GDPR, ENS, and NIS2: What These Regulations Actually Require from Your Company’s Network Infrastructure 

IT InfrastructureGDPR, ENS, and NIS2: What These Regulations Actually Require from Your Company's...
Share & summarize with IA

Complying with cybersecurity regulations is not a matter of signing documents or passing internal audits. Behind every regulation lie technical requirements that fall directly on network infrastructure: how traffic flows, who can access what, how environments are segmented, and what capacity the organization has to detect and respond to incidents. In Spain, three regulatory frameworks concentrate most of these obligations for mid-sized companies in regulated sectors: the GDPR, the National Security Framework, and the NIS2 Directive. Understanding what each one demands at a technical level is the first step toward knowing whether the corporate network is genuinely up to the task. 

Is your network ready to support the growth of IoT devices across your organization? Complete the IoT audit checklist and discover whether there are security, visibility, or performance risks that could impact your operations. 

GDPR, ENS, and NIS2 What These Regulations Actually Require from Your Company's Network Infrastructure
GDPR, ENS, and NIS2 What These Regulations Actually Require from Your Company’s Network Infrastructure

What the GDPR Requires in Terms of Encryption, Segmentation, and Access Control in Corporate Networks 

The General Data Protection Regulation does not describe network configurations, but its Articles 5 and 32 are unambiguous: personal data must be processed in a way that guarantees its confidentiality and integrity, and appropriate technical measures must be applied to protect it against unauthorized access, loss, or destruction. Translated to the infrastructure level, this has three direct implications. 

The first is encryption. Personal data in transit — whether between devices, between offices, or between the corporate network and cloud services — must travel encrypted. Protocols such as TLS 1.2 or higher are not optional in environments that process client, employee, or patient data; they are the technical expression of the confidentiality principle. The same applies to data at rest when stored on servers or network devices accessible from the infrastructure. 

The second is segmentation. The GDPR does not allow personal data to be reachable from any point on the network. A hospital environment, for example, cannot have its electronic health record system on the same network segment as reception terminals or medical IoT devices. Microsegmentation is not just a best practice; it is the technical means of satisfying the access minimization principle. A flat network is, from a regulatory standpoint, a non-compliant network. 

The third is access control. The regulation requires that only authorized individuals can access data, which in network terms translates into role-based access policies, robust authentication, and audit logs recording who accesses what and from where. Networks that do not enforce access control at the switch or wireless access point level leave a technical gap that an inspector from the Spanish Data Protection Agency can identify with relative ease. 

NIS2 for Mid-Sized Companies in Europe: New Obligations Around Resilience and Incident Reporting 

The NIS2 Directive — whose transposition into Spanish law was due to be completed in October 2024 and remains behind schedule — significantly expands the range of entities subject to its requirements compared to its predecessor. Mid-sized companies in sectors such as energy, transport, healthcare, digital infrastructure, public administration, critical manufacturing, and financial services fall within its scope, and with that comes a set of technical obligations that directly affect the network. 

The first area concerns risk management. NIS2 requires organizations to apply technical and organizational measures proportionate to the risk, explicitly listing among them security in the acquisition, development, and maintenance of network systems, vulnerability management, access control, and encryption. This is not a suggested checklist; it is a minimum catalogue. Organizations unable to demonstrate that these measures are in place face penalties that, for essential entities, can reach ten million euros or two percent of global annual turnover. 

The second area is operational resilience. The directive requires organizations to maintain service continuity in the face of incidents, which means tested response plans, network-segregated backups, and the ability to isolate compromised segments without halting the entire operation. Network architecture here is not a technical detail; it is a compliance requirement. 

The third area is incident notification. NIS2 establishes a reporting chain with strict deadlines: an early warning within the first 24 hours, a full notification within 72 hours, and a final report within one month. Meeting those timelines requires active detection capabilities. A network with no visibility into its own traffic, no anomaly detection systems, and no structured logs is a network that cannot comply with NIS2’s reporting obligations, regardless of how everything else is configured. 

ENS Compliance in Corporate Networks: Categorization, Technical Controls, and Public Sector Contracting 

The National Security Framework, governed by Royal Decree 311/2022, is mandatory for Spanish public sector entities and for any private company that provides services or develops information systems for public administration. In 2026, as public digital transformation contracts multiply, its scope now reaches a growing number of mid-sized companies managing data or services on behalf of public bodies. 

The ENS organizes its requirements around a prior and unavoidable process: system categorization. Based on the potential impact of a security incident on the services provided, the system is classified as basic, medium, or high, and that category determines which technical measures are mandatory. Not every organization needs to implement the same set of controls, but all must be able to demonstrate that the analysis has been carried out and that the measures applied are consistent with the assigned level. 

At the network infrastructure level, the ENS is particularly demanding across the dimensions of availability, integrity, and confidentiality. For medium and high categories, it requires concrete measures including logical or physical network separation, traffic filtering at defined perimeters, security event logging with correlation capability, two-factor authentication for access to critical systems, and continuous network monitoring. Annex II of the Royal Decree lists more than seventy technical and organizational controls, several of which apply directly to the network layer. 

One of the most overlooked requirements in practice is connected device management. In mixed environments where managed equipment, external user devices, and operational IoT elements coexist, the ENS requires that each device be identified and that its network access be controlled according to its risk profile. A corporate network without an up-to-date inventory, without identification of unmanaged devices, and without access policies differentiated by endpoint type will not pass a medium- or high-level ENS audit. 

Regulatory Convergence as a Driver of Technical Decision-Making 

All three regulatory frameworks share a common logic: they protect different assets through different legal mechanisms, but they converge on the same technical requirements for the network. Encryption, segmentation, access control, traffic visibility, anomaly detection, and response capability are requirements that appear — with varying levels of specificity — across all three regulatory texts. 

This has one important practical consequence for IT managers and operations directors at mid-sized companies: there is no need to build three separate compliance projects. A network infrastructure designed with security-by-default principles — one that incorporates full visibility over connected devices, enforces identity- and context-based access policies, and provides incident detection and response capabilities — simultaneously satisfies the technical requirements of the GDPR, the ENS, and NIS2. 

The question every organization should ask itself is not whether it complies with each regulation individually, but whether its network has the technical capacity to sustain that compliance continuously. Regulatory compliance is not a state to be reached; it is a condition to be maintained, and the network infrastructure is the foundation on which it rests. 

If your organization operates in a regulated sector and you are unsure whether your network meets the technical requirements of GDPR, ENS, or NIS2, the time to find out is before an audit takes place. Beyond Technology specialists can analyze your current infrastructure and identify the compliance gaps that pose the greatest risk to your company. Contact us, and we will put you in touch with a specialist. 

Follow us at Linkedin!

Related

Best Practices for Designing an Enterprise Network with HPE Aruba 

Enterprise networks have evolved far beyond simply connecting devices....

Success Stories: Companies That Have Transformed Their Networks with Mist AI 

Enterprise network management is undergoing a major transformation driven...

How to Implement Juniper SD-WAN in Your Business Without Disrupting Operations 

Digital transformation has significantly increased the demands placed on...