The NIS 2 Directive in Europe: Personal director liability and fines of up to €10 million.
Is your business ready for the cybersecurity audits that will become mandatory?
The deadline to implement the European NIS 2 cybersecurity directive expired in October 2024, but Spain has yet to complete its transposition into national law. Despite the delay and the infringement procedure initiated by the European Commission, experts warn: waiting for the final law is dangerous. The largest European players — the "essential entities" of the market have already begun auditing their supply chains. For medium-sized businesses, this creates the risk of a "silent blockade": losing key contracts due to non-compliance with partners' security standards, even if regulatory fines are not yet looming.
Legal briefing: How the NIS 2 directive actually works.
To understand the nature of the risks, it is essential to grasp the "architecture" of European legislation. Many business owners make the fatal mistake of confusing a Regulation (like GDPR) with a Directive (like NIS 2).
While a Regulation is a direct law that takes effect in all countries on the same day, a Directive is a mandatory order to member states to align their national laws with a unified standard. It is not a recommendation to do better. It is a strict demand: "Achieve the result by any means necessary, or we will fine you."
NIS 2 does not work on its own. It triggers an inevitable three-step process in every EU country, including Spain. And while you are waiting for the final stage, the first two are already reshaping the business landscape around you.
Here is how this process works:
1. Transposition stage. Status in Spain: Overdue, proceeding in emergency mode.(12 March 2026 Update).
2. Institutional capacity building stage. Status: Active phase. The law does not work without "overseers." The Directive requires the country to create or empower specific bodies:
While a Regulation is a direct law that takes effect in all countries on the same day, a Directive is a mandatory order to member states to align their national laws with a unified standard. It is not a recommendation to do better. It is a strict demand: "Achieve the result by any means necessary, or we will fine you."
NIS 2 does not work on its own. It triggers an inevitable three-step process in every EU country, including Spain. And while you are waiting for the final stage, the first two are already reshaping the business landscape around you.
Here is how this process works:
1. Transposition stage. Status in Spain: Overdue, proceeding in emergency mode.(12 March 2026 Update).
2. Institutional capacity building stage. Status: Active phase. The law does not work without "overseers." The Directive requires the country to create or empower specific bodies:
- Competent authorities: Those who will have the right to audit you, demand access to servers, and issue fines.
- CSIRTs (Computer Security Incident Response Teams): The "digital special forces" to whom you will be required to report incidents within 24 hours and submit progress reports and taken measures within 72 hours.
- SPOC (Single Points of Contact): For communication with other EU countries, ensuring that a breach in a Spanish logistics company is instantly known to its German partners.
The business trap: Many think: "Since stage 3 hasn't arrived yet, we can relax." This is an illusion. The NIS 2 Directive creates a direct effect through the market. Your European partners (especially in Germany or Northern Europe, where laws have already been passed) know that Spain is obligated to fulfill these requirements. They are not waiting for the Spanish law — they are already demanding compliance with Brussels' standards from their Spanish contractors to close their own risks.
Legally, Spain may be late, but economically, the EU has already transitioned to the new standard. In this gap between "the law" and "the market," hundreds of unprepared companies are currently at risk of falling through.
The Spanish scenario: Chronicle of a dangerous delay.
The situation with the implementation of NIS 2 in Spain is paradoxical. On the one hand, de jure, the country is in breach of its European obligations. On the other hand, it is precisely this breach that makes the forced, rapid adoption of the law in the coming months inevitable.
To understand the risks to your assets, you need to look at the timeline of this legislative delay.
To understand the risks to your assets, you need to look at the timeline of this legislative delay.
1. The missed deadline and Brussels' reaction.
The EU Directive set a strict deadline for all member states: the rules had to be integrated into national legislation by October 17, 2024. Spain missed this deadline.
The European Commission's reaction was bureaucratically ruthless. Since Madrid failed to notify Brussels of full transposition, an infringement procedure was officially initiated against the Kingdom in November 2024 . Spain received a "reasoned opinion" — the final warning before the case is referred to the EU Court of Justice.
What does this mean for business? For Pedro Sánchez's government, this is a red alert. To avoid massive fines from the EU, the parliament will be forced to pass the law in emergency mode. Businesses will not have the usual "transition period" to get up to speed — the law will be passed "yesterday," and enforcement will begin "today."
The European Commission's reaction was bureaucratically ruthless. Since Madrid failed to notify Brussels of full transposition, an infringement procedure was officially initiated against the Kingdom in November 2024 . Spain received a "reasoned opinion" — the final warning before the case is referred to the EU Court of Justice.
