AI-generated image

NIS2 · Directive (EU) 2022/2555

NIS2 consulting for companies: compliance, evidence and demonstrable resilience

Hard2bit's NIS2 consulting takes your organisation from "does it apply to us?" to compliance you can demonstrate: applicability assessment, Article 21 gap analysis, a roadmap approved by management, control implementation, a 24/72-hour incident reporting procedure and an evidence dashboard for customers, auditors and the authority.

Gap analysis
3–5 weeks
Full alignment
4–6 months
Incident reporting
24 h · 72 h · 1 month

No obligation · Proposal tailored to your classification and starting point.

Applicability

Which companies does NIS2 apply to?

NIS2 is Directive (EU) 2022/2555 on the security of network and information systems. It requires essential and important entities across 18 sectors to manage cyber risk, report incidents and answer for it before their management body. And it reaches, by contract, the suppliers of those entities.

Sectors, thresholds and what each measure requires are explained in detail in our practical guide to NIS2 compliance in Spain (in Spanish). Here we focus on how we help you comply.

  • You operate in a sector listed in Annex I or II of the directive: energy, transport, banking, health, water, digital infrastructure, public administration, ICT, postal, waste, chemicals, food, critical manufacturing or digital providers.
  • You have 50 or more employees or turnover above €10M, with criticality-based exceptions that reach smaller organisations.
  • You supply essential or important entities and NIS2 clauses are arriving in contracts, supplier questionnaires or customer audits.
  • A customer, a tender or the board is asking for NIS2 compliance evidence and you do not know what to hand over.
  • You already run ISO 27001 or Spain's ENS and need to know what NIS2 adds without duplicating effort.

Check it in five minutes

The regulatory assessment tells you which frameworks apply to you —NIS2, ENS, DORA, ISO 27001— by sector, size and customers. If the answer is NIS2, the next step is a defensible applicability report.

Run the assessment

Service scope

What our NIS2 consulting includes

NIS2 is not met with a folder of policies. It is met with controls that work, owners who answer for them and evidence you can show. The service covers the eight areas the directive demands.

Applicability assessment

We determine whether your organisation is an essential entity, an important entity or an affected supplier, with documented reasoning you can defend before customers and the authority.

Article 21 gap analysis

We check the ten risk-management measures against what actually exists: controls, processes, owners and evidence.

Governance and management accountability

Approval and oversight of the measures by the management body (Article 20), training for executives and indicator-based reporting.

Incident handling and reporting

Classification, escalation and reporting process at 24 hours, 72 hours and one month (Article 23), with playbooks and evidence.

Supply chain

Assessment of critical suppliers, contractual clauses and continuous monitoring of third-party risk.

Continuity and resilience

Backups, recovery, continuity plans and periodic tests aligned with the services that keep your business running.

Technical security

Segmentation, MFA, vulnerability management, hardening, monitoring and detection, prioritised by real exposure.

Evidence for audit and supervision

Compliance dashboard and evidence repository ready for the supervisor, the auditor or the customer.

Engagement models

How to engage us for NIS2 compliance

Four ways of working, depending on your starting point. We almost always begin with the assessment: it is short, it scopes the project and it stops you buying more than you need.

NIS2 assessment and gap analysis

3–5 weeks

Applicability, evaluation of the Article 21 measures against your real situation and a risk-prioritised roadmap. The starting point when you do not know where you stand.

  • Defensible applicability report
  • Gap per measure with criticality
  • 6-month roadmap with indicative budget

Full NIS2 alignment

4–6 months

We lead and implement the programme with you: governance, policies, incident and third-party management, continuity and technical controls, until the evidence is verifiable.

  • One clear project owner
  • Controls implemented, not just documented
  • Ready for audit, customer or supervisor

NIS2 on top of ENS or ISO 27001

2–4 months

If you already run a management system, we map NIS2 onto it and cover only the difference: reporting, management accountability, supply chain and resilience.

  • No duplicated controls or documentation
  • One evidence trail for several frameworks
  • Ideal for public-sector suppliers

NIS2 maintenance and vCISO

Recurring

After alignment someone has to sustain it: committee, indicators, third-party reviews, reporting drills and updates as the Spanish law lands.

  • Adjustable monthly commitment
  • Representation before customers and the authority
  • Coordinated with our vCISO

Methodology

How we approach NIS2 alignment

Six phases, from applicability to maintenance. Each ends with a deliverable that management can approve.

  1. 01 · Applicability and scope

    Sector, size, services provided and position in the supply chain. We decide with documented criteria whether you are an essential entity, an important entity or an affected supplier, and which systems are in scope.

  2. 02 · Article 21 gap analysis

    Interviews, document review and technical verification of the ten measures. Each gap gets a criticality and an estimated effort.

  3. 03 · Roadmap and management decision

    A 6-month plan prioritised by risk, with owners and budget. The management body approves it: that is its obligation and the first piece of evidence.

  4. 04 · Control implementation

    Minimum policies and procedures, incident reporting process, third-party management, continuity and technical measures. We work with your team and your suppliers.

  5. 05 · Drill and evidence

    A 24/72-hour reporting exercise, a continuity test and the evidence dashboard. We check the system works before a real incident tests it.

  6. 06 · Closure and maintenance

    Compliance report for management, executive training and a maintenance plan with indicators. Optionally, recurring follow-up.

Deliverables

What you receive in a NIS2 alignment project

Applicability report

Classification as essential entity, important entity or affected supplier, with the reasoning you can present to customers and the authority.

Article 21 gap analysis

Status of each measure, criticality, effort and required evidence. The document that structures the project.

Roadmap approved by management

6-month plan with owners, budget and the management body's approval minutes.

Incident reporting procedure

Significant-incident criteria, 24 h / 72 h / 1 month deadlines, templates and channel with the competent authority.

Essential policies and procedures

Risk management, third parties, continuity, access control, cryptography and cyber hygiene, at the minimum viable level.

Evidence dashboard and training

Evidence repository, indicators for the committee and recorded training for the management body.

Regulatory context

NIS2 in Spain: where things stand

Directive (EU) 2022/2555 had to be transposed by 17 October 2024. Spain missed the deadline and the European Commission referred the delay to the Court of Justice of the EU. While the draft Cybersecurity Coordination and Governance Act works its way through parliament, the directive is already the benchmark demanded by customers, insurers and tenders.

Our recommendation is to align with the directive now and adjust the details —competent authority, registration, penalties— once the Spanish law sets them. Those who wait for the law end up complying in a hurry, on someone else's deadlines.

NIS2 in Spain after the CJEU referral: what to do without a national law →
Directive (EU) 2022/2555
In force since January 2023. Transposition deadline: 17 October 2024.
Spain
No transposition law on time. The Commission referred Spain to the CJEU over the delay; the draft Cybersecurity Coordination and Governance Act is still going through the legislative process.
What it means for you
The directive's obligations are already the benchmark demanded by customers, insurers and tenders. Preparing now avoids rushing once the law sets deadlines and penalties.
Penalties foreseen
Up to €10M or 2% of worldwide turnover for essential entities; up to €7M or 1.4% for important entities. With personal liability for executives.

Fit with other frameworks

NIS2 on top of ENS, ISO 27001, DORA or PCI DSS: one evidence trail

Most companies affected by NIS2 already carry another framework. Our job is to make sure you do not pay twice for the same control.

NIS2 and ENS

If you serve the Spanish public sector, the ENS is mandatory and covers most of Article 21. NIS2 adds reporting, management accountability and supply chain.

ENS consulting →

NIS2 and ISO 27001

A certified ISMS is the best foundation for NIS2: Annex A controls cover most technical measures. What is missing is the regulatory fit and reporting.

ISO 27001 consulting →

NIS2 and DORA

If you are a financial entity, DORA is lex specialis and prevails over NIS2. We explain it in the NIS2 vs DORA comparison.

DORA consulting →

NIS2 and PCI DSS

If you process cards, PCI DSS coexists with NIS2: one governs overall risk and the other the cardholder data environment. One evidence trail serves both.

PCI DSS consulting →

Full comparison: ENS vs ISO 27001 vs NIS2 vs DORA · NIS2 vs DORA.

Planning

How long NIS2 consulting takes and what drives its cost

Indicative timelines

Assessment and gap analysis
3–5 weeks
NIS2 on top of ENS or ISO 27001
2–4 months
Full alignment from scratch
4–6 months
Maintenance
Recurring, monthly commitment

Timelines depend on the availability of your team and your suppliers to implement; the consulting work is rarely the bottleneck.

