Skip to content

NIS 2 IN SPAIN

Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — the national act transposing Directive (EU) 2022/2555 in Spain. Supervised by Centro Criptológico Nacional (CCN).

DRAFT PUBLISHED

Key facts

In force
Not yet in force
National law
Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad
Primary supervisor
Centro Criptológico Nacional (CCN)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Final registration mechanics depend on the law's final adoption; the draft mandates registration with the relevant CSIRT of reference based on entity type.

Scope and national nuance

Spain's transposition is delivered through the Ley de Coordinación y Gobernanza de la Ciberseguridad, which restructures the country's cybersecurity governance around three CSIRTs of national reference. The Consejo Nacional de Ciberseguridad sets cross-government policy.

Sector supervisors

SectorAuthorityAcronym
Private sector — incident responseInstituto Nacional de CiberseguridadINCIBE
Public administrationCentro Criptológico NacionalCCN-CERT
DefenceMando Conjunto del CiberespacioMCCE

What is specific to Spain

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to CCN’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →