NIS2: what we learned from the first year of applying it
Table of contents
- Key takeaways
- 24-hour notifications: the most disruptive change
- Supply chain: pressure reaching SMEs
- Personal liability: tone change without consequences yet
- Country differences: the fragmentation problem
- What has moved the needle most in real practice
- My read
- Frequently asked questions
- How long do I have to notify an incident under NIS2?
- What do I do if a large client sends my SME a 150-question NIS2 security questionnaire we cannot answer?
- Have executives already been sanctioned for NIS2 non-compliance in Spain?
- Sources
NIS2 entered force on 17 October 2024. Six months later, companies are in the trenches. I cover what has actually changed in operational security, what was paper theater, and where the directive still bites.
NIS2 entered force on 17 October 2024 and this April we are just over six months into real application. During that time, obligations that looked like paper have become operational practice and some predictions fell short. A layer of inconsistency between member states has also emerged, one the directive didn’t prevent well. This post collects what I’ve seen in Spanish companies I work with and contrasts it with public reports from ENISA and national authorities.
The transposition context is covered in the analysis of NIS2: transposition to the Spanish state. For the broader European compliance framework connecting with NIS2, the post on enterprise AI governance offers the organizational pattern that applies equally here.
Key takeaways
-
24-hour incident notifications are the most disruptive operational change; teams without a prior process have had to improvise.
-
NIS2’s extension to the supply chain is where SMEs feel the most pressure: large companies demand questionnaires SMEs don’t know how to answer.
-
Personal liability of executives (art. 20) has changed the tone of board conversations, but hasn’t yet generated real consequences in Spain.
-
Transposition inconsistency between EU countries complicates compliance for multinational groups.
-
What has moved the needle most in real practice: asset inventory, vulnerability management, and continuity testing.
24-hour notifications: the most disruptive change
Article 23 of NIS2 establishes a cascading notification obligation. The initial notice to the competent authority goes out within 24 hours of becoming aware of a significant incident. A full report follows within 72 hours and a final report within one month. This 24-hour window for the initial notice has been the hardest operational change to absorb.
Teams without a documented incident management process have had to build one under pressure. Recurring problems I’ve seen:
No definition of "significant incident." NIS2 sets criteria (impact on availability, personal data integrity, cross-border consequences), but practical application requires an internal decision threshold. Without that documented threshold, every potential incident generates a long discussion about whether to report, consuming critical time in the worst possible moment.
No clear notification owner. Who makes the notification decision: the CISO, the CEO or Legal?
I have seen companies where, when a real incident occurred, nobody knew who had authority to make the notification, and critical hours were lost.
No prepared notification templates. The 24-hour initial notice doesn’t require the full incident analysis (that’s the 72-hour report), but it does require minimum information on incident type, affected systems, and estimated impact. Having a basic template ready reduces preparation time at the moment of highest stress.
What has worked in the best-prepared companies is an incident playbook that explicitly includes the NIS2 notification process. It documents the decision threshold, names the notification owner, keeps the notification template ready and stores the competent authority contact.
Supply chain: pressure reaching SMEs
NIS2 extends cybersecurity responsibility to the supply chain. An essential or important entity cannot comply with NIS2 while ignoring the security posture of its critical suppliers. This has created a wave of security questionnaires flowing from large companies to their suppliers. Suppliers that are SMEs have neither the resources nor the knowledge to answer them.
The pattern I see repeatedly:
-
The large client sends a 150-question security questionnaire derived from their third-party risk management program.
-
The SME supplier has no answers for most questions because it hasn’t implemented the controls being asked about.
-
The SME has two options: refuse the questionnaire (and lose the client), or answer inaccurately to appear more mature than it is.
Neither is satisfactory, but the second is more frequent. This creates a paper compliance ecosystem that NIS2 aimed to avoid.
The solution beginning to be adopted in some sectors is standardizing the third-party questionnaire using frameworks like ENS (National Security Framework) or ISO 27001 certification as a substitute. An ISO 27001 certified supplier can refer the client to the certificate instead of answering 150 individual questions. But adoption of this practice is uneven.
Personal liability: tone change without consequences yet
Article 20 of NIS2 establishes that management bodies of entities are responsible for supervising cybersecurity risk management measures, and can be held personally liable in cases of serious non-compliance. This provision has had an immediate effect on board conversations: CEOs and directors have started asking about cybersecurity in ways they didn’t before.
