NIS 2 — Spain
NIS 2 IN SPAIN
Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — the national act transposing Directive (EU) 2022/2555 in Spain. Supervised by Centro Criptológico Nacional (CCN).
DRAFT PUBLISHED
Key facts
In force
Not yet in force
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Final registration mechanics depend on the law's final adoption; the draft mandates registration with the relevant CSIRT of reference based on entity type.
Scope and national nuance
Spain's transposition is delivered through the Ley de Coordinación y Gobernanza de la Ciberseguridad, which restructures the country's cybersecurity governance around three CSIRTs of national reference. The Consejo Nacional de Ciberseguridad sets cross-government policy.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Private sector — incident response | Instituto Nacional de Ciberseguridad | INCIBE |
| Public administration | Centro Criptológico Nacional | CCN-CERT |
| Defence | Mando Conjunto del Ciberespacio | MCCE |
What is specific to Spain
- Spain operates a three-CSIRT model: CCN-CERT for public administration, INCIBE-CERT for private sector and citizens, and ESPDEF-CERT for defence — covered entities report to the CSIRT matching their sector.
- The Esquema Nacional de Seguridad (ENS) is being aligned to the NIS 2 security-measure baseline, so public-sector entities can use ENS certification as evidence of NIS 2 compliance.
- The Consejo Nacional de Ciberseguridad and the Comisión Permanente de Ciberseguridad coordinate enforcement across the three CSIRTs.
- As of mid-2026 the final law is still under parliamentary consideration; entities should monitor the BOE for the final text and any transitional provisions.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to CCN’s supervisory expectations.