Practical guide

Practical NIS2 guide for enterprises and public administrations

What NIS2 is, who it applies to, the ten measures of Article 21, incident reporting deadlines, penalties and a 90-day roadmap with a checklist.

Last reviewed 9 min read

Request a free assessment

Scud Security · scudsecurity.com

The NIS2 Directive (Directive (EU) 2022/2555) is the European law that turns cybersecurity into a legal obligation for thousands of organisations: energy, transport, health, water, banking, public administration, manufacturing, food and digital services. This guide sums up, without legal jargon, what it requires, from whom and by when, and proposes a realistic roadmap to comply and to prove it.

It is written for management and for IT and compliance leads. It does not replace legal advice: the references to the articles of the directive let you check every point against the official text.

1. NIS2 in two minutes

NIS2 replaces the 2016 NIS Directive. It widens the sectors in scope, harmonises security requirements across the European Union, toughens penalties and makes management accountable. It entered into force on 16 January 2023 and Member States had to transpose it into national law by 17 October 2024.

Its core idea is simple: the organisations society depends on must manage cybersecurity risk continuously, report significant incidents quickly and be able to prove both to the competent authority.

NIS2 does not ask for a certificate or a yearly audit: it asks for measures proportionate to the risk, sustained monitoring and evidence.

2. Does it apply to you? Sectors and thresholds

The directive distinguishes two groups of sectors. Annex I lists the sectors of high criticality and Annex II other critical sectors:

  • Annex I (high criticality): energy (electricity, gas, oil, hydrogen and district heating), transport (air, rail, water and road), banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, business-to-business ICT service management, public administration and space.
  • Annex II (other critical sectors): postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing (medical devices, computers and electronics, machinery, motor vehicles and other transport equipment), digital providers (online marketplaces, search engines and social networks) and research organisations.

Within those sectors the general rule is size: medium-sized and large enterprises are in scope, that is, those with at least 50 employees or more than 10 million euros in annual turnover or balance sheet total. Some entities are in scope regardless of size: providers of public electronic communications networks and services, trust service providers, top-level domain name registries, DNS service providers, central public administration and any entity that is the sole provider of an essential service in a Member State.

Essential and important entities

The directive classifies entities as essential (broadly, large enterprises in Annex I sectors plus some specific types) and important (the remaining entities in scope). The substantive obligations are the same; what changes is the intensity of supervision (ex ante and ongoing for essential entities, ex post for important ones) and the maximum penalties.

The supply chain counts too

Even if your organisation is not on the list, you may be affected indirectly: entities in scope must manage the security of their direct suppliers (Article 21(2)(d)) and pass that requirement on in their contracts. If you sell to a utility, a hospital or a public body, you will be asked for evidence.

3. Timeline and the situation in Spain

  • 16 January 2023: the directive enters into force.
  • 17 October 2024: deadline for national transposition; the measures apply from 18 October 2024.
  • 17 April 2025: deadline for each Member State to have its list of essential and important entities.
  • 14 January 2025: the Spanish Council of Ministers approves the draft Law on Cybersecurity Coordination and Governance, the act that will transpose NIS2 in Spain and create the National Cybersecurity Centre.
  • May 2025: the European Commission sends Spain a reasoned opinion for the delay in transposition.

At the date of this guide the Spanish law is still going through Parliament. That does not mean you can wait: the directive already sets the standard demanded by auditors, customers and insurers, the law will apply with no meaningful grace period, and the measures it requires take months of work. If you are a public body or one of its suppliers, the Spanish National Security Framework (ENS, Royal Decree 311/2022) is already mandatory and covers a large part of the requirements.

4. The ten measures of Article 21

Article 21 requires technical, operational and organisational measures proportionate to the risk, following an all-hazards approach. As a minimum they must cover these ten areas:

  1. Risk analysis and information security policies: knowing which assets you have, which threats affect them and which measures you apply. Without an inventory there is no credible risk analysis.
  2. Incident handling: procedures to detect, analyse, contain and report incidents, with defined roles and contacts.
  3. Business continuity: backups, disaster recovery and crisis management, tested rather than merely documented.
  4. Supply chain security: assessing and contracting direct suppliers and service providers with security criteria.
  5. Security in acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.
  6. Assessing the effectiveness of the measures: policies and procedures to check that what you have put in place works.
  7. Basic cyber hygiene and training for all staff, not only the technical team.
  8. Cryptography and encryption: policies on when and how information is encrypted.
  9. Human resources security, access control and asset management: who accesses what, with which permissions, throughout the employment relationship.
  10. Multi-factor authentication, secured voice, video and text communications and emergency communication systems within the entity.

