SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
processes. While formally voluntary, certification often becomes effectively mandatory where embedded into procurement requirements or used as a presumption of regulatory conformity – particularly for sensitive or high trust deployments. Spain adds a distinctive national mechanism through the ENS, a binding cybersecurity standard for public sector information systems that also extends contrac - tually to private suppliers. ENS accreditation there - fore functions as a market access condition for many technology providers and is likely to remain a practical compliance reference for the public sector under NIS2 once transposition is complete. CER and the Cyber Solidarity Act: Resilience as an Interdependent System The CER Directive complements NIS2 by addressing the resilience of critical entities across sectors and promoting integrated cyber physical resilience. Spain is transposing CER through reforms to its critical infra - structure framework, with the expectation that cyber - security requirements will be embedded into existing planning tools. The Cyber Solidarity Act adds an EU level crisis response layer – comprising an EU SOC network, emergency mechanisms, and a cyber reserve. These measures focus less on day-to-day organisational controls and more on large scale incident response capacity. Practical Close: Managing the Spanish “Stack” Without Duplicating Effort 1. Map obligations by layer, not by statute. Distinguish between entity level duties (NIS2/CER), sector-specific duties (DORA), and product-level duties (CRA). This prevents parallel programmes that inadvertently solve the same problem twice. 2. Create a unified incident classification and notifica - tion matrix. Make a single, central decision framework for deter - mining whether an incident triggers NIS2, GDPR, DORA, or other obligations – and harmonise timelines and reporting channels.
3. Use procurement and supplier contracts as compli - ance tools. Leverage ENS (where relevant) and certification schemes to standardise assurance expectations, and ensure critical ICT contracts embed robust audit, noti - fication, and exit rights. 4. Demonstrate governance, not just controls. Throughout this regulatory stack, enforcement risk concentrates on whether organisations can evidence risk-based decision-making, clear accountability, and tested operational readiness – not just the existence of technical measures. 1.3 Cybersecurity Regulators Spanish National Intelligence Centre/CCN CERT The National Intelligence Centre’s cybersecurity divi - sion (CCN) is responsible for securing public sector systems, including classified environments and stra - tegic entities operating under public administration oversight. CCN CERT serves as the designated CSIRT for public administration and acts as Spain’s national CSIRT for NIS2 purposes in relation to public entities. CCN holds broad investigative powers and may con - duct technical audits, vulnerability assessments, and incident response co-ordination. INCIBE/INCIBE CERT The Instituto Nacional de Ciberseguridad operates INCIBE CERT, the CSIRT designated for private sec - tor entities and citizens. INCIBE CERT is the primary notification point for NIS2 incident reporting from pri - vate sector essential and important entities (excluding defence and public administration domains). INCIBE is also responsible for cybersecurity awareness, capacity building, and co-ordination with sector spe - cific competent authorities. CNPIC The Centro Nacional para la Protección de Infraes- tructuras Críticas acts as the competent authority under Act 8/2011 for designating critical operators and overseeing their security obligations. CNPIC col - laborates with sectoral ministries and regulatory bod - ies throughout the designation and oversight process.
329 CHAMBERS.COM
Powered by FlippingBook