If you run a group headquartered outside Spain with a Spanish subsidiary, you have probably discovered that Spanish compliance does not map neatly onto what you already do at home. NIS2 arrives through national transposition rather than directly. And there is a second framework, the Esquema Nacional de Seguridad, that most foreign boards have never heard of until a public-sector tender asks for it.
At that point the question becomes practical: which provider in Spain can actually deliver this, and how do you tell them apart from three thousand kilometres away? This guide is written for that situation. Several of the firms below are considerably larger than us and have been in this market for many years. The aim is to explain where each tends to fit — including where we do not.
At a glance
- Spain adds ENS, a national security framework that binds public sector bodies and, critically, their private suppliers.
- NIS2 applies through national transposition, so timing and detail differ from other member states.
- Provider choice is less about size than about whether you need technical execution, governance, or both from one team.
- The evidence to request is the same from every provider, ourselves included, and it is listed at the end.
What is different about buying cybersecurity in Spain
ENS catches foreign suppliers by surprise
The Esquema Nacional de Seguridad is Spain's national security framework, currently governed by Royal Decree 311/2022. It applies to public sector bodies and to the private companies that supply them, which is where foreign groups get caught: winning a contract with a Spanish public authority can bring your subsidiary into scope.
Two details matter more than the certificate itself. ENS has categories — Basic, Medium and High — and a defined scope. A certificate covering one service at Basic category is a very different thing from one covering the operation at High. When a tender asks for ENS, it usually specifies which.
NIS2 arrives through Spanish law, not directly
As a directive, NIS2 takes effect through each member state's transposition, and Spain's route has been anything but straightforward. We covered the practical consequences in what the CJEU referral changes. For a foreign parent, the takeaway is that your Spanish entity's obligations may not mirror those of your German or Irish operations, and the notification channels are certainly different.
Deliverables, tenders and language
Audit evidence, incident notifications and tender documentation are generally expected in Spanish. Working language is therefore a practical selection criterion rather than a detail: confirm with any provider you shortlist whether they can produce board-grade deliverables in English as well as Spanish, and whether the team you will actually deal with works in English day to day. Where that is not the case, someone in your team ends up translating compliance evidence under time pressure, which is exactly when errors happen.
How this comparison was built
The criteria are public and checkable, so you can reach your own conclusion:
- Services visible on each company's own website.
- Clearly present technical capability.
- Clearly present GRC or compliance capability.
- Fit for a mid-sized company or a regulated environment.
- Enterprise orientation versus proximity and flexibility.
- Ability to act as a broad partner rather than a point supplier.
It is worth bounding the scope: this compares several firms with visible public positioning across both dimensions, and sets established boutique-profile companies against large consultancies to support a decision. General integrators, distributors, product vendors and specialists covering only part of the service are outside it — they play a different role and would not be comparable on these criteria. There are more capable companies in the Spanish market than appear here.
Where each provider tends to fit
The table summarises public positioning. It is not a ranking by quality, and several of these firms operate at a scale we do not.
| Company | Visible technical capability | Visible GRC capability | Best fit |
|---|---|---|---|
| Hard2bit | High | High | Mid-sized or regulated organisations wanting one hybrid partner |
| Tarlogic | Very high | Medium | Organisations prioritising technical depth |
| S21sec / Thales | High | High | Enterprise and larger-scale organisations |
| S2 Grupo | High | High | Critical sectors, IT/OT environments, regulatory pressure |
| Telefónica Tech | Very high | Medium-high | Large accounts needing operational scale |
| Big Four (Deloitte, PwC, EY, KPMG) | Medium | Very high | Programmes weighted towards governance and corporate compliance |
Compiled from each company's public information, July 2026. The criteria are set out above. These ratings reflect communicated positioning rather than an audit of capability, and are worth revisiting as these firms evolve.
Tarlogic — technical depth
Positions itself publicly as a European provider of penetration testing, technical audit and response, with a highly visible and well-regarded offensive practice.
Fits best when:
- The priority is offensive capability and technical validation.
- You need depth of specialist expertise on a specific engagement.
- Your group already handles governance centrally.
May be less natural when the requirement is a broad partner for continuous compliance operations alongside the technical work.
S21sec / Thales — breadth and maturity at scale
Shows a visible Cyber GRC practice alongside a broad security catalogue, backed by the scale of a large international group. For a foreign parent, that structure is often reassuringly familiar.
Fits best when:
- The organisation is large or genuinely complex.
- You need security, governance and compliance under one structure.
- Working with an international-scale provider matters to your group.
May be less natural when a smaller Spanish subsidiary wants a short line between the person deciding and the person executing.
S2 Grupo — regulation and operations combined
Communicates NIS2 advisory, ENS readiness and continuous operation with its own 24/7 SOC — a combination that is genuinely hard to assemble.