Notice the pattern: six of the ten measures depend on knowing what is connected to your network and what it does. That is the starting point for everything else.

5. Reporting incidents: 24 hours, 72 hours, one month

Article 23 sets strict deadlines for significant incidents: those that cause or may cause severe operational disruption or financial loss, or that affect or may affect other natural or legal persons by causing considerable damage.

  • Early warning within 24 hours of becoming aware of the incident, indicating whether it is suspected to be caused by unlawful or malicious acts and whether it could have a cross-border impact.
  • Incident notification within 72 hours, with an initial assessment of severity and impact and the indicators of compromise available.
  • Final report within one month, with a detailed description, the likely root cause, the mitigation measures applied and the cross-border impact. If the incident is still ongoing, a progress report and the final report once it is handled.

Recipients of the services who may be affected must also be informed without undue delay. In Spain, notifications will go through the relevant CSIRT: INCIBE-CERT for the private sector and citizens and CCN-CERT for the public sector, via the channels set by the transposition law.

Twenty-four hours is very little time if the first to learn about the incident is your customer. Detecting in time is the only way to report in time.

6. Management accountability and penalties

Article 20 requires management bodies to approve the risk-management measures, oversee their implementation and receive training in cybersecurity. They can be held liable for infringements. It is no longer a matter for the IT department alone.

The penalty regime (Article 34) provides for fines of up to 10 million euros or 2 % of worldwide turnover for essential entities and up to 7 million euros or 1.4 % for important entities, whichever is higher. For essential entities, the authority may also temporarily suspend certifications and authorisations and temporarily ban the persons responsible from exercising managerial functions (Article 32(5)).

7. A 90-day roadmap

You do not need to start with the paperwork. This order of work prioritises what reduces real risk and produces evidence from the first week:

Weeks 1 to 3: know what you have

  • A complete inventory of connected assets: servers, workstations, cameras, printers, OT and IoT devices and cloud services. Automated, not in a spreadsheet.
  • A dependency map: which essential services you provide and which systems and suppliers they depend on.
  • Named owners: who decides, who executes and who reports.

Weeks 4 to 6: measure the risk

  • Vulnerability analysis on the real inventory, prioritised by impact on essential services.
  • Access review: privileged accounts, multi-factor authentication and orphaned accounts.
  • A list of critical suppliers and the security clauses missing from their contracts.

Weeks 7 to 10: close the gaps and prepare the response

  • An incident-handling plan with the 24-hour, 72-hour and one-month deadlines built in, and a notification template ready to use.
  • Backups tested with a real restore and a crisis exercise with management.
  • Continuous network monitoring: without it there is neither early detection nor evidence.

Weeks 11 to 13: prove it

  • Policies approved by management and training on record, including the training of the management body itself.
  • An evidence matrix: which measure covers each area of Article 21 and where the proof is.
  • A review calendar: risk analysis and tests are repeated, not filed away.

8. Self-assessment checklist

Answer honestly. Every “no” is a task for the roadmap.

  • Do we have an up-to-date, automated inventory of every device connected to the network, including OT and IoT?
  • Do we know which of the services we provide the directive considers essential or important?
  • Is there a risk analysis approved by management and reviewed in the last twelve months?
  • Is there an incident-handling procedure with owners and reporting deadlines?
  • Could we send an early warning within 24 hours if we detected an incident today?
  • Would we detect an outbound connection to known malicious infrastructure in under an hour?
  • Have we tested a full restore from backup in the last six months?
  • Do we use multi-factor authentication for all remote access and privileged accounts?
  • Do we know the open vulnerabilities in our systems and how long we take to fix them?
  • Do our contracts with critical suppliers include security and incident-reporting requirements?
  • Has all staff received cybersecurity training in the last year?
  • Has the management body received specific training, and does it approve the security policies?
  • Can we prove each of the ten measures of Article 21 with evidence?

9. How Scud helps

Scud covers the part of NIS2 that is hardest to sustain over time: visibility and continuous monitoring of the network.

  • Scud Sensor builds the real inventory of everything connected, including forgotten devices, and detects their vulnerabilities: the basis of risk analysis and asset management (measures 1, 5 and 9).
  • Scud Smart Platform compares traffic with known threats in real time and documents every detection: incident handling and effectiveness assessment (measures 2 and 6).
  • Scud Monitor puts our own analysts on continuous watch and response, with the reports you need to notify on time and prove compliance.

It all starts with a free assessment: we plug in a Sensor, map the network and hand you the report of devices and vulnerabilities. You can also see the frameworks we cover in the compliance section and read our article on the NIS2 Directive (in Spanish).

Sources

This guide is for information only and reflects the legislation as of the date shown. For decisions with legal effect, consult your legal adviser.