Back to blog
June 10, 2026CybersecurityApoga Team

NIS2 in 2026: Why Spanish SMEs Can't Wait for a Cybersecurity Law That Still Hasn't Passed

Spain missed the EU's October 2024 deadline to transpose the NIS2 cybersecurity directive, and its national law is still stuck in parliament — but the obligations already apply, and Brussels has proposed easing them for 28,700 smaller companies. Here's what Spanish SMEs need to do now.

NIS2 cybersecurity compliance for Spanish SMEs
Boardroom accountability for cybersecurity is now EU law — whether or not Spain has finished writing its own version of it.
Spain's national cybersecurity law is still moving through parliament. NIS2 itself is not waiting: the directive has applied EU-wide since October 2024, and Brussels has already opened infringement proceedings over the delay.

A Deadline Spain Missed, and a Law That Still Isn't Finished

The EU's NIS2 Directive (Directive (EU) 2022/2555) set October 17, 2024 as the deadline for every member state to transpose its cybersecurity rules into national law. Spain missed it. The European Commission opened an infringement procedure against Spain on November 28, 2024, and escalated to a formal reasoned opinion on May 7, 2025 — one of 19 member states still lagging at that point. Spain's Council of Ministers had already approved a draft law, the Ley de Coordinación y Gobernanza de la Ciberseguridad, on January 14, 2025. It would create a new Centro Nacional de Ciberseguridad to oversee compliance nationally — but as of this writing, the bill is still moving through the Cortes Generales and hasn't been published in the BOE.

No Law Doesn't Mean No Obligations

That gap matters less than it looks. NIS2's substantive obligations don't wait on Spain's paperwork — the directive has applied across the EU since it entered into force in January 2023, and Brussels has made clear that a missing national law doesn't suspend the underlying requirements for the public bodies that oversee compliance. For companies, the real risk isn't a loophole; it's assuming there's more runway than there is. Once Spain's law is finally published, other member states' experience suggests the grace period for affected businesses to prove compliance will likely be measured in months, not years.

Who's Actually In Scope — and Why It's Bigger Than You Think

NIS2 covers 18 'essential' and 'important' sectors, roughly double what its predecessor (NIS1) covered — energy, transport, banking, health, drinking water, digital infrastructure and public administration, plus newer additions like waste management, food production, postal and courier services, and providers of digital services such as marketplaces and social platforms. Medium and large companies operating in these sectors are directly in scope. But the reach extends further: NIS2 explicitly requires in-scope companies to manage cybersecurity risk in their supply chains, which means a small supplier or subcontractor can get pulled into a client's security questionnaire and contract requirements even without being regulated directly.

ObligationWhat It RequiresWhen It Applies
Risk-management measuresDocumented policies covering incident handling, business continuity, supply chain security, access control and encryptionOngoing, once in scope
Early warningNotify the competent authority or CSIRT of a significant incidentWithin 24 hours of becoming aware
Incident notificationProvide an initial severity and impact assessmentWithin 72 hours
Final reportFull incident report covering root cause and mitigationWithin 1 month
Management accountabilityBoards must approve, oversee and be trained on cybersecurity risk measures, with personal liability for failuresOngoing

Relief Is Coming, but It Isn't Law Yet

On January 20, 2026, the European Commission proposed a package of targeted amendments to NIS2 alongside a revised Cybersecurity Act, aimed at cutting red tape for smaller companies. The Commission's own estimate: the changes would reduce compliance burden for 28,700 companies, including 6,200 micro and small enterprises, and create a new 'small mid-cap' category expected to lower compliance costs for a further 22,500 companies. It's a meaningful signal that Brussels knows the current rules land hard on smaller businesses — but as of this writing it's still a proposal, subject to negotiation between the European Parliament and the Council. Treat it as a reason for cautious optimism, not a reason to delay preparing for the rules as they stand today.

  • Confirm exposure: check whether your sector and size puts you directly in scope, or whether a client or supplier contract effectively puts you there anyway.
  • Fix the highest-impact gaps first: multi-factor authentication on email and VPN access, a centralized password manager, and tested cloud backups cover a large share of typical incident risk for modest effort.
  • Name someone responsible for cybersecurity and keep an inventory of critical systems and vendors, even if that person wears the hat part-time.
  • Update vendor and client contracts to reflect incident-notification timelines and security expectations, especially where you supply an essential or important entity.

None of this requires building an in-house security operations center. AI-assisted monitoring tools can flag anomalous activity fast enough to make the 24-hour early-warning window realistic for a small IT team, and the same automation can maintain the audit trail — asset inventories, vendor risk records, incident logs — that NIS2's governance requirements expect boards to review. At Apoga, this is the same kind of AI integration and IT consulting work we already do for SMEs adapting to other EU compliance regimes: the goal isn't a compliance department, it's tooling that makes the existing team capable of meeting the bar.