If your organisation operates in energy, transport, banking, health, water, digital infrastructure, public administration, managed ICT services, manufacturing, food or waste, NIS2 very likely applies to you as an essential or important entity. And it applies even though Spain has still not transposed it.
Spain has no law yet. That is not an extension
The transposition deadline for Directive (EU) 2022/2555 expired on 17 October 2024. The draft Spanish Cybersecurity Coordination and Governance Act was approved by the Council of Ministers on 14 January 2025 and has still not been published in the official gazette.
On 9 July 2026 the European Commission referred Spain to the Court of Justice of the EU over that failure to transpose, asking for a lump sum and daily penalty payments. The direction of travel is settled; only the publication date is missing.
What that means in practice: when the law is published, compliance deadlines will run from that day, not from the day you start. Organisations that arrive with the gap analysis already done will comply. Those that start then will be negotiating against the clock.
What it will require of you
Risk management measures (art. 21): risk analysis policy, incident handling, business continuity and backups, supply chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human resources security, access control and multi-factor authentication.
Incident reporting against the clock: early warning within 24 hours, notification within 72 hours and a final report within one month.
Management body accountability: approving the measures, overseeing their implementation and being trained. This cannot be delegated to the IT department.
Supply chain: you are also accountable for the risk that reaches you through your suppliers.
Penalties: up to €10M or 2% of worldwide turnover for essential entities and up to €7M or 1.4% for important ones.
What we do
Phase 1
Gap analysis
We measure the real distance between what the regulation demands and what you have today, control by control. No generic checklists: we review evidence, not statements of intent.
Phase 2
Action plan
Every gap becomes a task with an owner, an effort estimate and a priority based on risk. You decide what comes first knowing what protects you most.
Phase 3
Remediation
We work alongside you through delivery: policies, procedures, technical controls and evidence, until compliance holds up in front of an auditor.
How we work
1
Does it apply, and as what?
We determine whether you are an essential or an important entity based on sector, size and scoping criteria. It is the first question and many organisations get it wrong, in both directions.
2
Gap analysis against article 21
We work through the ten required measures and test them against real evidence: configurations, logs, contracts, minutes. The output is a map of where you are and where you must be.
3
Risk-prioritised action plan
Every gap with an owner, an effort estimate and a priority. What exposes you most comes first, not what closes fastest.
4
A reporting procedure that survives 24 hours
A plan nobody has rehearsed will not deliver a notification in 24 hours. We leave the process defined, with roles, templates and the channel to the competent authority.
5
Support through to compliance
Implementation of what was agreed and periodic progress review, with the supporting documentation ready to show.
What you get
Applicability report with a reasoned classification of your entity.
Gap analysis control by control, with maturity level and linked evidence.
Action plan, prioritised, with owners and effort estimates.
Incident reporting procedure aligned to the 24-hour, 72-hour and one-month deadlines.
Executive report for the management body, which is where accountability sits.
Traceability matrix between what the regulation requires and what you have implemented.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Does it make sense to start before the law is published?
Yes, and it is the cheap decision. The technical substance of article 21 will not change with transposition: what will change is deadlines, the competent authority and the penalty regime. The analysis and remediation work carries over in full.
We already have ISO 27001. Is that enough?
It is a strong base and saves you a good part of the journey, but it is not equivalent. NIS2 adds obligations the standard does not cover in that detail: the reporting deadlines, the explicit accountability of the management body and supply chain treatment. We reuse what you have and work on the difference.
Do you certify us against NIS2?
NIS2 is not a certification scheme, it is a legal obligation supervised by the competent authority. We prepare you to answer to that authority and to evidence what you have done, which is what will be asked of you.
We supply an essential entity, we are not one. Does it affect us?
Yes, through the supply chain. Your clients will pass requirements down by contract and ask you for evidence. Having it ready is a commercial argument today.
Know where you stand before the clock starts
Half an hour with an auditor to review whether NIS2 applies to you, in what capacity, and what a sensible gap analysis scope would look like. No commitment and no forms.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