What determines the cost

  • Classification: essential entity, important entity or affected supplier.
  • Starting point: an existing ISMS (ISO 27001) or ENS certification cuts the effort substantially.
  • Size and spread: sites, subsidiaries, services and systems in scope.
  • Technical maturity: monitoring, vulnerability management and continuity already running or still to build.
  • Number of critical suppliers to assess.
  • Engagement model: assessment only, full alignment or recurring maintenance.
Request a fixed proposal

NIS2 consulting frequently asked questions

What is NIS2 consulting and what does it include?
It is the service that takes an organisation from "I think NIS2 applies to us" to demonstrable compliance: applicability assessment, gap analysis of the Article 21 measures, a roadmap approved by management, implementation of controls and procedures, an incident reporting process and an evidence dashboard.
We are an 80-person company providing ICT services to an essential entity: does NIS2 apply to us?
Very probably, in two ways: by size and sector if you fall under the directive's annexes, and in any case through the supply chain, because your customer must demand guarantees from its critical suppliers. The applicability assessment settles it with documented criteria. You can run a first check with the regulatory assessment.
How do I hire a NIS2 consultancy and what should I ask for?
Ask for three things: a defensible applicability report before they sell you a project, controls implemented rather than documents delivered, and audited experience in equivalent frameworks. Hard2bit operates certified to Spain's ENS (HIGH category) and ISO 27001, so we have been through the same process that awaits you.
How long does NIS2 alignment take?
An assessment and gap analysis takes 3–5 weeks. Full alignment from scratch usually needs 4 to 6 months. If you already have ISO 27001 or ENS, covering the difference takes 2–4 months.
How much does NIS2 consulting cost?
It depends mainly on your classification, your starting point and the number of systems and suppliers in scope. A gap analysis is a bounded project of a few weeks; full alignment is quoted in phases after the assessment. We send a fixed proposal after a no-obligation scoping session.
Spain has not transposed NIS2 yet: does it make sense to align now?
Yes. The directive is already the benchmark demanded by customers, insurers and tenders, and the Spanish law will arrive with short deadlines. Besides, NIS2 controls are resilience good practices with value of their own. We explain the situation in NIS2 in Spain after the CJEU referral: what to do without a national law.
What does Article 21 of NIS2 require?
Ten risk-management measures: risk analysis and policies, incident handling, continuity and backups, supply chain security, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, personnel security and access control, and multi-factor authentication and secure communications. We cover them one by one in our practical guide to NIS2 compliance in Spain (in Spanish).
What accountability do executives have under NIS2?
Article 20 requires the management body to approve and oversee the risk-management measures and to receive cybersecurity training, and provides for personal liability in case of non-compliance. That is why management approves the roadmap and why we include recorded training for them.
What are the incident reporting deadlines?
Early warning within 24 hours of becoming aware of a significant incident, notification with an initial assessment within 72 hours and a final report within one month. The procedure we deliver sets significance criteria, owners, templates and the channel with the competent authority.
We already have ISO 27001 or ENS: what is missing for NIS2?
Usually four things: the reporting process with its deadlines, formal accountability and training of the management body, active supply chain management and continuity testing. We map it onto your system and cover only the difference. We compare the four frameworks in ENS vs ISO 27001 vs NIS2 vs DORA.
NIS2 or DORA for a financial entity?
DORA is the sector-specific regulation for finance and prevails over NIS2 in what it governs. We explain it in NIS2 vs DORA and offer dedicated DORA consulting.
What penalties does NIS2 provide for?
Up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities, plus administrative measures and executive liability. The final figures in Spain will be set by the transposition law.
Do you provide NIS2 consulting across Spain and the EU?
Yes. The Compliance and GRC team works from Madrid for organisations across Spain and the European Union, remotely and on site for the sessions that require it: kick-off, management committee and drills.
Where does NIS2 sit within Hard2bit's services?
It belongs to the Compliance and GRC practice, alongside ENS, ISO 27001 and DORA. It relies on the managed SOC for detection and on incident response for reporting and containment.

Concepts from our cybersecurity glossary that connect directly with this service.

Comply with NIS2 before someone sets your deadline

In a 45-minute scoping session we review applicability, starting point and engagement model, and send you a fixed proposal.

Reviewed by Thilina Manana and Hard2bit's Compliance and GRC team

Last reviewed: