NIS2 consulting for companies:
compliance, evidenceand demonstrable resilience
Hard2bit's NIS2 consulting takes your organisation from "does it apply to us?" to compliance you can demonstrate:
applicability assessment, Article 21 gap analysis, a roadmap approved by management, control implementation, a 24/72-hour
incident reporting procedure and an evidence dashboard for customers, auditors and the authority.
No obligation · Proposal tailored to your classification and starting point.
Applicability
Which companies does NIS2 apply to?
NIS2 is Directive (EU) 2022/2555 on the security of network and information systems. It requires essential
and important entities across 18 sectors to manage cyber risk, report incidents and answer for it before their
management body. And it reaches, by contract, the suppliers of those entities.
Sectors, thresholds and what each measure requires are explained in detail in our
practical guide to NIS2 compliance in Spain (in Spanish).
Here we focus on how we help you comply.
You operate in a sector listed in Annex I or II of the directive: energy, transport, banking, health, water, digital infrastructure, public administration, ICT, postal, waste, chemicals, food, critical manufacturing or digital providers.
You have 50 or more employees or turnover above €10M, with criticality-based exceptions that reach smaller organisations.
You supply essential or important entities and NIS2 clauses are arriving in contracts, supplier questionnaires or customer audits.
A customer, a tender or the board is asking for NIS2 compliance evidence and you do not know what to hand over.
You already run ISO 27001 or Spain's ENS and need to know what NIS2 adds without duplicating effort.
Check it in five minutes
The regulatory assessment tells you which frameworks apply to you —NIS2, ENS, DORA, ISO 27001— by sector, size and customers.
If the answer is NIS2, the next step is a defensible applicability report.
NIS2 is not met with a folder of policies. It is met with controls that work, owners who answer for them and evidence you
can show. The service covers the eight areas the directive demands.
01
Applicability assessment
We determine whether your organisation is an essential entity, an important entity or an affected supplier, with documented reasoning you can defend before customers and the authority.
02
Article 21 gap analysis
We check the ten risk-management measures against what actually exists: controls, processes, owners and evidence.
03
Governance and management accountability
Approval and oversight of the measures by the management body (Article 20), training for executives and indicator-based reporting.
04
Incident handling and reporting
Classification, escalation and reporting process at 24 hours, 72 hours and one month (Article 23), with playbooks and evidence.
05
Supply chain
Assessment of critical suppliers, contractual clauses and continuous monitoring of third-party risk.
06
Continuity and resilience
Backups, recovery, continuity plans and periodic tests aligned with the services that keep your business running.
07
Technical security
Segmentation, MFA, vulnerability management, hardening, monitoring and detection, prioritised by real exposure.
08
Evidence for audit and supervision
Compliance dashboard and evidence repository ready for the supervisor, the auditor or the customer.
Engagement models
How to engage us for NIS2 compliance
Four ways of working, depending on your starting point. We almost always begin with the assessment: it is short, it scopes
the project and it stops you buying more than you need.
NIS2 assessment and gap analysis
3–5 weeks
Applicability, evaluation of the Article 21 measures against your real situation and a risk-prioritised roadmap. The starting point when you do not know where you stand.
Defensible applicability report
Gap per measure with criticality
6-month roadmap with indicative budget
Full NIS2 alignment
4–6 months
We lead and implement the programme with you: governance, policies, incident and third-party management, continuity and technical controls, until the evidence is verifiable.
One clear project owner
Controls implemented, not just documented
Ready for audit, customer or supervisor
NIS2 on top of ENS or ISO 27001
2–4 months
If you already run a management system, we map NIS2 onto it and cover only the difference: reporting, management accountability, supply chain and resilience.
No duplicated controls or documentation
One evidence trail for several frameworks
Ideal for public-sector suppliers
NIS2 maintenance and vCISO
Recurring
After alignment someone has to sustain it: committee, indicators, third-party reviews, reporting drills and updates as the Spanish law lands.
Adjustable monthly commitment
Representation before customers and the authority
Coordinated with our vCISO
Methodology
How we approach NIS2 alignment
Six phases, from applicability to maintenance. Each ends with a deliverable that management can approve.
01
01 · Applicability and scope
Sector, size, services provided and position in the supply chain. We decide with documented criteria whether you are an essential entity, an important entity or an affected supplier, and which systems are in scope.
02
02 · Article 21 gap analysis
Interviews, document review and technical verification of the ten measures. Each gap gets a criticality and an estimated effort.
03
03 · Roadmap and management decision
A 6-month plan prioritised by risk, with owners and budget. The management body approves it: that is its obligation and the first piece of evidence.
04
04 · Control implementation
Minimum policies and procedures, incident reporting process, third-party management, continuity and technical measures. We work with your team and your suppliers.
05
05 · Drill and evidence
A 24/72-hour reporting exercise, a continuity test and the evidence dashboard. We check the system works before a real incident tests it.
06
06 · Closure and maintenance
Compliance report for management, executive training and a maintenance plan with indicators. Optionally, recurring follow-up.
Deliverables
What you receive in a NIS2 alignment project
01
Applicability report
Classification as essential entity, important entity or affected supplier, with the reasoning you can present to customers and the authority.
02
Article 21 gap analysis
Status of each measure, criticality, effort and required evidence. The document that structures the project.
03
Roadmap approved by management
6-month plan with owners, budget and the management body's approval minutes.
04
Incident reporting procedure
Significant-incident criteria, 24 h / 72 h / 1 month deadlines, templates and channel with the competent authority.
