HomeFluxBLOG
regulation

NIS2: mandatory cybersecurity for industrial SMEs

EU Directive 2022/2555 in force in Spain. Who's required and penalties for non-compliance.

Flux Team 1 April 2026 8 min

NIS2: mandatory cybersecurity

The NIS2 Directive (2022/2555) was transposed in Spain via RD-Law 7/2025 and is now in force. It extends cybersecurity measure obligations to a much wider universe of companies, including many industrial SMEs.

Who's required

"Essential entities" (strict obligations)

  • Energy, transport, banking, health, water, digital infrastructure
  • SMEs >50 employees or >€10M revenue in these sectors

"Important entities" (standard obligations)

  • Critical manufacturing (chemical, electronics, vehicles)
  • Food production and distribution
  • Industrial companies >50 employees >€10M revenue
  • Postal services, waste management, research

What it requires

  • Documented security policy
  • Annual risk analysis
  • Incident management plan with 24h notification to CNPIC
  • Encrypted backups with restoration tests
  • Employee cybersecurity training
  • Periodic audit (external certified for >250 employees)

Penalties

Article 35 RD-Law 7/2025 establishes:

  • Essential entities: up to €10M or 2% global revenue (whichever higher)
  • Important entities: up to €7M or 1.4% global revenue
  • Personal CEO liability: temporary disqualification possible in serious cases

Why industrial SMEs are at risk

  • 97% of SMEs have no formal cybersecurity policy
  • Industrial ransomware attacks rose +89% in 2025
  • Average production downtime after attack: 18 days
  • Average cost: €180,000-450,000 per incident (recovery + lost revenue)

What to do

  • Digital asset inventory (who has access to what)
  • Mandatory MFA on all admin accounts
  • 3-2-1 backups (3 copies, 2 media types, 1 offsite)
  • Quarterly training on phishing, passwords
  • Documented incident plan with 5-10 scenarios
  • Cyber insurance (~€3,000-12,000/year for industrial SMEs)

The "we're small, no one will attack us" excuse is statistically false. SMEs are the preferred target for ransomware because they pay.

#nis2#cybersecurity#ransomware

Share

Contact us

Let's talk

Questions? Drop a message — we reply within 24h.

hola@fluxsaas.com

Usem cookies necessaries per al funcionament del servei. Llegir politica de cookies