1. Home
  2. Resources
  3. NIS2 checklist
Resources · Practical guide

NIS2 checklist for companies operating in Spain

Whether it applies to you, what it requires of management, the ten measures of Article 21 and the notification deadlines, in a list you can review in twenty minutes.

Practical guide · Updated 2026-10-04 · Reading time: 20 minutes

Directive (EU) 2022/2555, known as NIS2, is the European law that sets the cybersecurity obligations of companies and bodies providing essential or important services. It replaces the 2016 NIS Directive, greatly widens the sectors affected and, for the first time, makes management accountable. This checklist summarises what it requires and lets you check where your organisation stands.

Guidance prepared by Jaquers Ciberseguridad from the text of the Directive. It is not legal advice: the specific obligations depend on your sector, your size and the Spanish transposition law in force, whose text and timeline you should verify with your legal advisers.

1. Does NIS2 apply to you?

NIS2 applies, as a general rule, to medium and large entities (from 50 employees or 10 million euros in turnover or balance sheet) operating in the sectors of its annexes. Annex I lists the sectors of high criticality and Annex II other critical sectors. Some entities are included regardless of size (for example, DNS service providers, domain name registries, trust service providers or entities that are the sole provider of a service in a Member State).

Annex I · Sectors of high criticalityAnnex II · Other critical sectors
Energy · Transport · Banking · Financial market infrastructures · Health · Drinking water · Waste water · Digital infrastructure · ICT service management (B2B) · Public administration · SpacePostal and courier services · Waste management · Chemicals · Food · Manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment) · Digital providers (online marketplaces, search engines, social networks) · Research

The Directive distinguishes between essential entities (generally, the large companies of Annex I) and important entities (the rest). The substantive obligations are the same; what changes is the supervisory regime and the maximum penalties.

We have identified which sector and annex our activity falls under

And we have checked whether we exceed the size thresholds or are included regardless of size.

We know whether we are an essential or an important entity

It determines the supervisory regime and the applicable penalties.

We have reviewed the Spanish transposition law

In Spain, NIS2 is transposed through the Cybersecurity Coordination and Governance Act; check its status and final text, which may add nuances on authorities, deadlines and registration.

Even if it does not apply to us directly, we know whether our customers are covered

Entities subject to NIS2 must require security guarantees from their suppliers. If you sell to one of them, questionnaires and contractual clauses will come your way.

2. Governance: what it requires of management

Article 20 places responsibility on the management bodies: they must approve the risk management measures, oversee their implementation and can be held personally liable for breaches. They must also train in cybersecurity and encourage employee training.

Management has formally approved the cybersecurity policy and measures

With minutes or a signed document, not as a matter delegated solely to the IT department.

There is an identified owner and a periodic oversight mechanism

A dashboard or status report that management reviews at a defined cadence.

Members of management have received cybersecurity training

And can prove it.

There is a training and awareness plan for the rest of the staff

With measurable results, for example through periodic phishing simulations.

3. The ten minimum measures of Article 21

Article 21 requires technical, operational and organisational measures that are "appropriate and proportionate" to the risk, based on an all-hazards approach. As a minimum they must cover these ten areas:

a) Risk analysis and information system security policies

An up-to-date risk analysis, with a methodology, and approved policies. A periodic pentest is the most direct way to check the analysis against reality.

b) Incident handling

A procedure for detection, triage, containment, eradication, recovery and closure, with defined roles and contacts, rehearsed at least once a year.

c) Business continuity

Tested backups, disaster recovery and crisis management, with defined recovery objectives.

d) Supply chain security

Risk assessment of suppliers and service providers, contractual clauses and review of third-party access.

e) Security in the acquisition, development and maintenance of systems

Including vulnerability handling and disclosure: inventory, patching, testing before going to production and a channel for receiving reports.

f) Policies and procedures to assess the effectiveness of the measures

Audits, penetration tests and metrics that show the measures work, not just that they exist.

g) Basic cyber hygiene and cybersecurity training

Updates, passwords, device locking, email use and ongoing awareness for all staff.

h) Policies on the use of cryptography and, where appropriate, encryption

Encryption in transit and at rest, key and certificate management.

i) Human resources security, access control and asset management

Joiners and leavers, least privilege, periodic permission reviews and an up-to-date asset inventory.

j) Multi-factor authentication, secure communications and emergency communications

MFA or continuous authentication where appropriate, encrypted voice, video and text, and emergency communication channels within the entity.

