.

Art. 21.2(b) · Incidents

Incident handling

Detection, response and lessons learned. Covers playbooks, centralised telemetry (SIEM/XDR) and the procedure to meet the Article 23 deadlines (24/72h + final report).

Art. 21.2(c) · Continuity

Business continuity

Backups, disaster recovery and crisis management. Tested: if you haven't rehearsed the restore, it doesn't exist.

Art. 21.2(d) · Supply chain

Supply-chain security

Inventory of critical ICT suppliers, assessment of their security posture and contractual clauses on incident notification and audit rights.

Art. 21.2(e) · Acquisition

Acquisition, development, maintenance

Security in the procurement, development and maintenance of network and information systems. Vulnerability management with patching SLAs and coordinated disclosure.

Art. 21.2(f) · Effectiveness

Assessing effectiveness

Policies and procedures to measure whether the measures actually work. Metrics, indicators and periodic internal audits.

Art. 21.2(g) · Training

Cyber hygiene and training

Mandatory training for staff and management. Documented and reviewed basic cyber-hygiene practices.

Art. 21.2(h) · Cryptography

Cryptography and encryption

Policies on the use of cryptography and, where appropriate, encryption: data in transit, at rest and on devices.

Art. 21.2(i) · Access

HR, access control and assets

Security during onboarding and off-boarding, least-privilege principle, identity management and asset management with an assigned owner.

Art. 21.2(j) · MFA

MFA and secure communications

Multi-factor or continuous authentication for privileged and remote access, secure voice, video and text communications, and secure emergency communication systems within the entity.

Art. 23 · Incident reporting

The clock starts the moment you detect a significant incident.

Without centralised telemetry (SIEM/XDR) and a rehearsed response procedure, these deadlines don't hold. In the pre-audit we measure them in a real dry-run.

24h
Early warning

Notify the competent authority of the initial suspicion and any potential cross-border impact.

72h
Notification

Initial assessment, severity, indicators of compromise and containment measures adopted.

1mo
Final report

Detailed description, root cause, mitigation applied and residual cross-border impact.

05 · It doesn't go alone

NIS2, ISO 27001 and the ENS.

NIS2 does not reinvent cybersecurity. Most of its controls already lived in ISO/IEC 27001, in Spain's ENS or in NIST CSF. The difference is that they are now a direct legal obligation, with harmonised sanctions and personal accountability for management.

If you already run ISO 27001 or the ENS, a large portion of Article 21 is already covered: risk, incidents, continuity, supply chain and access control. What is usually missing are the NIS2-specific additions: 24/72h notification with technical evidence, ICT supply-chain security clauses and mandatory training for the management body. A proper mapping saves half the work.

If you don't have a baseline yet, consider closing ISO 27001 as the backbone of the cybersecurity programme: the same controls serve NIS2, tenders and due diligence. One project, three fronts covered.

06 · Frequently asked questions

NIS2, in plain English.

What exactly is NIS2?
NIS2 is Directive (EU) 2022/2555 on the security of network and information systems. It replaces the 2016 NIS1 with tougher cybersecurity obligations, harmonised sanctions across the EU and personal accountability for management. It has been applicable throughout the EU since 18 October 2024.
Who does NIS2 apply to?
Medium and large entities (≥50 employees or ≥€10M turnover) in 18 essential sectors (energy, transport, banking, health, digital infrastructure, public administration, space) or important sectors (postal, waste, food, manufacturing, digital services, research). Authorities may include smaller entities if their activity is critical.
How long do I have to report an incident?
Article 23 requires three steps: an early warning within 24 hours, a formal notification within 72 hours, and a final report within one month of the entity becoming aware of the significant incident. The clock starts from awareness, not from when the incident occurred.
What sanctions does NIS2 provide for?
Article 34 sets fines of up to €10M or 2% of total worldwide annual turnover for essential entities, and up to €7M or 1.4% for important entities (whichever is higher). Management bodies are responsible for approving and overseeing the measures and can be temporarily banned from managerial functions in serious cases.
Do I still have to comply with NIS2 in Spain if it hasn't been transposed?
Yes. The obligations arising from NIS2 have been enforceable since 18 October 2024. The European Commission has opened infringement proceedings against Member States that failed to transpose it. The forthcoming Spanish Law on Coordination and Governance of Cybersecurity will add national detail but will not lower the substantive content.
Do ISO 27001 or the ENS help with NIS2 compliance?
They are a solid baseline and cover most Article 21 controls, but they are not automatically equivalent. You still need to map existing controls against NIS2, close what is missing (24/72h notification with technical evidence, ICT supply chain, management training) and document it.
Does SIXE certify NIS2?
NIS2 is not a certifiable standard: it is a mandatory Directive supervised by the competent authority (INCIBE-CERT and CCN-CERT in Spain, or the authority designated by the future law). SIXE prepares your organisation for that supervision with certified lead auditors, using the same criteria the authority applies.

NIS2 in scope and no idea where to start?

Tell us your sector, your size and where your cybersecurity stands today. We come back with a preliminary applicability assessment and a proposal broken down into the three phases: assessment, gap analysis against Article 21 and inspection readiness. Per-phase pricing.

+34 91 198 02 43 (EU)  ·  +1 628 900 3024 (US)  ·  Mon–Fri 8:30–16:30 (GMT+1)