Back to Blog

NIS2 in Spain: the law is not here yet, your customer's questionnaire is

The law is not here. The questionnaire is
NIS2 in Spain, as of 29 July 2026

On 8 July, the European Commission decided to refer Spain to the Court of Justice of the EU for failing to transpose NIS2, and to ask for a lump-sum fine and a daily one while it is at it. It is worth saying out loud what that means: as of today, 29 July 2026, the Spanish law transposing NIS2 has not been published in the official gazette. And even so, NIS2 is already deciding contracts. For most mid-sized companies in this country, this regulation will not arrive as an inspector: it will arrive as a security questionnaire sent by your largest customer's procurement department, with a short turnaround.

Where the law actually is

Directive (EU) 2022/2555, which everybody calls NIS2, set 17 October 2024 in its Article 41 as the deadline for member states to bring it into national law. Spain missed it. The chosen instrument is the Cybersecurity Coordination and Governance Act, whose draft the Council of Ministers approved at first reading on 14 January 2025 — and there it remains: to this day it has not reached parliament as a bill. The European case file, meanwhile, has run through its three stages: letter of formal notice on 28 November 2024, reasoned opinion on 7 May 2025 and, this month, referral to the Court of Justice alongside Ireland, France and the Netherlands, with a request for a lump sum and daily penalty payments until full transposition is notified.

In the meantime, what is in force in Spain remains Royal Decree-Law 12/2018, the transposition of the original NIS, with supervision split between INCIBE-CERT and the CCN. Nobody knows when the new one will land. What is worth assuming is what the analyses of the process anticipate: that there will be no long transitional period and that it will come into force practically on publication. Translated into a work calendar: the day it appears in the gazette is not the day your compliance project starts, it is the day your obligation does.

Contradictory timelines are doing the rounds on all this, with dates and adaptation windows we have not been able to verify in any official source. We only assert what can be checked, and what can be checked is this: the law is not in the gazette. If somebody puts a deadline on the table in front of you, ask them for the reference number of the provision. It is a polite question and it tidies up the conversation considerably.

What already applies today, without waiting for anyone

There is one piece of this regulation that needs no transposition, because it is a regulation and not a directive: Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, published in the Official Journal the following day. It fleshes out the technical and methodological requirements of the measures in Article 21(2) of NIS2 and spells out when an incident counts as significant. And it does so for a very specific list of recipients: DNS service providers, top-level domain name registries, cloud computing providers, data centre service providers, content delivery networks, managed service providers and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers.

Translated: if you make a living administering other people's infrastructure — or watching over it — there is an annex there with your name on it. We are exactly one of the provider types that regulation names, and we do not mind: it is one of the few parts of this whole business that can be brought down to a table of concrete controls rather than a statement of intent. A European text spelling out exactly what a managed service provider has to document is more useful than twenty articles of principles.

Why it reaches you anyway, even if you are not an "essential entity"

The direct scope of NIS2 is usually summed up in two strokes: operating in one of the sectors in its annexes — energy, transport, banking, health, water, digital infrastructure, public administration, plus a list of "important" sectors covering manufacturing, food, postal services or digital providers — and passing the threshold of 50 employees or 10 million euros in turnover or balance sheet. There is a third stroke that gets told less often: Article 2 pulls in a list of entities whatever their size, among them electronic communications operators, trust service providers, domain name registries and anyone who is the sole provider of a critical service in a member state. Even so, plenty of mid-sized companies run the numbers, see they fit no annex, and close the file. That is exactly where they get it wrong.

Because Article 21 requires the entities that are in scope to manage the risks of their supply chain, including the security of their direct suppliers. An obligation like that does not stay put: it is passed down by contract. The customer who is in scope cannot audit the law on your behalf, but they can absolutely write into the contract that you evidence controls, notify them of incidents within a deadline and let them audit you. So the useful question is not "am I an essential entity?" but "which of my customers are?". That one has a date on it, and it is set by their procurement department, not by the gazette.

