NIS2 · National implementation
NIS2 in Spain
Spain has not yet transposed NIS2. The draft — the Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — remains in the legislative process, and Spain has been referred to the CJEU.
- National law
- Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad
- Draft cybersecurity coordination and governance act
- Status
- Not transposed
- In force
- Not in force
- Authority
- Centro Nacional de Ciberseguridad (proposed)
Who will supervise
The draft creates a Centro Nacional de Ciberseguridad (CNC) as coordinating authority, with roles for INCIBE (private sector and citizens) and CCN-CERT (public sector) as CSIRTs.
What applies meanwhile
Spain's existing framework continues: the Esquema Nacional de Seguridad (ENS) for the public sector and its suppliers, the RD-l 12/2018 regime (the NIS1 transposition) for operators of essential services, and sector rules. Entities covered by ENS or NIS1 should maintain those certifications — they map well onto Article 21 and will shorten the path when the new law lands.
Official sources
Primary references: the national statute book at www.boe.es and the national cybersecurity authority at www.incibe.es.
NIS2 in Spain: frequently asked questions
Last reviewed:
Related reading
Definitions