What does this mean for business? For Pedro Sánchez's government, this is a red alert. To avoid massive fines from the EU, the parliament will be forced to pass the law in emergency mode. Businesses will not have the usual "transition period" to get up to speed — the law will be passed "yesterday," and enforcement will begin "today."
2. Status of the Law: A "Pending" Draft.
As of April 2026, the regulatory framework exists as a preliminary draft law on cybersecurity coordination and governance (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad), which was approved by the Council of Ministers in January 2025.
This document is designed to create the institutional basis for NIS 2, but it is still awaiting final approval in Parliament. This pause creates a false sense of security for business owners — an "illusion of a reprieve."
This document is designed to create the institutional basis for NIS 2, but it is still awaiting final approval in Parliament. This pause creates a false sense of security for business owners — an "illusion of a reprieve."
3. The regulators' position: Focus on the ENS.
While politicians argue, the relevant authorities, the National Cryptologic Center (CCN-CERT) and the National Cybersecurity Institute (INCIBE) — explicitly recommend that companies ignore the law's delay and begin adapting immediately.
Their logic is simple: Spain already has the National Security Scheme (ENS — Esquema Nacional de Seguridad). Originally created for the public sector, it contains most of the requirements that duplicate NIS 2.
Their logic is simple: Spain already has the National Security Scheme (ENS — Esquema Nacional de Seguridad). Originally created for the public sector, it contains most of the requirements that duplicate NIS 2.
You do not need to wait for the law to be published in the BOE (Official State Gazette) to know what to do. ENS standards are de facto the "rough draft" of the future NIS 2 requirements. Those who implement them now will gain immunity during the initial audits. Those who wait for the official law will find themselves out of time, facing double pressure: from a rushed government and from European partners.
"Non tech business owners ask: 'ok, and what will the fines be?'. That is the wrong question. The right question is: 'How many contracts will I lose next quarter if I fail my client's security audit?'. Fines and director disqualification are extreme measures that may never happen. But exclusion from tenders due to a lack of transparent IT protocols is today's reality."
— Polina Bacho, Founder of Rostoria
On Sanctions: Extreme measures you need to know.
Commercial risks are already in effect, and this does not negate the inevitability of state enforcement. As soon as the Anteproyecto de Ley passes parliamentary hearings and is published in the BOE, the administrative liability timer will start.
The NIS 2 Directive is designed by European legislators to make ignoring cybersecurity economically unviable for the company and personally dangerous for its leadership.
The NIS 2 Directive is designed by European legislators to make ignoring cybersecurity economically unviable for the company and personally dangerous for its leadership.
1. The math of fines: More than just expenses.
The European regulator has moved away from small, fixed fines that were cheaper for large businesses to pay than to fix the violations. A two-tier sanction system tied to global turnover has been introduced (similar to GDPR, but stricter):
Important nuance: A fine can be imposed not only for a breach (an incident) but also for failing to comply with risk management obligations. That is, if an auditor discovers that you do not have approved security policies or do not conduct regular staff training, sanctions can be applied preventively, even if no data leak has occurred.
The European regulator has moved away from small, fixed fines that were cheaper for large businesses to pay than to fix the violations. A two-tier sanction system tied to global turnover has been introduced (similar to GDPR, but stricter):
- For "Essential Entities": a fine of up to €10M or 2% of the total worldwide annual turnover (whichever is higher).
- For "Important Entities": a fine of up to €7M or 1.4% of the turnover.
Important nuance: A fine can be imposed not only for a breach (an incident) but also for failing to comply with risk management obligations. That is, if an auditor discovers that you do not have approved security policies or do not conduct regular staff training, sanctions can be applied preventively, even if no data leak has occurred.
2. The "Nuclear Option": C-lvl disqualification.
A radical innovation of NIS 2 that fundamentally changes corporate governance in Europe is the introduction of Management Liability.
The legislator operates on the principle that cybersecurity is no longer a technical task for the IT department, but a strategic business responsibility. If a company systematically violates the directive's requirements and financial fines prove ineffective, competent authorities (in Spain, through a judicial procedure) have the right to apply a temporary ban on holding managerial positions (disqualification) for the CEO or other responsible individuals.
For a business owner, this means the risk of losing legal control over their own asset.
A radical innovation of NIS 2 that fundamentally changes corporate governance in Europe is the introduction of Management Liability.