It is the same mechanism, the right way round, as when a software vendor's incident ends up carrying its customers' names. We wrote about it two days ago in the context of an extortion campaign that encrypted nothing: risk comes in through the same door as trust. NIS2 does not invent that problem; it writes it down and puts a signature under it.

The questionnaire, question by question

Supplier questionnaires look a lot like each other, and most of them get answered with a "yes" that means nothing. What follows is how we read them: what is being asked, and what is really being measured behind the question.

  • "Do you use MFA?" — The right answer is not yes, it is which one. An SMS code and a passkey do not defend against the same thing, and Microsoft has already put a date on retiring SMS as an authentication method. We covered it in the piece on Entra and the end of SMS. If you answer "yes" and your MFA is a text message, you have signed something that is not quite true.
  • "Do you apply security patches?" — Everybody says yes. What is being measured is how quickly and on what priority criteria. Sorting by CVSS score is comfortable and it is a mistake: what orders the queue is a system's real exposure and whether active exploitation is documented.
  • "Do you take backups?" — The question that separates the prepared from the rest is a different one: when did you last do a full restore and how long did it take? And whether those copies are immutable, because an attacker with admin credentials deletes backups before encrypting anything. That is the lesson of the land registry that was wiped entirely.
  • "Do you have an asset inventory?" — This is where a lot of people fall over, and it underpins everything else: you cannot protect, patch or report on something you do not know you have. We use NetBox as the network's source of truth for exactly this reason, not out of a fondness for documentation.
  • "Do you monitor security 24/7?" — What is being measured is whether there is somebody on the other end, and what happens at three in the morning on a Saturday. Having logs is not detection; an alert with no owner is not a defence, it is a record. That is the subject of what we published this very morning on alert fatigue.
  • "How do you handle joiners and leavers?" — The real indicator is how long an account takes to die when somebody leaves, including third-party access and the service accounts nobody claims. It is the least glamorous part and the one that shows up most often in incident reports.
  • "Will you notify us of incidents within X hours?" — Watch this one, because it is the item most likely to end up as a contractual clause with a deadline. If your customer has 24 hours facing the regulator, they will ask you for 12 or fewer. Before signing up to that deadline, check that somebody is on call who can actually meet it.
  • "Do you have a continuity plan?" — A PDF is not a plan. A plan has the date of its last exercise, a degraded mode decided in advance and a list of external dependencies. We went into it after this month's Microsoft 365 outage.

None of these questions is new, or specifically European: they are the questions of any serious security review. What changes with NIS2 is that now the answer gets signed, and whoever signs it answers for it.

The three clocks: 24 hours, 72 hours, one month

The part of NIS2 that changes day-to-day work the most is the reporting deadlines for a significant incident: early warning within 24 hours, notification with an initial assessment within 72 hours and a final report within one month of that notification (plus an interim report if the CSIRT asks for one along the way). On paper it looks like a matter of forms. In practice it is a decision problem.

Because at two in the morning, with an odd alert and half the context, somebody has to say "this is reportable". That somebody has to exist, has to be reachable and has to have written down in advance what counts and what does not. Otherwise the first hours — the only ones that matter — go on finding out who to call. We see it this way: the 24-hour clock does not measure your ability to write, it measures whether you have a real on-call rota and written criteria. Everything else is templates, and templates fill in fast once the decision is made.

The fines, without selling fear

The figures you will see everywhere are true: up to 10 million euros or 2% of worldwide turnover — whichever is higher — for essential entities and 7 million or 1.4% for important ones, with management bodies responsible for approving and overseeing the measures. Now the two caveats that almost never sit next to them. First: those are not price lists, they are the maximums the directive obliges each member state to provide for at a minimum in its own law, and they are applied through an enforcement procedure. Second: for a mid-sized Spanish company that fits no annex, the realistic twelve-month risk is not a multi-million fine. It is being left out of a tender or a contract renewal for not knowing how to answer half a dozen of the questions on that list.

