No Spanish law yet; commercial demands already
Directive (EU) 2022/2555 is in force across the Union, but Spain has not passed the law that transposes it, and the European Commission has taken the delay to the Court of Justice. So today there is no direct legal obligation on your company under NIS2. We say it plainly because some people sell the opposite.
What does exist is the knock-on effect: the entities that will be covered are already managing their suppliers' risk, because the directive itself requires them to. That's why your customer's security questionnaire, the new clause in the contract or the request to 'demonstrate measures' arrive before the BOE does. Getting ahead isn't about complying with a law that doesn't exist yet: it's about continuing to sell to those who will have to.
An analysis written from the supplier's side
Map against the Article 21 measures
Risk policies, incident handling, business continuity, supply chain, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, access control, authentication. Where you stand on each, with or without evidence.
Your customer's questionnaire, answered
We take the actual questionnaire you've been sent (or the standard one large buyers use) and turn it into defensible answers with the evidence you already have and the evidence you're missing.
Supply chain in both directions
What you'll be asked for as a supplier and what you should ask of your own suppliers (hosting, SaaS, outsourced support). A security annex for contracts you can actually use.
Incidents and notification
What you need in place to detect, log and notify an incident within the timelines the directive sets (early warning, notification, final report), even if today only a customer is asking.
Prioritised, budgetable closure plan
The gaps ranked by risk and by what buyers ask about most, with effort estimates. What you can do yourself, what makes sense to outsource, and in what order.
Ready for the day it hits the BOE
When the transposition is approved, we review with you what changes against what you already have. Most of the work will already be done: that's the advantage of getting ahead.
- —Implementing the measures: the gap analysis diagnoses and plans; implementation is Ongoing support or a separate project, and the plan shows what your own team can do.
- —Certifications (ISO 27001, ENS — Spain's National Security Framework, mandatory for public-sector suppliers): we leave you aligned with them so no work is duplicated, but the certification is issued by an accredited third party.
- —Determining whether your company will be legally covered by the Spanish law: the text that gets passed will decide that; today we work from the directive and from what your customers are asking for.
- —Intrusive technical testing (pentest): the analysis is documentary and evidence-based; if needed, the pentest is contracted as a specific service.
- Deliverable
- Measure-by-measure gap report (Article 21), answers and evidence for your customer's questionnaire, a security annex for your suppliers and a prioritised closure plan, with a presentation session for management.
- Duration
- 3–4 weeks: interviews, document and evidence review, report.
- Price
- Fixed price, agreed in writing before we start, based on size and number of sites or systems.
- Next step
- Send us the questionnaire you've received (or tell us what you're being asked for) and within 48 hours we tell you which parts you can already answer and where the visible gaps are.
Don't let the questionnaire be what stalls the contract
Start by finding out what your company looks like from the outside with the free Radar scan; the gap analysis does the rest.