The legislator operates on the principle that cybersecurity is no longer a technical task for the IT department, but a strategic business responsibility. If a company systematically violates the directive's requirements and financial fines prove ineffective, competent authorities (in Spain, through a judicial procedure) have the right to apply a temporary ban on holding managerial positions (disqualification) for the CEO or other responsible individuals.
For a business owner, this means the risk of losing legal control over their own asset.
3. The time trap.
Many businessmen choose the strategy of "waiting until the law is passed." This is a dangerous illusion. Building a compliance system is not a one-time action; it is a process of restructuring business architecture that takes anywhere from 9 to 22 months. But you will say that we have AI, and I will answer you that it will still take a long time and be very expensive.
When the law comes into force and national authorities (empowered as inspectors) begin their first checks, there will be no time left to "build the foundation." At that point, your system must be ready to be demonstrated; otherwise, you will face the full power of the state enforcement machine alone.
Many businessmen choose the strategy of "waiting until the law is passed." This is a dangerous illusion. Building a compliance system is not a one-time action; it is a process of restructuring business architecture that takes anywhere from 9 to 22 months. But you will say that we have AI, and I will answer you that it will still take a long time and be very expensive.
When the law comes into force and national authorities (empowered as inspectors) begin their first checks, there will be no time left to "build the foundation." At that point, your system must be ready to be demonstrated; otherwise, you will face the full power of the state enforcement machine alone.
FAQ: The Essentials of NIS 2 in Spain.
Is the NIS 2 directive currently active in Spain?
No, the directive requires transposition. Legally, the EU directive has already entered into force, but the Spanish national law (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad) is still pending approval. Since the European Commission has already officially initiated an infringement procedure against Spain for the delay, Madrid will now force the adoption of the legislation in emergency mode.
Crucial for business: Do not view this pause as a reprieve. European counterparties already consider NIS 2 requirements a mandatory standard and make no allowances for the sluggishness of the Spanish parliament.
Crucial for business: Do not view this pause as a reprieve. European counterparties already consider NIS 2 requirements a mandatory standard and make no allowances for the sluggishness of the Spanish parliament.
Who will be affected by the new law? My business is not related to energy or banking.
The regulatory perimeter has been expanded unprecedentedly. The list of "Essential" and "Important" entities now includes not only critical infrastructure but also:
- Food production and processing.
- Transport and logistics.
- Waste management.
- Wholesale trade and distribution.
- Manufacturing of chemicals and machinery.
- Companies that qualify as medium-sized enterprises (Fewer than 250 employees. Plus either: Annual turnover not exceeding €50 million, or an annual balance sheet total not exceeding €43 million) or exceed these thresholds.
What should we do if the law hasn't been passed yet? Wait for BOE publication?
Waiting is the riskiest strategy. When the law is published in the BOE, you will have no time left to restructure your processes — audits will begin immediately. The National Cryptologic Center (CCN) and INCIBE recommend using this time to audit and adapt, guided by the already existing National Security Scheme (ENS). Compliance with ENS standards will be a strong argument in your favor during any future NIS 2 audit and is already highly valued by large corporate clients.
Additionally: When conducting a security risk assessment, consider both technical factors (e.g., equipment vulnerabilities) and non-technical factors (Who manufactures the equipment? In what country? Is this supplier reliable, or could they be subject to influence from hostile states?).
Additionally: When conducting a security risk assessment, consider both technical factors (e.g., equipment vulnerabilities) and non-technical factors (Who manufactures the equipment? In what country? Is this supplier reliable, or could they be subject to influence from hostile states?).
Conclusion: The "Owner's Representative" Strategy.
In a situation where the law is delayed but the market already demands compliance, the worst strategy for an owner is to adopt a wait-and-see approach. But this does not mean you must abandon running your business to dive into studying encryption protocols.
To meet NIS 2 requirements and retain contracts, you do not need to become an IT Director. You need to apply the same logic you use when building a new warehouse or office: hire an Owner's Representative (Technical Client).
In construction, you don't lay the bricks yourself; you hire an engineer who checks the concrete quality and prevents contractors from inflating the budget. In digital transformation, Rostoria's role is to act precisely as that representative of your interests.
Contact us — everything can be fixed or built from scratch.
To meet NIS 2 requirements and retain contracts, you do not need to become an IT Director. You need to apply the same logic you use when building a new warehouse or office: hire an Owner's Representative (Technical Client).
In construction, you don't lay the bricks yourself; you hire an engineer who checks the concrete quality and prevents contractors from inflating the budget. In digital transformation, Rostoria's role is to act precisely as that representative of your interests.
Contact us — everything can be fixed or built from scratch.