And a practical warning: there is no "NIS2 certified company" badge. The directive envisages member states being able to lean on European certification schemes, but nobody issues a seal today that exempts you from anything. If you are offered one, what you are buying is a PDF. An audit report with evidence, on the other hand, does help you answer a questionnaire, and usually costs less.

What we would do with ninety days ahead

With no law published, no badge to buy and a questionnaire on the table, this is the order in which we would spend the budget. Sorted by real impact, not by what looks best in a steering committee.

  • Weeks 1-2: inventory and owners. What systems exist, who is accountable for each, and what is published on the internet. Without this, the rest is opinion.
  • Weeks 2-4: identity. Phishing-resistant MFA on what really matters — admins, VPN, email — before anything else. And service accounts, which are never in the project and always in the incident.
  • Weeks 4-6: backups and immutability, with a timed restore. A date in the calendar, a real system, and the number of minutes written down. That number answers half a dozen questions in the questionnaire.
  • Weeks 6-10: detection with an owner. Fewer and better alerts: what wakes somebody at night, who that somebody is, and what they do in the first ten minutes.
  • Weeks 10-12: the one-page notification procedure. Who decides an incident is reportable, who gets told, what goes out in the first 24 hours, and through which alternative channel if corporate email is precisely what is down.
  • And the item nobody puts on the list: read the security clauses in the contracts you have already signed. It is quite possible that the notification deadline you signed up to is tighter than the directive's own.

None of these six things depends on the law appearing in September, in January or next year. All of them improve your operation even if NIS2 did not exist, and all of them can be shown to somebody. That is, for us, the acid test of a compliance measure: if it only serves to pass an audit, it is not worth having.

Waiting for the law is a strategy. It depends what for

If your only goal is not to be fined, waiting for the text to be published and seeing exactly what it says is defensible. Plenty of sensible people are doing just that. If your goal is not to lose contracts, you are already behind: questionnaires do not wait for the gazette, and the first time one arrives with a seven-day turnaround there is no time to build anything, only to answer with what you already have.

Sources (reviewed on 29 Jul 2026): referral of Spain, Ireland, France and the Netherlands to the Court of Justice of the EU with a request for a lump sum and daily penalty payments, and the case timeline (letter of formal notice 28 Nov 2024, reasoned opinion 7 May 2025): July 2026 infringement package, European Commission Representation in Spain (9 Jul 2026) and Red Seguridad. Transposition deadline of 17 Oct 2024 (Art. 41), scope and size exceptions (Art. 2), risk-management and supply-chain security obligations (Art. 21), reporting deadlines of 24 h / 72 h / 1 month (Art. 23) and penalty limits of €10M or 2% and €7M or 1.4% (Art. 34): Directive (EU) 2022/2555, EUR-Lex. Status of the Spanish rule — draft approved by the Council of Ministers on 14 Jan 2025 at first reading, never sent to parliament as a bill nor published in the gazette, and Royal Decree-Law 12/2018 still in force: NIS2 status tracker for Spain (nisd2.eu, reviewed June 2026) and analysis of the Cybersecurity Coordination and Governance Act's progress (updated 10 Jul 2026). Full title, categories of covered entities and publication in the Official Journal of 18 Oct 2024 of Commission Implementing Regulation (EU) 2024/2690. The prioritisation criteria, the reading of supplier questionnaires and the opinions are ours.

Has the questionnaire landed?

At everyWAN we approach compliance and continuity from operations, not from a template: inventory, identity, backups that genuinely restore, and a notification procedure somebody can actually run at three in the morning. Our consultancy is vendor-agnostic we are not resellers for any particular platform and we sell no compliance badges, so if your answer to the questionnaire is fixed by tidying up what you already have, we will tell you exactly that.

Talk to everyWAN

Tags:

Share:

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN