NIS2 · National implementation

NIS2 in Spain

Spain has not yet transposed NIS2. The draft — the Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — remains in the legislative process, and Spain has been referred to the CJEU.

National law
Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad
Draft cybersecurity coordination and governance act
Status
Not transposed
In force
Not in force
Authority
Centro Nacional de Ciberseguridad (proposed)

Who will supervise

The draft creates a Centro Nacional de Ciberseguridad (CNC) as coordinating authority, with roles for INCIBE (private sector and citizens) and CCN-CERT (public sector) as CSIRTs.

What applies meanwhile

Spain's existing framework continues: the Esquema Nacional de Seguridad (ENS) for the public sector and its suppliers, the RD-l 12/2018 regime (the NIS1 transposition) for operators of essential services, and sector rules. Entities covered by ENS or NIS1 should maintain those certifications — they map well onto Article 21 and will shorten the path when the new law lands.

Official sources

Primary references: the national statute book at www.boe.es and the national cybersecurity authority at www.incibe.es.

NIS2 in Spain: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states