4. Incident notification: 24 hours, 72 hours and one month

Article 23 requires significant incidents to be reported without undue delay to the relevant CSIRT or competent authority: those that cause or may cause severe operational disruption or financial loss, or affect other people with considerable damage. The procedure has three milestones:

DeadlineWhat must be sent
24 hours from becoming awareEarly warning: whether an unlawful or malicious act is suspected and whether it could have a cross-border impact.
72 hours from becoming awareIncident notification: an update of the early warning, an initial assessment of severity and impact and any available indicators of compromise.
One month from the notificationFinal report: a detailed description, type of threat and root cause, mitigation measures applied and, where applicable, cross-border impact. If the incident is still ongoing, a progress report and a final report once closed.
At the authority's requestIntermediate progress reports.

In addition, where appropriate, the recipients of the affected services must be informed without delay and, if personal data is involved, the 72-hour notification to the AEPD required by the GDPR must be made in parallel. In Spain the reference CSIRTs are INCIBE-CERT for the private sector and citizens and CCN-CERT for the public sector.

We have defined what a significant incident means for us

With severity and impact criteria agreed with management.

We know who to notify and how

The reference CSIRT, the competent authority, the AEPD if personal data is involved, and the contacts for our insurer and legal advisers.

We have templates ready for the 24-hour early warning, the 72-hour notification and the final report

During an incident nobody has time to write from scratch.

We can reconstruct what happened with evidence

Centralised, retained logs and forensic analysis capability with chain of custody.

5. Supply chain

NIS2 requires assessing the risks introduced by suppliers and service providers, including data storage and processing services and managed security services, and taking into account the quality of their cybersecurity and secure development practices.

We have an inventory of suppliers with access to our systems or data

With each one's level of access and an internal owner.

We require security guarantees in contracts

Security clauses, incident notification, right to audit and data location.

We monitor our attack surface, including the part that depends on third parties

Domains, services and certificates that a provider exposes on our behalf.

We know where our data is hosted and processed

And we can prove it to customers and auditors.

6. Registration, supervision and penalties

Entities must register with the competent authority, providing their contact details, sector, the Member States in which they provide services and their IP address ranges (Article 27). Essential entities are subject to ex ante and ex post supervision (audits, inspections and information requests); important entities to ex post supervision.

Administrative fines can reach, for essential entities, 10 million euros or 2% of total worldwide annual turnover, and for important entities 7 million euros or 1.4%, whichever is higher in each case. National law may add further penalties and measures such as the temporary suspension of certifications or a temporary ban on holding management positions.

We have completed or planned registration with the competent authority

And we keep our contact details up to date.

We keep evidence of the measures applied

Audit and pentest reports, training records, management minutes and continuity plan tests.

7. Relationship with ENS, ISO 27001 and DORA

If your organisation is already ISO/IEC 27001 certified or compliant with the Spanish National Security Framework (ENS), much of the ground is covered: both frameworks address risk analysis, policies, access control and incident management. NIS2 adds the personal accountability of management, the notification deadlines and the emphasis on the supply chain. Financial entities are governed by DORA, which acts as a special regime with stricter notification deadlines (4 hours for the initial notification from classifying the incident as major).

8. How Jaquers helps

Our services provide the technical evidence required by Article 21 and the response capability required by Article 23. Every finding keeps its evidence, dates, owner and status, and can be exported in PDF and Word as control evidence.

If you want to know where your organisation stands, request an initial assessment: a 30-minute conversation to understand your systems and what worries you.

Talk to usCall