NIS2 Compliance for Businesses | GRUPO LINKA
DIRECTIVE (EU) 2022/2555 · NIS2 COMPLIANCE

NIS2 Compliance for Your Company, without Surprises

Applicability diagnosis, gap analysis against Article 21 and an adaptation roadmap, operated by a consultancy certified in ISO 27001, ENS High and NIS2.

Essential EntityImportant EntityArticle 2118 SectorsINCIBE-CERT
Sep 2026

The European Commission assesses Spain’s progress.

10 M€ · 2%

Fines of up to €10M or 2% of turnover.

Directors

Personal liability of management.

[ WHAT IT IS AND WHY IT AFFECTS YOU NOW ]

The Obligation Already Exists, Don’t Wait for the Law

The NIS2 Directive replaces the 2016 NIS and vastly expands the universe of covered companies: from 7 sectors to 18, and from a few hundred operators to thousands of organizations across Spain.

Spain transposed it only partially through Royal Decree-law 7/2025, and the Cybersecurity Coordination and Governance Act is still being processed. But the core obligations are already enforceable, because they arise from the directive itself: inspections have begun and European clients already pass these requirements into their contracts.

Real Decreto-ley 7/2025Article 21Supply chain
EU NIS2 Directive: mandatory cybersecurity for 18 sectors
[ SELF-TEST ]

Does NIS2 Apply to Me?

Answer three questions and get an idea in 30 seconds. It doesn’t replace a formal diagnosis, but it tells you whether you should be concerned.

01

Do you operate in any of the 18 regulated sectors?

See the 18 sectors

energy, transport, banking, financial markets, health, drinking and waste water, digital infrastructure, managed ICT providers, public administration, space, postal services, waste management, manufacturing, food production and distribution, manufacturing of critical products, digital providers and research.

02

Do you have 50 or more employees, or turnover above €10M?

03

Are you a supplier to an essential or important entity?

INDICATIVE RESULT

Answer the three questions to see your result.

Self-classification has pitfalls: if you have subsidiaries or provide services to an essential entity, the scope can reach you even if your size didn’t include you directly.

Confirm your situation with a diagnosis
[ THE ARTICLE 21 OBLIGATIONS ]

Real Measures, and Demonstrable

NIS2 is not paperwork: it requires real technical and organizational measures, and that you can demonstrate them with evidence. These are the main ones.

Risk Analysis & Management

A documented framework, approved by management and reviewed periodically.

Incident Management

Detection, response and staged notification: 24h, 72h and 1 month.

Business Continuity

Backups, crisis management and disaster recovery.

Supply Chain Security

Assess and supervise the security of your critical suppliers.

Encryption & Cryptography

Data protected at rest and in transit, with key management.

Access Control & MFA

Multi-factor authentication for privileged and remote access.

Training

Staff awareness and documented training for management.

Effectiveness Assessment

Audits, technical tests and pentesting that prove it works.

The watchword of NIS2 is traceability: any compliance claim must be backed by evidence the day the authority comes knocking.

[ DEADLINES & PENALTIES ]

The Clock Is Already Ticking

24h · 72h · 1 mes
STAGED NOTIFICATION

Warning, preliminary report and final report of serious incidents to the competent CSIRT (INCIBE-CERT for the private sector).

10 M€ · 2%
PENALTY CAP

The higher of the two figures, calculated on the organization’s worldwide turnover.

Disqualification
PERSONAL LIABILITY

Management is personally liable; in serious breaches, directors can be temporarily disqualified.

If an incident affects personal data, notification to the AEPD under GDPR is triggered in parallel: they are independent procedures and penalties can add up. And one date in red: in September 2026 the European Commission will assess Spain’s progress. The State’s delay does not exempt companies.

[ HOW GRUPO LINKA HELPS YOU ]

From Doubt to Evidence

We support you from start to finish, no smoke and mirrors: from knowing whether you’re in scope to operating your security and generating the evidence the auditor will ask for.

