On 8 July the European Commission decided to refer Spain to the Court of Justice of the European Union. The reason is the failure to notify the transposition of the NIS2 Directive, the rules that set a common level of cybersecurity across eighteen critical sectors, among them health, energy, transport and the public sector. Spain is not alone. Ireland, France and the Netherlands go with it. The Commission is asking the Court to impose financial sanctions, a lump sum and daily penalties until transposition is complete.
The timeline leaves little room for interpretation. The deadline expired on 17 October 2024. The Commission sent letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025. In Spain, the draft Law on Coordination and Governance of Cybersecurity was approved by the Council of Ministers on 14 January 2025 and there it remains, never reaching the official gazette. Almost two years past the deadline, the Spanish rule does not exist.
From this comes a comfortable and mistaken conclusion. If the law is not there, there is nothing to do. The error is confusing who the rule binds with how far it reaches.
NIS2 does not apply to every company. It follows a size rule and covers medium and large entities in those eighteen sectors, with room for each state to include smaller ones with a critical profile. A thirty-person SMB is not usually a covered entity. But the directive requires those who are to manage the risk in their supply chain and in their supplier relationships. That is where the SMB appears, not as the addressee of the rule, but as the supplier of whoever has to comply with it.
NIS2 will not reach your company through the official gazette. It will reach you in your best client's contract.
This is already happening, and it is not waiting for the Spanish legislator. The hospital, the utility, the logistics operator or the public body that buys from you has to show it keeps its suppliers under control. That obligation always takes the same shape, a security questionnaire before signing and new clauses at renewal. Four things come up in all of them.
- Who answers. A name and a phone number to call when something happens, inside your company, not the generic number of your IT provider. It tends to be the first question on the questionnaire and half of SMBs have no answer for it.
- Reporting fast. Covered entities report their incidents within hours, not days. That clock is passed down into the contract, so if the incident starts in your systems, you have to warn your client in time for them to warn theirs.
- Measures you can show. Saying you have backups is not enough. They ask since when, how often, when the last restore was tested and who checked it. What is not recorded does not exist in a review.
- Your own chain. If part of your service rests on a third party, the question is passed to you whole. In front of the client, your supplier becomes your business.
Sanctions deserve to be put in their place. For covered entities, NIS2 sets fines of at least ten million euros or 2% of worldwide annual turnover for essential entities, and at least seven million or 1.4% for important ones. The supplier SMB is not exposed to that fine. It is exposed to something more immediate, a renewal that does not come and a contract that goes to the competitor who did know how to answer.
There is one reasonable temptation left, waiting. In January 2026 the Commission proposed amendments to NIS2 itself, to add legal clarity and make compliance easier. But what is being simplified is how you comply, not whether you have to, and your client's questionnaire does not depend on that. It depends on their next audit.
The useful question today is not when the Spanish law will arrive. It is who in your company would answer that questionnaire tomorrow, with what evidence and how fast. If no name comes to mind, that is the finding. In a transaction, the next question is what that evidence gap means for risk and execution. Prufy's sample diligence shows how we trace that path from signal to implication.