However, in Spain and most member states, there are still no public sanctioning resolutions derived from NIS2. The regime is in early application, national authorities are in the process of establishing their supervision procedures, and incomplete transposition deadlines in some states complicate the picture. The effect of personal liability is more attitude change than tangible consequences in this first semester.
What has changed: cybersecurity budgets in companies that previously had no structured program have increased, and the argument "NIS2 requires it" has unlocked conversations the security team had been trying to have for years.
Country differences: the fragmentation problem
NIS2 is an EU directive, but transposition is done individually by member states, and there are significant differences in how it has been implemented:
-
Scope: some states have extended scope beyond the directive’s minimum; others have transposed more restrictively.
-
Size thresholds: the directive sets employee and turnover thresholds to determine whether a company falls in scope, but states have interpretation margin for some sectors.
-
Notification timelines: although the 24/72-hour deadlines are in the directive, interpretation of what constitutes "awareness" of an incident varies.
-
Competent authorities: some states have a single authority; others have one per sector.
For a multinational group with operations in multiple EU countries, this means NIS2 compliance cannot be a single policy: it requires per-country adaptation. Some groups are opting to apply the most demanding standard of the countries they operate in as corporate baseline, which simplifies management at the cost of overcompliance in countries with lower requirements.
What has moved the needle most in real practice
Beyond notification processes and governance, the controls where NIS2 has generated the most work and real value in the companies I’ve accompanied:
Asset inventory. NIS2’s Annex X lists risk management measures explicitly including asset inventory. Companies without an updated inventory of systems, applications, and data have had to build one. The positive side effect: the inventory revealed forgotten systems with outdated versions nobody knew were still active.
Vulnerability management. The vulnerability management cycle (scanning, prioritization, remediation, verification) has gone from informal practice to documented process in the companies I’ve accompanied. Companies already with Trivy, Grype, or equivalent tools integrated in CI have it easier; those who didn’t have had to build from scratch.
Continuity and recovery testing. NIS2 measures include business continuity and disaster recovery, with documented regular testing. The pattern repeated: continuity plans on paper that had never been tested. The compliance process forced real tests, with instructive results: a significant percentage of plans tested didn’t work as expected.
My read
NIS2 is generating real changes in the security posture of companies subject to it, though unevenly. Companies that already had a structured security program have mainly had documentation and process adjustment work. Those that didn’t have had to build from scratch under regulatory pressure, with variable results.
The most lasting changes are not those generated by fear of sanction, but those generated by the shift in board conversation. Article 20’s personal liability has put cybersecurity on the management agenda in a way security teams had been trying to achieve for years. That shift in attention, if sustained, has more value than any specific technical control.
The second year of NIS2 will be that of the first sanctioning resolutions. When they appear, the market effect will be faster than all prior communication: nothing concentrates board attention like seeing an equivalent sector receive a significant sanction with real names attached.
This article is also available in Spanish: NIS2: qué hemos aprendido del primer año aplicándola.
Sources:
- EUR-Lex: Directive (EU) 2022/2555 (NIS2), consolidated text[1]
- ENISA: NIS Directive 2, tasks and transposition timeline[2]
- European Commission: NIS2 Directive, securing network and information systems[3]
- INCIBE-CERT: NIS2, what you need to know[4]
Frequently asked questions
How long do I have to notify an incident under NIS2?
Article 23 sets a cascading notification: the initial notice goes to the competent authority within 24 hours of becoming aware of a significant incident. A full report follows within 72 hours and a final report within one month. The 24-hour notice does not require the full analysis, but it does need minimum information on incident type, affected systems and estimated impact. What works is a playbook with the "significant incident" threshold documented, the notification owner identified, a template prepared and the authority's contact saved.
What do I do if a large client sends my SME a 150-question NIS2 security questionnaire we cannot answer?
Neither refuse it (you lose the client) nor answer inaccurately, which is the most frequent choice and creates the paper compliance NIS2 aimed to avoid. The approach beginning to be adopted in some sectors is to point to a substitute certification. A supplier certified to ISO 27001, or aligned with ENS (Spain's National Security Framework), can refer the client to the certificate instead of answering 150 individual questions. Adoption of this practice is still uneven across sectors.
Have executives already been sanctioned for NIS2 non-compliance in Spain?
No: Article 20 makes management bodies responsible for supervising cybersecurity risk management measures, and personally liable in cases of serious non-compliance. Even so, Spain has published no sanctioning resolutions derived from NIS2, and precedents elsewhere in the EU are scarce. The regime is in early application and national authorities are still establishing their supervision procedures. The effect so far has been a change in attitude, with cybersecurity budgets rising; the first sanctions are expected in the second year.