Directive (EU) 2022/2555, known as NIS2, is the European law that sets the cybersecurity obligations of companies and bodies providing essential or important services. It replaces the 2016 NIS Directive, greatly widens the sectors affected and, for the first time, makes management accountable. This checklist summarises what it requires and lets you check where your organisation stands.
Guidance prepared by Jaquers Ciberseguridad from the text of the Directive. It is not legal advice: the specific obligations depend on your sector, your size and the Spanish transposition law in force, whose text and timeline you should verify with your legal advisers.
1. Does NIS2 apply to you?
NIS2 applies, as a general rule, to medium and large entities (from 50 employees or 10 million euros in turnover or balance sheet) operating in the sectors of its annexes. Annex I lists the sectors of high criticality and Annex II other critical sectors. Some entities are included regardless of size (for example, DNS service providers, domain name registries, trust service providers or entities that are the sole provider of a service in a Member State).
| Annex I · Sectors of high criticality | Annex II · Other critical sectors |
|---|---|
| Energy · Transport · Banking · Financial market infrastructures · Health · Drinking water · Waste water · Digital infrastructure · ICT service management (B2B) · Public administration · Space | Postal and courier services · Waste management · Chemicals · Food · Manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment) · Digital providers (online marketplaces, search engines, social networks) · Research |
The Directive distinguishes between essential entities (generally, the large companies of Annex I) and important entities (the rest). The substantive obligations are the same; what changes is the supervisory regime and the maximum penalties.
And we have checked whether we exceed the size thresholds or are included regardless of size.
It determines the supervisory regime and the applicable penalties.
In Spain, NIS2 is transposed through the Cybersecurity Coordination and Governance Act; check its status and final text, which may add nuances on authorities, deadlines and registration.
Entities subject to NIS2 must require security guarantees from their suppliers. If you sell to one of them, questionnaires and contractual clauses will come your way.
2. Governance: what it requires of management
Article 20 places responsibility on the management bodies: they must approve the risk management measures, oversee their implementation and can be held personally liable for breaches. They must also train in cybersecurity and encourage employee training.
With minutes or a signed document, not as a matter delegated solely to the IT department.
A dashboard or status report that management reviews at a defined cadence.
And can prove it.
With measurable results, for example through periodic phishing simulations.
3. The ten minimum measures of Article 21
Article 21 requires technical, operational and organisational measures that are "appropriate and proportionate" to the risk, based on an all-hazards approach. As a minimum they must cover these ten areas:
An up-to-date risk analysis, with a methodology, and approved policies. A periodic pentest is the most direct way to check the analysis against reality.
A procedure for detection, triage, containment, eradication, recovery and closure, with defined roles and contacts, rehearsed at least once a year.
Tested backups, disaster recovery and crisis management, with defined recovery objectives.
Risk assessment of suppliers and service providers, contractual clauses and review of third-party access.
Including vulnerability handling and disclosure: inventory, patching, testing before going to production and a channel for receiving reports.
Audits, penetration tests and metrics that show the measures work, not just that they exist.
Updates, passwords, device locking, email use and ongoing awareness for all staff.
Encryption in transit and at rest, key and certificate management.
Joiners and leavers, least privilege, periodic permission reviews and an up-to-date asset inventory.
MFA or continuous authentication where appropriate, encrypted voice, video and text, and emergency communication channels within the entity.
4. Incident notification: 24 hours, 72 hours and one month
Article 23 requires significant incidents to be reported without undue delay to the relevant CSIRT or competent authority: those that cause or may cause severe operational disruption or financial loss, or affect other people with considerable damage. The procedure has three milestones:
| Deadline | What must be sent |
|---|---|
| 24 hours from becoming aware | Early warning: whether an unlawful or malicious act is suspected and whether it could have a cross-border impact. |
| 72 hours from becoming aware | Incident notification: an update of the early warning, an initial assessment of severity and impact and any available indicators of compromise. |
| One month from the notification | Final report: a detailed description, type of threat and root cause, mitigation measures applied and, where applicable, cross-border impact. If the incident is still ongoing, a progress report and a final report once closed. |
| At the authority's request | Intermediate progress reports. |
In addition, where appropriate, the recipients of the affected services must be informed without delay and, if personal data is involved, the 72-hour notification to the AEPD required by the GDPR must be made in parallel. In Spain the reference CSIRTs are INCIBE-CERT for the private sector and citizens and CCN-CERT for the public sector.
With severity and impact criteria agreed with management.
The reference CSIRT, the competent authority, the AEPD if personal data is involved, and the contacts for our insurer and legal advisers.
During an incident nobody has time to write from scratch.
Centralised, retained logs and forensic analysis capability with chain of custody.
5. Supply chain
NIS2 requires assessing the risks introduced by suppliers and service providers, including data storage and processing services and managed security services, and taking into account the quality of their cybersecurity and secure development practices.
With each one's level of access and an internal owner.
Security clauses, incident notification, right to audit and data location.
Domains, services and certificates that a provider exposes on our behalf.
And we can prove it to customers and auditors.
6. Registration, supervision and penalties
Entities must register with the competent authority, providing their contact details, sector, the Member States in which they provide services and their IP address ranges (Article 27). Essential entities are subject to ex ante and ex post supervision (audits, inspections and information requests); important entities to ex post supervision.
Administrative fines can reach, for essential entities, 10 million euros or 2% of total worldwide annual turnover, and for important entities 7 million euros or 1.4%, whichever is higher in each case. National law may add further penalties and measures such as the temporary suspension of certifications or a temporary ban on holding management positions.
And we keep our contact details up to date.
Audit and pentest reports, training records, management minutes and continuity plan tests.
7. Relationship with ENS, ISO 27001 and DORA
If your organisation is already ISO/IEC 27001 certified or compliant with the Spanish National Security Framework (ENS), much of the ground is covered: both frameworks address risk analysis, policies, access control and incident management. NIS2 adds the personal accountability of management, the notification deadlines and the emphasis on the supply chain. Financial entities are governed by DORA, which acts as a special regime with stricter notification deadlines (4 hours for the initial notification from classifying the incident as major).
8. How Jaquers helps
Our services provide the technical evidence required by Article 21 and the response capability required by Article 23. Every finding keeps its evidence, dates, owner and status, and can be exported in PDF and Word as control evidence.
If you want to know where your organisation stands, request an initial assessment: a 30-minute conversation to understand your systems and what worries you.