01

Applicability Diagnosis

We determine whether NIS2 applies to you and whether you are an essential or important entity. Clearing up doubts is the first step.

02

Gap Analysis (GAP)

We compare your situation against the ten areas of Article 21 and tell you, plainly, where you stand and what you’re missing.

03

Adaptation Plan

A 12-month prioritized roadmap, with owners, deadlines and budget, aligned with your business.

04

Implementation & Evidence

We deploy and operate the controls 24/7 from our Spartan SOC and prepare the auditable evidence.

Already have ISO 27001? Then you cover approximately 65-75% of Article 21; the typical gaps (24h notification, board training, supply chain) are containable. And if you need the security officer role the regulation requires, we provide it as a service with our CISO as a Service (vCISO), without you expanding headcount.

Applicability DiagnosisAre you in scope?Gap AnalysisArticle 21Adaptation Plan12-month roadmapImplementationControls + evidenceCompliant
NIS2 ADAPTATION PATH
[ YOUR ROADMAP ]

A Clear Roadmap over 12 Months

We turn a complex obligation into a phased plan: you always know where you stand, what’s missing and by when. And we go all the way to auditable evidence.

65-75%

of Article 21 is already covered if you have ISO 27001. We scope the rest and take you to compliance.

[ WHY GRUPO LINKA ]

A Consultancy That Leads by Example

We don’t just help you comply: we already comply. We operate under the certifications many of your clients require, ISO 27001, ISO 27701, ENS High Category and NIS2 adherence, and we watch your company 24/7 from our own Spartan SOC, with our own technical team.

+15 years of experienceA broad in-house teamNationwide coverageSpartan SOC 24/74.8★ · 145 reviews
NIS2 · ISO 27001 · ENS
[ FREQUENTLY ASKED QUESTIONS ]

We Answer Your Questions

Who does NIS2 apply to in Spain?+

To entities in 18 sectors with 50 or more employees or more than €10M in turnover, and to some below that threshold due to their critical nature. It can also reach you indirectly if you are a supplier to a covered entity.

How does NIS2 differ from the ENS?+

They are complementary frameworks. The ENS regulates public-sector systems and their suppliers; NIS2 regulates the cybersecurity of entities in designated sectors. A single company may be subject to both.

What fines does NIS2 provide for?+

Up to €10M or 2% of worldwide turnover (whichever is higher), plus possible personal liability and disqualification of directors.

Do I need ISO 27001?+

It is not mandatory, but it greatly shortens the path: it covers around 65-75% of Article 21. If you are starting from scratch, it makes sense to build the system with the ISO 27001 structure from the outset.

Do I have to wait for the Spanish law to act?+

No. The core obligations arise from the directive and are already enforceable. Waiting for full transposition only reduces the time you have to prepare.

[ TRUST & COMPLIANCE ]

Certifications & Tier-1 Alliances

We operate under the most demanding standards and with the market-leading vendors to guarantee your security, your continuity and your regulatory compliance, including the NIS2.

CERTIFIED
ISO
9001
COMPANY
Quality Management
CERTIFIED
ISO
27001
COMPANY
Information Security
CONFORMITY
ENS
HIGH CAT.
National Security Framework
CERTIFIED
ISO
27018
COMPANY
Personal Data in the Cloud
CERTIFIED
ISO
14001
COMPANY
Environmental Management
CERTIFIED
ISO
20000
COMPANY
IT Service Management
CERTIFIED
ISO
22301
COMPANY
Business Continuity

Ready to Comply with NIS2?

A first step with no commitment: you’ll know if it applies to you, which category you fit and what you need to comply.

[ IN SUMMARY ]

GRUPO LINKA helps companies achieve NIS2 Directive compliance: applicability diagnosis, Article 21 gap analysis and an adaptation roadmap with auditable evidence. We are a Fortinet Expert Partner with our own 24/7 SOC (Spartan SOC), certified in ISO 27001 and with ENS High Level accreditation, and we provide service across Spain. It is part of our Cyber Consulting.

CallContact