The fastest way to prove your security to clients and auditors, while complying with NIS2, ENS and ISO 27001

Your company probably already has security in place. You have a firewall, backups, multi-factor authentication, perhaps an external SOC. And yet, when a large client sends a supplier qualification questionnaire, or an auditor asks for evidence, or the board asks "are we covered for NIS2?", the answer takes weeks and arrives incomplete. The problem is no longer having controls — it's being able to prove them.
Under this pressure, the instinctive reaction is usually to jump straight to a solution: launch an ISO 27001 certification, buy tools, or wait for the Spanish law transposing NIS2 to be published. All three options fail for the same reason: decisions are made without knowing where the organisation actually stands.
In this article we explain why the fastest way to prove your security doesn't start with implementing anything, but with a diagnostic that unifies NIS2, ENS and ISO 27001 into a single compliance and priority map.
The usual reflex: implement before you measure
When the pressure arrives — in the form of contractual clauses, security questionnaires or questions from the board — most midmarket organisations respond with one of these three reactions:
- Rushing into certification. An ISO 27001 or ENS compliance project is launched without knowing how much of the path has already been covered. The result: long, oversized projects and duplicated controls across frameworks.
- Buying technology. Money is spent on security tools without a prior gap analysis. The visible gaps get covered, but auditors don't ask for tools. They ask for evidence, governance and documented processes.
- Waiting for the law. Everything is postponed until the Spanish transposition of NIS2 is published in the Official State Gazette (BOE). But building a serious security programme takes months. Anyone who waits for publication to get started will arrive late.
All three fail in the same way: they make decisions based on a picture no one has actually taken. No management team approves an industrial or financial investment without data — cybersecurity and regulatory compliance should be no different. First the diagnostic. Then the investment.
The requirements are already here, even if the Spanish law isn't
The regulatory context of 2026 makes the wait-and-see strategy untenable. The NIS2 Directive has been in force in the EU since 2023, and its core obligations (risk management, management accountability, incident reporting and supply chain security, among others) stem from the directive itself, not from its transposition. Spain missed the October 2024 deadline, has transposed it only partially (Royal Decree-Law 7/2025), and the Cybersecurity Coordination and Governance Law is still going through parliament. It's worth noting that Brussels continues to demand that it be transposed "as a matter of urgency". When it arrives, there will be no grace period.
In the meantime, the requirements are flowing through another channel: the supply chain. Large clients are already including NIS2-aligned security clauses in their contracts, and supplier qualification processes demand concrete evidence, not statements of intent. In addition, the Spanish draft bill provides for personal sanctions against executives — and even their temporary disqualification — in the event of non-compliance.
What does a real compliance diagnostic mean? Three frameworks, one single map
A rigorous compliance diagnostic is not about running through a generic checklist. It means assessing the organisation against the three frameworks that today determine whether it can prove its security in Spain (NIS2, ENS and ISO 27001), and doing so in a unified way, because they share a substantial portion of their controls:
- NIS2 (EU Directive 2022/2555). Applicability (is your company in scope, directly or as a supplier to an obligated entity?), governance and management accountability, the risk management measures of Article 21, and the ability to report incidents within the required deadlines (24 h / 72 h / 1 month).
- ENS (Spain's National Security Framework). Determining the system's category (basic, medium or high) and the status of organisational, operational and protection measures. It is the gateway to working with the Spanish public sector and a solid baseline recognised by the regulatory ecosystem itself.
- ISO/IEC 27001. The maturity of the ISMS, the status of Annex A controls, risk management, and the real distance to an auditable certification, if that is the path the company decides to take.
Assessing each framework separately is the most expensive mistake: it produces three projects, three consultants and duplicated controls. NIS2, ENS and ISO 27001 overlap in risk management, access control, business continuity, incident management and supplier security. A well-executed diagnostic maps the three frameworks against each other. Every control implemented pays off on all three fronts, and every gap is identified only once.
Just as important is what the diagnostic rules out. Knowing that a framework doesn't apply to you, or that your ENS category is lower than you feared, prevents unnecessary investments. The goal is not to comply with everything, but to know — with data — what each framework actually requires of your organisation.
From diagnostic to action: a report built for decisions, not just for audits
The deliverable of a useful diagnostic is not a 200-page descriptive document that nobody will read. It's an executive report designed so that management can make investment decisions based on data:
- Executive risk traffic-light view: the company's situation at a glance, in the language of the board.
- Detailed gap analysis per framework: what NIS2, ENS and ISO 27001 require, what is covered and what is missing, with cross-mapping across the three.
- NIS2 applicability and ENS category: your real regulatory exposure, in black and white.
- Prioritised action plan: quick wins that close gaps in weeks versus structural investments that require budget and a timeline.
- A recommended path forward: certify, adapt, or consolidate first — justified with data, not intuition.
The distinction between quick wins and structural investments is what changes the conversation with management. A significant part of the gap can usually be closed by configuring the environment you already have — especially in organisations running Microsoft 365, where identity, information protection and event logging capabilities are often licensed but underused. Another part requires real investment. Separating the two turns the security budget into a reasoned decision instead of a gamble.
And there is an immediate side benefit: with the report in hand, answering the next client questionnaire or preparing for the next audit stops being a fire drill. The evidence is organised, the acknowledged gaps have a plan and a date — and that conveys far more confidence to an auditor than apparent compliance with no traceability.
A proven method, not an experiment
At Itequia we have turned this approach into a fixed-scope service: the NIS2, ENS and ISO 27001 Diagnostic in 10 days. An initial, clearly bounded engagement (scoping, analysis and presentation of results) that ends with the executive report and the prioritised action plan presented to management. We help you decide, with data, what to do and in what order.
Three reasons why this diagnostic works:
- We know how to map frameworks, not treat them separately. NIS2, ENS and ISO 27001 share controls; we unify them into a single plan and avoid duplication.
- Hands-on experience in regulated environments. Security projects and preparation for frameworks such as ENS and ISO 27001 with organisations that are demanding in technology, security and compliance.
- Microsoft specialists. As a Microsoft partner since 2010, we review how much of the gap can be closed with a better configuration of your existing Microsoft 365 environment before recommending new investments.
Start with a diagnostic. Decide with data. In 10 days you will have a clear view of your NIS2/ENS/ISO 27001 exposure and a prioritised action plan. Want to know what the diagnostic would reveal in your organisation? Book a meeting with us.