SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
NIS2: The Entity Level Baseline (and Spain’s Current Transposition Gap) NIS2 establishes the EU’s horizontal baseline for the security of network and information systems across essential and important entities. Its scope is defined through a general size threshold, with targeted inclu - sions for certain digital services regardless of size. Its significance lies less in the sector list and more in the governance model it enforces: risk-based technical and organisational measures, supply chain controls, and structured incident reporting. Spain has not yet transposed NIS2. In the meantime, the earlier NIS1-based domestic framework continues to apply, creating a structural gap between the EU’s intended perimeter and Spain’s current national obli - gations. This gap does not eliminate compliance risk. For organisations with operations in member states that have completed transposition, NIS2 aligned obli - gations already apply in those jurisdictions. The operational consequence: a “Spain only” com - pliance assessment is no longer sufficient. For many groups, the effective NIS2 compliance perimeter is determined by where they operate in the EU, not sole - ly by the status of Spain’s transposition. DORA: Sector-Specific Resilience With “Reach Through” to ICT Providers DORA is directly applicable and binding on in scope financial entities. It establishes an integrated frame - work covering ICT risk management, incident report - ing, digital operational resilience testing, and ICT third party risk management. A decisive feature of DORA is that it extends beyond regulated financial entities to reshape how the financial system governs its technology dependencies. All ICT suppliers must meet strengthened governance and contractual expectations. For providers designated as critical ICT third party providers (CTPPs), DORA goes further by imposing direct EU level oversight under a designated Lead Overseer. This creates a significant extraterritorial effect, potentially requiring non-EU ICT providers serving EU financial institutions to establish an EU subsidiary and submit to oversight.
In Spain, DORA’s implementation carries an addi - tional operational nuance: supervisory responsibility is distributed across multiple authorities ( Banco de España , CNMV, and DGSFP). Regulated entities there - fore require one internal operational resilience model capable of being demonstrated consistently to each supervisory interface. CRA: Product-Level Cyber Resilience and Market Access The Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements, covering them across their entire life cycle. The CRA shifts responsibility upstream: many cyber - security outcomes depend on product design choices (secure defaults, update mechanisms, vulnerabil - ity handling) that cannot be compensated for solely through organisational controls. Its scope is wide, covering most hardware and soft - ware with a direct or indirect connection to networks or devices. Because it applies to products placed on the EU market regardless of manufacturer location, the CRA has broad extraterritorial reach. Two scope aspects are especially relevant for Spanish businesses. • 1. Procurement and product governance become compliance critical, given the wide coverage of connected products. • 2. The SaaS boundary matters: (a) purely remote SaaS with no local installed component is outside the CRA’s direct scope; and (b) SaaS elements integrated into an in-scope product (eg, IoT backends) are covered as part of that product. CRA, Article 6 also signals intended co-ordination with NIS2 incident reporting, reflecting that many incidents arise from the interplay between product vulnerabili - ties and organisational impact. CSA, Certification, and the “Voluntary in Law, Mandatory in Practice” Dynamic The EU Cybersecurity Act (CSA) creates the EU wide certification framework for ICT products, services, and
328 CHAMBERS.COM
Powered by FlippingBook