NIS2: mandatory cybersecurity for industrial SMEs
EU Directive 2022/2555 in force in Spain. Who's required and penalties for non-compliance.
Flux Team 1 April 2026 8 min
NIS2: mandatory cybersecurity
The NIS2 Directive (2022/2555) was transposed in Spain via RD-Law 7/2025 and is now in force. It extends cybersecurity measure obligations to a much wider universe of companies, including many industrial SMEs.
Who's required
"Essential entities" (strict obligations)
- Energy, transport, banking, health, water, digital infrastructure
- SMEs >50 employees or >€10M revenue in these sectors
"Important entities" (standard obligations)
- Critical manufacturing (chemical, electronics, vehicles)
- Food production and distribution
- Industrial companies >50 employees >€10M revenue
- Postal services, waste management, research
What it requires
- Documented security policy
- Annual risk analysis
- Incident management plan with 24h notification to CNPIC
- Encrypted backups with restoration tests
- Employee cybersecurity training
- Periodic audit (external certified for >250 employees)
Penalties
Article 35 RD-Law 7/2025 establishes:
- Essential entities: up to €10M or 2% global revenue (whichever higher)
- Important entities: up to €7M or 1.4% global revenue
- Personal CEO liability: temporary disqualification possible in serious cases
Why industrial SMEs are at risk
- 97% of SMEs have no formal cybersecurity policy
- Industrial ransomware attacks rose +89% in 2025
- Average production downtime after attack: 18 days
- Average cost: €180,000-450,000 per incident (recovery + lost revenue)
What to do
- Digital asset inventory (who has access to what)
- Mandatory MFA on all admin accounts
- 3-2-1 backups (3 copies, 2 media types, 1 offsite)
- Quarterly training on phishing, passwords
- Documented incident plan with 5-10 scenarios
- Cyber insurance (~€3,000-12,000/year for industrial SMEs)
The "we're small, no one will attack us" excuse is statistically false. SMEs are the preferred target for ransomware because they pay.
#nis2#cybersecurity#ransomware