05
Essential policies and procedures
Risk management, third parties, continuity, access control, cryptography and cyber hygiene, at the minimum viable level.
06
Evidence dashboard and training
Evidence repository, indicators for the committee and recorded training for the management body.
Regulatory context
NIS2 in Spain: where things stand
Directive (EU) 2022/2555
had to be transposed by 17 October 2024. Spain missed the deadline and the European Commission referred the delay to the
Court of Justice of the EU. While the draft Cybersecurity Coordination and Governance Act works its way through parliament,
the directive is already the benchmark demanded by customers, insurers and tenders.
Our recommendation is to align with the directive now and adjust the details —competent authority, registration, penalties— once
the Spanish law sets them. Those who wait for the law end up complying in a hurry, on someone else's deadlines.
In force since January 2023. Transposition deadline: 17 October 2024.
Spain
No transposition law on time. The Commission referred Spain to the CJEU over the delay; the draft Cybersecurity Coordination and Governance Act is still going through the legislative process.
What it means for you
The directive's obligations are already the benchmark demanded by customers, insurers and tenders. Preparing now avoids rushing once the law sets deadlines and penalties.
Penalties foreseen
Up to €10M or 2% of worldwide turnover for essential entities; up to €7M or 1.4% for important entities. With personal liability for executives.
Fit with other frameworks
NIS2 on top of ENS, ISO 27001, DORA or PCI DSS: one evidence trail
Most companies affected by NIS2 already carry another framework. Our job is to make sure you do not pay twice for the same control.
NIS2 and ENS
If you serve the Spanish public sector, the ENS is mandatory and covers most of Article 21. NIS2 adds reporting, management accountability and supply chain.
If you process cards, PCI DSS coexists with NIS2: one governs overall risk and the other the cardholder data environment. One evidence trail serves both.
It is the service that takes an organisation from "I think NIS2 applies to us" to demonstrable compliance: applicability assessment, gap analysis of the Article 21 measures, a roadmap approved by management, implementation of controls and procedures, an incident reporting process and an evidence dashboard.
We are an 80-person company providing ICT services to an essential entity: does NIS2 apply to us?
Very probably, in two ways: by size and sector if you fall under the directive's annexes, and in any case through the supply chain, because your customer must demand guarantees from its critical suppliers. The applicability assessment settles it with documented criteria. You can run a first check with the regulatory assessment.
How do I hire a NIS2 consultancy and what should I ask for?
Ask for three things: a defensible applicability report before they sell you a project, controls implemented rather than documents delivered, and audited experience in equivalent frameworks. Hard2bit operates certified to Spain's ENS (HIGH category) and ISO 27001, so we have been through the same process that awaits you.
How long does NIS2 alignment take?
An assessment and gap analysis takes 3–5 weeks. Full alignment from scratch usually needs 4 to 6 months. If you already have ISO 27001 or ENS, covering the difference takes 2–4 months.
How much does NIS2 consulting cost?
It depends mainly on your classification, your starting point and the number of systems and suppliers in scope. A gap analysis is a bounded project of a few weeks; full alignment is quoted in phases after the assessment. We send a fixed proposal after a no-obligation scoping session.
Spain has not transposed NIS2 yet: does it make sense to align now?
Yes. The directive is already the benchmark demanded by customers, insurers and tenders, and the Spanish law will arrive with short deadlines. Besides, NIS2 controls are resilience good practices with value of their own. We explain the situation in NIS2 in Spain after the CJEU referral: what to do without a national law.
What does Article 21 of NIS2 require?
Ten risk-management measures: risk analysis and policies, incident handling, continuity and backups, supply chain security, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, personnel security and access control, and multi-factor authentication and secure communications. We cover them one by one in our practical guide to NIS2 compliance in Spain (in Spanish).
What accountability do executives have under NIS2?
Article 20 requires the management body to approve and oversee the risk-management measures and to receive cybersecurity training, and provides for personal liability in case of non-compliance. That is why management approves the roadmap and why we include recorded training for them.
What are the incident reporting deadlines?
Early warning within 24 hours of becoming aware of a significant incident, notification with an initial assessment within 72 hours and a final report within one month. The procedure we deliver sets significance criteria, owners, templates and the channel with the competent authority.
We already have ISO 27001 or ENS: what is missing for NIS2?
Usually four things: the reporting process with its deadlines, formal accountability and training of the management body, active supply chain management and continuity testing. We map it onto your system and cover only the difference. We compare the four frameworks in ENS vs ISO 27001 vs NIS2 vs DORA.
NIS2 or DORA for a financial entity?
DORA is the sector-specific regulation for finance and prevails over NIS2 in what it governs. We explain it in NIS2 vs DORA and offer dedicated DORA consulting.
What penalties does NIS2 provide for?
Up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities, plus administrative measures and executive liability. The final figures in Spain will be set by the transposition law.
Do you provide NIS2 consulting across Spain and the EU?
Yes. The Compliance and GRC team works from Madrid for organisations across Spain and the European Union, remotely and on site for the sessions that require it: kick-off, management committee and drills.
Reviewed by Thilina Manana and Hard2bit's Compliance and GRC team
Last reviewed:
Cookies and privacy
We value your privacy
We use necessary cookies to make the site work. With your consent, we also use analytics and marketing cookies to understand usage and improve. You choose — and you can change it whenever you want.
Quick 15-minute assessment and we'll tell you what to prioritise first: Microsoft 365, pentesting, vulnerability management, SOC, DORA, NIS2, ENS or ISO 27001.