BLOG · 2026-06-25
NIS2 and the supply chain: your security is your suppliers' security
NIS2 requires managing your suppliers' cyber risk, with real verification. Status in Spain, who it applies to, and the fines.
Quick summary
- Directive (EU) 2022/2555 (NIS2) has been in force at EU level since January 2023; the transposition deadline was 17 October 2024.
- Spain has not completed transposition. It has been partially transposed via Royal Decree-law 7/2025, and the Cybersecurity Coordination and Governance Act is still in the legislative pipeline. The European Commission keeps an infringement procedure open.
- It applies, in general, to entities in 18 critical sectors with 50+ employees or over €10M turnover, with exceptions for SMEs in highly critical sectors.
- A core requirement is supply-chain risk management: you must verify suppliers, not just collect a signed declaration.
- Fines reach €10M or 2% of global turnover, with personal liability for directors and even possible disqualification.
Why does your security depend on your suppliers?
Because your real cybersecurity level is, in practice, the weighted average of the companies you depend on. A compromised supplier can expose your data, break your service and trigger your notification obligations, all at once.
NIS2 recognises this and raises supply-chain risk management to an obligation: protecting your own systems is no longer enough; you have to answer for who you connect to.
Is NIS2 in force in Spain?
At EU level, yes, since 2023. In Spain, transposition is not complete: it's advancing through Royal Decree-law 7/2025 and the Cybersecurity Coordination and Governance Act, still in parliament, while the European Commission presses over the delay.
The important nuance: the delay doesn't exempt you. The substantive obligations already set the direction, regulators and — above all — European clients apply criteria consistent with the directive without waiting for full transposition, and it's already appearing in tenders and contracts.
What's wrong with the usual way of assessing suppliers?
The questionnaire you email, the supplier fills in ticking everything green, and you file unverified. It's worthless, and NIS2 demands the opposite: verification, not just declaration.
What moves the needle is combining two things:
- The supplier's declaration: questionnaire, certification, ISO 27001 or SOC 2 if they have them.
- An external, technical view: what's visible of that supplier from outside — certificate status, exposed systems, weak configurations, leaked credentials. The picture an attacker would see.
That second part is what almost nobody does, because it needs real technical scanning, not a form. And it's the difference between "I have a signed paper" and "I can prove I verified".
Keep reading
Was this article useful? Let's talk.