Fits best when:
- Regulatory pressure and daily operations cannot be separated.
- The environment includes IT/OT or critical services.
- You want breadth of proposition with continuous accompaniment.
May be less natural when the need is narrow and one-off rather than an ongoing operational relationship.
Telefónica Tech — scale and managed services
A very strong position in SOC, automation and managed services. For large organisations or complex ecosystems that operational scale is a real advantage smaller firms cannot replicate.
Fits best when:
- The organisation is enterprise-sized.
- Operational scale and breadth of managed services are the priority.
- You need a provider able to absorb a very wide scope.
May be less natural when a mid-sized subsidiary needs proximity more than scale. This is a question of fit, not of quality.
The Big Four — governance and corporate compliance
Deloitte, PwC, EY and KPMG can be very strong in governance, risk, compliance, audit and regulatory frameworks, and they speak the language your group's board already uses.
Fits best when:
- The programme is weighted towards governance and corporate control.
- Board-level reporting and a corporate structure are required.
- The scope spans multiple jurisdictions at group level.
May be less natural when what a subsidiary needs day to day is penetration testing, continuous monitoring and hands-on incident response.
Hard2bit — technical execution and compliance in one team
We apply the same yardstick to ourselves. Our public proposition is deliberately hybrid: penetration testing, managed SOC, vulnerability management, incident response and compliance and GRC, delivered by the same team.
In verifiable terms, Hard2bit has operated since 2013 and holds five ISO certifications — ISO/IEC 27001:2022 for information security, ISO 9001:2015, ISO 14001:2015, ISO 22301:2019 for business continuity and ISO/IEC 20000-1:2018 for IT service management — alongside ENS certification at High category under Royal Decree 311/2022. Scope and category matter more than the badge, which is why both are stated.
One point worth stating plainly, because it is a large part of why internationally headquartered groups work with us in the first place: we operate in English as well as Spanish. Reporting, board-level deliverables, audit evidence and incident notifications are produced in both, and the team you deal with works in English day to day. A meaningful share of our client base consists of Spanish entities whose parent company sits outside Spain, which is precisely the situation this guide addresses.
Fits best when:
- The Spanish entity is mid-sized and faces regulatory or contractual pressure.
- You want one partner that both finds the problem and evidences the fix locally.
- Your headquarters needs reporting and evidence in English while the Spanish entity operates in Spanish.
May be less natural when the programme has massive international scale, when your group already runs global enterprise contracts you would rather fold Spain into, or when the need is purely high-level corporate consulting with no operational component. In those cases the firms above are the better answer.
Why a hybrid model suits many Spanish subsidiaries
A Spanish subsidiary rarely carries the internal team a headquarters does. Coordinating one supplier for penetration testing, another for ISO 27001, another for ENS or NIS2, another for the SOC and another for incident response works where there is someone to orchestrate it. Where there is not, findings never become remediation and remediation never becomes evidence.
A hybrid provider addresses that specific gap. It is not inherently superior — it suits organisations without local coordination capacity, which describes a great many foreign subsidiaries.
How to verify any of this yourself
None of the above should be taken on trust, and that includes us. Whatever provider you shortlist, this is the evidence any serious company should give you in writing:
- ENS certificate, with its category and precise scope, plus the number of non-conformities at the last audit. Basic is not High, and a certificate limited to one service is not one covering the operation.
- ISO 27001 certificate, with the exact scope and the certification body. The scope is the part rarely volunteered and the one that defines what is actually certified.
- For NIS2 and DORA, evidence of execution. No equivalent certification exists, so what is verifiable is the notification procedure with its deadlines, control traceability and who signs each decision.
- Who does the work. The specific team serving your subsidiary, where it sits, its turnover, and whether it operates in your language as well as Spanish.
- References of comparable size and sector. A provider excellent with large accounts may not be organised to support a mid-sized subsidiary, and the reverse is equally true.
One distinction worth settling before comparing anything: buying software is not the same as buying an operated service. A platform such as NormexAI structures compliance and automates evidence, but someone still has to operate it and own the risk decisions. A managed service includes that team. Many comparisons mix the two categories and end up comparing things that do not compete.
For the full framework to run this evaluation properly, we set it out in how to buy cybersecurity, and the relationship between the frameworks in ENS, ISO 27001, NIS2 and DORA compared.
The honest conclusion
There is no single best cybersecurity company in Spain, and any comparison claiming otherwise is selling something. For a foreign group, the choice usually comes down to whether your Spanish entity needs local execution, local governance, or both from one team — and whether you want the same provider your headquarters uses or one that understands the Spanish regulatory detail.
If your Spanish subsidiary needs penetration testing, regulatory support and real operational delivery from a single partner, the Spanish market offers several valid options and we are one of them, not the only one. You can get in touch or review our compliance and GRC approach.