You keep hearing about NIS2 and you still don't know if it applies to you. The short answer, if your company has between 10 and 50 employees, is that you almost certainly fall outside the directive's direct scope. The fuller answer is more interesting: even if it doesn't reach you directly, there is a good chance it is already reaching you indirectly, through the larger clients you sell to. Meanwhile, a different regulation already applies to you today, with real fines, and it gets talked about far less.
What NIS2 actually is
NIS2 is Directive (EU) 2022/2555, adopted on 14 December 2022, on measures for a high common level of cybersecurity across the European Union. Member states had until 17 October 2024 to transpose it into national law. As of this writing, Spain had not yet enacted its transposition law: there is no Spanish NIS2 statute in force, and any content claiming a specific Spanish cybersecurity law exists should be treated with suspicion.
That does not make the directive irrelevant. An EU directive sets the direction even when the national law is delayed, and the obligations it spells out in detail (risk management, incident notification, management-level accountability) will land in Spanish law sooner or later. The useful question for an SME is this: does the model the directive describes reach me, directly or indirectly? That question matters more than whether the law is already in force.
Who is actually in direct scope
NIS2 uses a size threshold borrowed from Recommendation 2003/361/EC: it covers medium enterprises or larger within a list of sectors classified as essential or important (energy, transport, banking, health, digital infrastructure, public administration and several others). A 10 to 50 employee company is, by definition, a small enterprise, so it sits outside direct scope except for a handful of flat exceptions:
- Being the sole national provider of an essential service.
- Operating in telecommunications.
- Providing DNS or trust services.
- Running domain name registration.
- Being part of central public administration.
If your company doesn't match any of these, NIS2 imposes no direct obligation on you today. It is still worth reading on.
The real channel through which NIS2 reaches SMEs: the supply chain
The directive itself anticipates this. Recital 85 devotes a full paragraph to the cybersecurity risk that reaches a regulated entity through its supply chain and its suppliers. In practice, this translates into something very concrete: if you sell software, managed services, maintenance or any product to a medium or large company that does fall within NIS2's scope, that company is obligated to review and demand assurances from its own suppliers, and you are one of them.
This explains something many small companies are already living through: longer security questionnaires, new contract clauses about incident management, requests for evidence of technical controls before a contract is renewed. It doesn't arrive as a law enforced by a regulator; it arrives as an email from your client asking you to fill out a form by Friday. It's the most honest way to explain why a 30-person company in no regulated sector ends up investing in cybersecurity: the real driver is the pressure the directive puts on whoever buys from you, more than the directive itself.
Preparing for those questionnaires with a risk assessment done ahead of time changes the conversation with a large client completely. Instead of improvising answers, you hand over a report.
What already applies to you today: GDPR
Here there is no ambiguity and no "not yet". The GDPR (Regulation (EU) 2016/679) applies directly in Spain, complemented by the LOPDGDD (Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights). If your company processes personal data belonging to customers, employees or suppliers, and almost every company does, you have been subject to both from day one of operating.
A few points that tend to surprise a leadership team that has never sat down to review this:
- GDPR Article 33 requires notifying a personal data breach to the relevant supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the people affected.
- The LOPDGDD, in its Article 76, applies the GDPR's own sanction tiers: fines can reach up to 10 million euros or 2% of annual global turnover for lower-tier infringements, and up to 20 million euros or 4% for the more serious ones, whichever figure is higher.
- This duty exists regardless of company size. There is no small-business exemption in the GDPR.
Spain's data protection authority, the AEPD (Agencia Española de Protección de Datos), offers free tools built specifically for small companies: Facilita RGPD helps build the record of processing activities and the minimum required policies, and Asesora Brecha helps decide whether a specific incident must be notified within the 72 hour window. Both are a reasonable starting point if you have nothing documented yet, though neither replaces a risk assessment built around how your business actually operates.
Two more frameworks worth knowing, even if they don't apply to everyone
ENS, if you work with the public sector
Spain's National Security Framework, known as ENS (Real Decreto 311/2022, of 3 May), is aimed primarily at the public sector. Its Article 2.3 also reaches private companies that provide services or solutions to the public sector under contract, and explicitly extends that requirement to those contractors' own supply chain. If you sell to a town hall, a regional government or any public body, or if you are a subcontractor to someone who does, ENS can apply to you even if your company had never heard of it before.
DORA, only if you work with financial institutions
Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025, governs the digital operational resilience of banks, insurers and financial entities, and also reaches their third-party ICT service providers. It is only relevant to your company if your client is a bank, an insurer or a payment institution and you provide them software or technology services.
The certification that opens doors without being a legal requirement
ISO 27001 is not a legal requirement for any Spanish SME. It is, instead, what an increasing number of clients and public tenders ask for as a condition of entry. Treating it as an obligation is a framing mistake. Treating it as a commercial calling card in front of demanding clients is accurate, and it's usually the natural next step once GDPR and the basic controls are already in order.
Where to start without getting lost in the fine print
With this many regulations in play, it's easy to freeze. The order that makes sense for a 10 to 50 employee company looks like this:
- Close out GDPR and LOPDGDD compliance first: both are mandatory today and the fines are real.
- Document what data you process, where it lives and who can access it, using Facilita RGPD as a starting point if you haven't begun.
- Check whether you sell, directly or indirectly, to the public sector (ENS) or the financial sector (DORA).
- Assume a security questionnaire from a large client is coming, and prepare with a risk assessment before it arrives instead of after.
- Consider ISO 27001 once the commercial case justifies it, not before.
If you'd rather have someone with real experience review your specific situation and tell you clearly what applies and what doesn't, a virtual CISO can deliver that diagnosis in weeks, not months, without you having to hire anyone in house.
Want to know how exposed your website is?
Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.