Applicability diagnosis, gap analysis against Article 21 and an adaptation roadmap, operated by a consultancy certified in ISO 27001, ENS High and NIS2.
The European Commission assesses Spain’s progress.
Fines of up to €10M or 2% of turnover.
Personal liability of management.
The NIS2 Directive replaces the 2016 NIS and vastly expands the universe of covered companies: from 7 sectors to 18, and from a few hundred operators to thousands of organizations across Spain.
Spain transposed it only partially through Royal Decree-law 7/2025, and the Cybersecurity Coordination and Governance Act is still being processed. But the core obligations are already enforceable, because they arise from the directive itself: inspections have begun and European clients already pass these requirements into their contracts.
Answer three questions and get an idea in 30 seconds. It doesn’t replace a formal diagnosis, but it tells you whether you should be concerned.
Do you operate in any of the 18 regulated sectors?
energy, transport, banking, financial markets, health, drinking and waste water, digital infrastructure, managed ICT providers, public administration, space, postal services, waste management, manufacturing, food production and distribution, manufacturing of critical products, digital providers and research.
Do you have 50 or more employees, or turnover above €10M?
Are you a supplier to an essential or important entity?
Answer the three questions to see your result.
Self-classification has pitfalls: if you have subsidiaries or provide services to an essential entity, the scope can reach you even if your size didn’t include you directly.
Confirm your situation with a diagnosisWarning, preliminary report and final report of serious incidents to the competent CSIRT (INCIBE-CERT for the private sector).
The higher of the two figures, calculated on the organization’s worldwide turnover.
Management is personally liable; in serious breaches, directors can be temporarily disqualified.
If an incident affects personal data, notification to the AEPD under GDPR is triggered in parallel: they are independent procedures and penalties can add up. And one date in red: in September 2026 the European Commission will assess Spain’s progress. The State’s delay does not exempt companies.
We support you from start to finish, no smoke and mirrors: from knowing whether you’re in scope to operating your security and generating the evidence the auditor will ask for.
We determine whether NIS2 applies to you and whether you are an essential or important entity. Clearing up doubts is the first step.
We compare your situation against the ten areas of Article 21 and tell you, plainly, where you stand and what you’re missing.
A 12-month prioritized roadmap, with owners, deadlines and budget, aligned with your business.
We deploy and operate the controls 24/7 from our Spartan SOC and prepare the auditable evidence.
Already have ISO 27001? Then you cover approximately 65-75% of Article 21; the typical gaps (24h notification, board training, supply chain) are containable. And if you need the security officer role the regulation requires, we provide it as a service with our CISO as a Service (vCISO), without you expanding headcount.
We turn a complex obligation into a phased plan: you always know where you stand, what’s missing and by when. And we go all the way to auditable evidence.
of Article 21 is already covered if you have ISO 27001. We scope the rest and take you to compliance.
To entities in 18 sectors with 50 or more employees or more than €10M in turnover, and to some below that threshold due to their critical nature. It can also reach you indirectly if you are a supplier to a covered entity.
They are complementary frameworks. The ENS regulates public-sector systems and their suppliers; NIS2 regulates the cybersecurity of entities in designated sectors. A single company may be subject to both.
Up to €10M or 2% of worldwide turnover (whichever is higher), plus possible personal liability and disqualification of directors.
It is not mandatory, but it greatly shortens the path: it covers around 65-75% of Article 21. If you are starting from scratch, it makes sense to build the system with the ISO 27001 structure from the outset.
No. The core obligations arise from the directive and are already enforceable. Waiting for full transposition only reduces the time you have to prepare.
GRUPO LINKA helps companies achieve NIS2 Directive compliance: applicability diagnosis, Article 21 gap analysis and an adaptation roadmap with auditable evidence. We are a Fortinet Expert Partner with our own 24/7 SOC (Spartan SOC), certified in ISO 27001 and with ENS High Level accreditation, and we provide service across Spain. It is part of our Cyber Consulting.