Today we want to tell you something important: we have successfully passed the AENOR NIS2 compliance audit, making MailComms Group the first company in Spain to obtain this certificate, which is issued by AENOR under very demanding requirements. This achievement not only reflects our commitment to cybersecurity and privacy, but also offers a number of significant guarantees for our customers.
What is NIS2?
NIS2 (Revised Network and Information Systems Security Directive) is the EU Directive on the security of network and information systems that establishes a robust and consistent framework for improving cybersecurity across the European Union. This standard, which is an evolution of its predecessor NIS, imposes a set of technical and organizational requirements that entities must meet to ensure the security and resilience of their information systems. Among the highlights of NIS2 are:
-
- Governance and risk management: entities must have adequate and proportionate risk management measures in place to prevent and mitigate cybersecurity incidents.
- Incident detection and response: requires the implementation of incident monitoring, detection and response capabilities to minimize the impact of attacks.
- Technical requirements: includes, in detail, the technical standards that systems must meet to reduce risks. These standards are developed by the European Telecommunications Standards Institute (ETSI), an independent organization that produces globally applicable standards for information and communication technologies, including those related to cybersecurity. ETSI 319/401 (ETSI EN 319 401 v3.1.1 General Policy Requirements for Trust Service Providers) is mandatory for all qualified trust service providers (TSPs). This ETSI establishes general requirements to ensure that high levels of security and reliability are maintained in the services provided to users or customers.
- Incident reporting: entities have to report relevant incidents to the competent authorities within a deadline specified in the text itself.
- Technical and organizational measures: incorporation of appropriate technical and organizational measures to ensure the security of networks and information systems.
| Metrics / Scope | Operational Details and Capacity |
|---|---|
| Physical Delivery Timeframe (Burofax) | Same-day delivery (in major cities) or next business day (nationwide). |
| Mail Delivery Attempts | 2 delivery attempts included in the standard mail service, with a notice of arrival left in your mailbox if you are not home. |
| Holding Period at the Post Office | The shipment remains available for pickup at the corresponding post office for 15 or 30 days (depending on settings). |
| Safekeeping of Legal Evidence | Guaranteed safekeeping of the acknowledgment of receipt, the certification of contents, and the original document for a minimum of 5 years. |
| Geographic Coverage | Nationwide coverage (Spain, islands, and territories under Spanish sovereignty) and international connections for cross-border shipments. |
| Massive Processing Capacity | An automated platform designed to generate, envelope (in physical format), and send thousands of notifications daily in parallel. |
What guarantees does NIS2 certification offer our customers?
MailComms Group is the first qualified trust service provider in Spain to pass the strict audit carried out by AENOR to issue its NIS2 certificate.
This accreditation ensures that our core services are fully aligned with the most rigorous European standards and that our information security and privacy management systems (ISPS) meet our customers’ stringent requirements in terms of cybersecurity, within our supply chain work.
In addition, it is particularly interesting for our clients because it guarantees that their data and communications are protected with the most advanced and up-to-date security measures. Confidence in our services is reinforced by our ability to identify, prevent and respond effectively to any cyber threat, ensuring the continuity and privacy of your operations.
Furthermore, this accreditation, combined with the other certifications we hold at MailComms Group, places us at a higher level in terms of security, privacy, business continuity, and regulatory compliance. In other words, it ensures that companies that integrate us into their supply chain exercise due diligence in selecting suppliers.
Sonia Las Heras, CISO of MailComms Group, explains: “The audit process to obtain this certificate was extremely rigorous, but we are proud to offer such a significant guarantee of security and privacy through our commitment to the ‘security and compliance by design’ philosophy. This approach is always present in the DNA of our platforms and in the business processes we develop together with our external technology partners “.
Due diligence in supplier selection
Due diligence in supplier selection is the process by which a company verifies that a third party in its supply chain complies with the security, privacy, and continuity standards required by applicable regulations before integrating that party as a critical supplier.
In today’s business environment, cybersecurity has become a top priority. Choosing trusted “cybersecure” service providers not only ensures data protection and business continuity, but also complies with the due diligence required in the selection of suppliers. Companies need to ensure that their suppliers comply with the highest security and privacy standards, as established by the NIS2 regulation, to mitigate risks, protect the integrity of their information systems and offer secure services to their users and customers.
Find out everything you need to know about the SAC Act.
Linkage between DORA and NIS2
Although DORA and NIS2 focus on different sectors, both regulations share a common link: improving cybersecurity and operational resilience in the European Union.
DORA (Digital Operational Resilience Act) focuses on ensuring the operational resilience of the financial sector. Among other things, it calls for comprehensive ICT risk management, incident management, resilience testing, third-party risk management and information sharing within the financial sector.
For its part, NIS2 aims to optimize the overall cybersecurity posture across the EU. This directive focuses on governance and incident detection and response and secures and tests perimeters and assets in several critical sectors, covering a wider range of essential and important sectors.
| Dimension | DORA | NIS2 |
|---|---|---|
| Sector | Financial sector (banks, insurance companies, asset management firms) | Essential and important sectors throughout the EU |
| Main Objective | Digital Operational Resilience | Cybersecurity and Network and System Resilience |
| ICT Risk Management | Comprehensive ICT Risk Management | Impact-Based Risk Management |
| Third Parties / Supply Chain | ICT Supplier Risk Management | Supply Chain Due Diligence |
| Incident Reporting | Mandatory reporting to financial authorities | Mandatory to competent authorities (NIS2) |
| Resilience Tests | Required operational resilience tests | No equivalent formalized tests are required |
Both regulations share fundamental principles such as ICT risk management, incident detection and response, and the importance of cooperation and information sharing to address growing cyber threats.
At MailComms we pride ourselves on being at the forefront of cybersecurity compliance to provide maximum protection and confidence for our customers.
Related content:
> Legal Validity of Email in Commercial Transactions and Online Contracts
Frequently Asked Questions
What is NIS2 certification, and what does it guarantee?
NIS2 certification, issued by AENOR, attests that an organization complies with the technical and organizational requirements of EU Directive 2022/2555 on cybersecurity: risk governance, incident detection and response, and technical measures aligned with the ETSI EN 319 401 standard. For a customer, choosing an NIS2-certified provider means that their communications and data are protected under the most stringent European standards.
Why is it important for a trusted service provider to be NIS2-certified?
Because the ETSI EN 319 401 standard is mandatory for Qualified Trust Service Providers (QTSPs), and NIS2 requires companies to exercise due diligence regarding their supply chain. Hiring a certified provider makes it easier to meet that obligation without having to individually audit their cybersecurity level.
What is the difference between DORA and NIS2?
DORA focuses on the digital operational resilience of the financial sector (banks, insurance companies, asset management firms), while NIS2 has a broader scope and applies to critical and important sectors throughout the European Union. Both share principles regarding ICT risk management, incident reporting, and third-party oversight, but DORA is sector-specific and NIS2 is cross-sectoral.
What does the ETSI EN 319 401 standard require of a supplier?
ETSI EN 319 401 establishes the general policy requirements that trust service providers must meet to ensure high and consistent levels of security and reliability for their customers. It is the reference technical standard under which trust service providers must operate within the framework of NIS2 and eIDAS.
How does a provider’s NIS2 certification affect my company’s due diligence?
If your company is subject to NIS2, DORA, or other regulations to perform due diligence on your supply chain, contracting with suppliers who are already certified (NIS2, ISO 27001, ISO 27701) shifts part of that responsibility to the supplier and reduces the risk of indirect noncompliance by third parties.
