For years, “mandatory” cybersecurity was something for banks, hospitals and large operators. NIS2 has broken that mould. The new European directive extends security obligations to many more sectors and to mid-sized companies that until now lived on the sidelines, and —this is what almost nobody sees coming— it stretches the requirement to their entire supply chain. Translation: even if your company doesn’t appear on the list of affected sectors, you may end up having to comply because you sell to someone who does.
We’re not going to bore you here with article numbers or quote exact penalties —for the legal detail, that’s what your lawyer is for. Let’s get to what really matters to you: if NIS2 affects you, what it obliges you to do in practice and how to comply with NIS2 in your company without setting up an entire security department or losing your mind along the way.
What NIS2 is and who it really applies to
NIS2 is the evolution of the first European directive on the security of networks and systems. Its goal is to raise the level of cybersecurity across the Union, and to achieve it, it does two important things: it widens the number of sectors considered essential or important —energy, transport, health, water, banking, digital infrastructure, public administration, but also manufacturing, food, waste management, postal services, chemicals and more— and it lowers the size threshold, pulling in many mid-sized companies that used to fall outside its scope.
But the point most people overlook is the supply chain. NIS2 obliges affected entities to manage the risk that reaches them through their suppliers. What does that mean for you? That if you’re the one providing the IT support, the software, the hosting, the logistics or any critical service to a company that is subject to NIS2, that company is going to start demanding security guarantees from you by contract. The “I’m not on the list” trap is exactly that: you don’t need to be on the list for the rule to reach you.
NIS2 doesn’t just ask whether your company is critical. It asks who you depend on and who depends on you. That’s where most companies come in.
That’s why the first step isn’t to assume it doesn’t concern you, but to check it properly: look at your sector, your size and —above all— who you sell to. Many SMEs discover they’re indirectly subject to it the day a large client sends them a security questionnaire they don’t know how to answer.
What it obliges you to do in practice
NIS2 doesn’t hand you a checklist of products to buy. It requires a risk management approach: identify what can go wrong, assess its impact and put proportionate measures in place. Within that framework, there are recurring obligations that are worth being clear about right now.
- Risk analysis and management. Knowing what assets you have, what threats affect them and what you’d do about each one. It’s the foundation everything else rests on.
- Minimum technical measures. Access control, strong authentication (ideally multi-factor), encryption, up-to-date patching, tested backups, network segmentation and email security. The essentials, but done for real.
- Incident notification. In the event of a significant incident, you must notify the competent authority within tight deadlines. Improvising on the day is not an option: you need to know who you call, what you report and who does it.
- Supply chain security. Assessing and demanding guarantees from your suppliers, and being in a position to give them to your clients.
- Continuity and recovery. Plans to keep operating and get back to normal after an incident, including crisis management.
- Training and awareness. Your team is the front line. The rule expects people to be trained, starting with management.
And there’s an underlying shift that runs through everything: responsibility falls on management. NIS2 stops treating cybersecurity as a matter for “the IT guy” and places it on the directors’ table, where they must approve the measures, oversee compliance and get trained themselves. Delegating and looking the other way no longer works: if something fails, the responsibility has a name and surname at the top.
Where to start if you’re beginning from scratch
If you read all of the above and feel the pressure, breathe. You don’t have to do it all at once or buy ten expensive tools. You have to do it in order. And the order matters more than the rush.
1. An honest risk assessment
Before protecting anything, you have to know what you’re protecting. Inventory your systems, your data and your dependencies, and assess where your biggest holes are. This diagnosis is what turns a generic list of obligations into a concrete plan for your company. Without it, any investment in security is a shot in the dark.
2. The basic measures first
Most serious incidents come in through the same old door: a weak password, an unpatched machine, a phishing email, a backup that was never tested. Closing those doors is more cost-effective than any sophisticated technology. Multi-factor, automated updates, backups that actually restore and control over who accesses what: that takes a huge chunk of the risk off your plate with a reasonable effort.
3. A realistic, phased plan
The rest —incident notification, continuity, training, supplier requirements— rolls out in stages, with clear owners and dates. A well-built compliance roadmap tells you what you do this quarter and what you do next, so that compliance is a sustainable journey and not an impossible sprint you abandon halfway. This is where having someone who has done it before makes the difference between moving forward and going in circles.
The mistake of treating it as paperwork
There’s a temptation to experience NIS2 as a formality: gather four documents, put a policy in a drawer and carry on as usual. It’s the worst possible mistake, and for two reasons. The first is practical: a box-ticking approach to compliance won’t survive a real incident. The day ransomware gets in, paper doesn’t restore your servers or stop your operations from grinding to a halt. The second is deeper: complying properly with NIS2 literally means being more secure. The obligations aren’t the legislator’s whims; they’re the measures that have been preventing disasters for years in the companies that apply them.
Look at it the other way round: the directive is giving you the perfect excuse —and management’s backing— to finally do what your cybersecurity should have had all along. A company that truly complies with NIS2 doesn’t just avoid legal problems: it suffers fewer outages, loses less data and inspires more confidence in its clients. Compliance stops being a cost and becomes a competitive advantage, especially when those clients start asking about your security before signing with you.
The MagicBoxDesk offering: NIS2 as a managed service
At MagicBoxDesk we handle the technical and organisational side of NIS2 compliance as an ongoing managed service, not as a report we hand over before disappearing. We’re the IT department your company outsources: we set up the measures, keep them monitored and are there on the day there’s an incident. And we do it with a flat monthly fee with no surprises, so that security is predictable in your budget instead of a fright every time something happens.
Here’s what hiring MagicBoxDesk’s managed cybersecurity includes to reach NIS2 compliance:
- Initial assessment. We analyse whether NIS2 affects you —directly or through your supply chain— and measure your real situation against what the rule requires.
- Phased compliance plan. A prioritised roadmap, with owners and deadlines, tailored to your size and your budget.
- Technical measures implemented. Access control, multi-factor, encryption, updates, segmentation, tested backups and monitoring of your systems.
- Incident response plan. A clear procedure for detection, containment and timely notification, so that on the day you know exactly what to do and who does it.
- Ongoing support. Regular reviews, training for your team and management, and support across Spain, remote and on-site when needed.
What you gain is easy to sum up: peace of mind, compliance and a company that’s harder to take down. You focus on your business; we make sure NIS2 is covered and that you stay secure once the rule stops making headlines. You can see all our IT services or talk it through directly with us via contact.
NIS2 won’t wait until you’re ready, and neither will your clients. Request a no-obligation quote and we’ll tell you clearly whether it affects you and what you really need to comply without losing your mind.



