Home/Services/NIS2 gap analysis

Your biggest customer is going to ask about security. Be ready.

NIS2 (the EU cybersecurity directive) is not yet law in Spain, but your customers who will fall under it are already reviewing their suppliers: questionnaires, new contract clauses, evidence. The gap analysis tells you where you stand against the NIS2 measures and what you're missing, written from your side — the supplier who has to answer — so that when the questionnaire arrives, or the Official State Gazette (BOE) publishes the law, it doesn't catch you starting from scratch.

Where NIS2 stands in Spain today

No Spanish law yet; commercial demands already

Directive (EU) 2022/2555 is in force across the Union, but Spain has not passed the law that transposes it, and the European Commission has taken the delay to the Court of Justice. So today there is no direct legal obligation on your company under NIS2. We say it plainly because some people sell the opposite.

What does exist is the knock-on effect: the entities that will be covered are already managing their suppliers' risk, because the directive itself requires them to. That's why your customer's security questionnaire, the new clause in the contract or the request to 'demonstrate measures' arrive before the BOE does. Getting ahead isn't about complying with a law that doesn't exist yet: it's about continuing to sell to those who will have to.

What's included

An analysis written from the supplier's side

Map against the Article 21 measures

Risk policies, incident handling, business continuity, supply chain, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, access control, authentication. Where you stand on each, with or without evidence.

Your customer's questionnaire, answered

We take the actual questionnaire you've been sent (or the standard one large buyers use) and turn it into defensible answers with the evidence you already have and the evidence you're missing.

Supply chain in both directions

What you'll be asked for as a supplier and what you should ask of your own suppliers (hosting, SaaS, outsourced support). A security annex for contracts you can actually use.

Incidents and notification

What you need in place to detect, log and notify an incident within the timelines the directive sets (early warning, notification, final report), even if today only a customer is asking.

Prioritised, budgetable closure plan

The gaps ranked by risk and by what buyers ask about most, with effort estimates. What you can do yourself, what makes sense to outsource, and in what order.

Ready for the day it hits the BOE

When the transposition is approved, we review with you what changes against what you already have. Most of the work will already be done: that's the advantage of getting ahead.

What's not included
  • Implementing the measures: the gap analysis diagnoses and plans; implementation is Ongoing support or a separate project, and the plan shows what your own team can do.
  • Certifications (ISO 27001, ENS — Spain's National Security Framework, mandatory for public-sector suppliers): we leave you aligned with them so no work is duplicated, but the certification is issued by an accredited third party.
  • Determining whether your company will be legally covered by the Spanish law: the text that gets passed will decide that; today we work from the directive and from what your customers are asking for.
  • Intrusive technical testing (pentest): the analysis is documentary and evidence-based; if needed, the pentest is contracted as a specific service.
How it works
Deliverable
Measure-by-measure gap report (Article 21), answers and evidence for your customer's questionnaire, a security annex for your suppliers and a prioritised closure plan, with a presentation session for management.
Duration
3–4 weeks: interviews, document and evidence review, report.
Price
Fixed price, agreed in writing before we start, based on size and number of sites or systems.
Next step
Send us the questionnaire you've received (or tell us what you're being asked for) and within 48 hours we tell you which parts you can already answer and where the visible gaps are.

Don't let the questionnaire be what stalls the contract

Start by finding out what your company looks like from the outside with the free Radar scan; the gap analysis does the rest.