NUDAYOSH

BLOG · 2026-06-25

NIS2 and the supply chain: your security is your suppliers' security

NIS2 requires managing your suppliers' cyber risk, with real verification. Status in Spain, who it applies to, and the fines.

Quick summary

  • Directive (EU) 2022/2555 (NIS2) has been in force at EU level since January 2023; the transposition deadline was 17 October 2024.
  • Spain has not completed transposition. It has been partially transposed via Royal Decree-law 7/2025, and the Cybersecurity Coordination and Governance Act is still in the legislative pipeline. The European Commission keeps an infringement procedure open.
  • It applies, in general, to entities in 18 critical sectors with 50+ employees or over €10M turnover, with exceptions for SMEs in highly critical sectors.
  • A core requirement is supply-chain risk management: you must verify suppliers, not just collect a signed declaration.
  • Fines reach €10M or 2% of global turnover, with personal liability for directors and even possible disqualification.

Why does your security depend on your suppliers?

Because your real cybersecurity level is, in practice, the weighted average of the companies you depend on. A compromised supplier can expose your data, break your service and trigger your notification obligations, all at once.

NIS2 recognises this and raises supply-chain risk management to an obligation: protecting your own systems is no longer enough; you have to answer for who you connect to.

Is NIS2 in force in Spain?

At EU level, yes, since 2023. In Spain, transposition is not complete: it's advancing through Royal Decree-law 7/2025 and the Cybersecurity Coordination and Governance Act, still in parliament, while the European Commission presses over the delay.

The important nuance: the delay doesn't exempt you. The substantive obligations already set the direction, regulators and — above all — European clients apply criteria consistent with the directive without waiting for full transposition, and it's already appearing in tenders and contracts.

What's wrong with the usual way of assessing suppliers?

The questionnaire you email, the supplier fills in ticking everything green, and you file unverified. It's worthless, and NIS2 demands the opposite: verification, not just declaration.

What moves the needle is combining two things:

  1. The supplier's declaration: questionnaire, certification, ISO 27001 or SOC 2 if they have them.
  2. An external, technical view: what's visible of that supplier from outside — certificate status, exposed systems, weak configurations, leaked credentials. The picture an attacker would see.

That second part is what almost nobody does, because it needs real technical scanning, not a form. And it's the difference between "I have a signed paper" and "I can prove I verified".

Keep reading

Was this article useful? Let's talk.

Do you know how many of your suppliers expose you today?

We make it clear: how many handle data, embed AI, or access your systems, and for how many you have an up-to-date contract and verification. GDPR, AI Act and NIS2 in a single record.

Ask us for details →

We'll reply with a first diagnosis of your supplier exposure · hola@nudayosh.com

Frequently asked questions

About NIS2 and the supply chain.

Is NIS2 already mandatory in Spain?

Directive (EU) 2022/2555 has been in force at EU level since 2023, but transposition in Spain is not complete: it's advancing via Royal Decree-law 7/2025 and the Cybersecurity Coordination and Governance Act, still in progress. The delay does not exempt companies from preparing.

Which companies does NIS2 apply to?

In general, to entities in 18 critical sectors with 50+ employees or over €10M turnover, with exceptions for SMEs in highly critical sectors such as DNS or trust services.

Does NIS2 affect me if I'm a supplier to an obligated company?

It can affect you indirectly. Obligated entities must manage their supply-chain risk and will pass security requirements to suppliers by contract, even if the suppliers aren't directly in scope.

Is a signed security questionnaire from my suppliers enough?

No. NIS2 requires verification, not just a signed declaration. A supplier self-assessment without checking does not prove due diligence.

What fines does NIS2 carry?

Up to €10M or 2% of global turnover, with personal liability for management bodies and even possible temporary disqualification of directors.