Cybersecurity 2026

SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal

Sectoral Regulators Sector specific competent authorities play a central role under both NIS2 and DORA. For financial sector DORA supervision, the competent authorities are the Banco de España (BdE), the Comisión Nacional del Mercado de Valores (CNMV), and the Dirección Gen- eral de Seguros y Fondos de Pensiones (DGSFP). The Comisión Nacional de los Mercados y la Competen- cia (CNMC) is responsible for electronic communica - tions and digital infrastructure oversight. The Agencia Española de Protección de Datos (AEPD) supervises GDPR compliance and exercises concurrent jurisdic - tion where cybersecurity incidents involve personal data breaches. DSN The Departamento de Seguridad Nacional co-ordi - nates Spain’s national cybersecurity strategy and high-level crisis management, including activation of the national cybersecurity crisis framework under the Marco Nacional de Ciberseguridad . 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The regulatory framework governing cybersecurity for critical infrastructure in Spain is undergoing a structural transition driven by EU law: a shift from an infrastructure centric model to an entity centric resil - ience model. This transition is not merely conceptual; it changes how scope is defined, how obligations are allocated, and how compliance must be organised internally by operators pending completion of domes - tic transposition. The Legacy Framework: Infrastructure-Centric Designation The framework currently in force is rooted in Act 8/2011 on Critical Infrastructure Protection and its implementing regulation. Under this model, regula - tion focuses on specific physical infrastructures – installations, systems or networks whose disruption would have serious consequences for essential social functions or public safety. Designation flows from the asset to the operator, and obligations are organised

around security planning instruments designed to pro - tect identified critical services. Historically, this model prioritised physical security and continuity of supply, with cybersecurity treated as a supporting component rather than a primary regulatory focus. The EU Driven Shift: Designation of Entities, Not Assets The Critical Entities Resilience Directive replaces this asset-based logic with an entity designation model. Under CER, the regulated subject is the legal entity that provides an essential service, and obligations are structured around the entity’s ability to prevent, with - stand, adapt to and recover from incidents – wheth - er physical, cyber or hybrid. CER requires member states to identify critical entities through national risk assessments and designate them across eleven sec - tors, including energy, transport, banking, financial market infrastructure, health, digital infrastructure and public administration. The regulatory focus therefore shifts from protecting isolated assets to ensuring con - tinuity of essential services delivered through com - plex combinations of physical infrastructure, digital systems, organisational processes and supply chain dependencies. Spain is Transposing CER Through Reform of Act 8/2011 The reform is expected to replace infrastructure des - ignation with entity designation and to modernise planning obligations accordingly. Designated criti - cal entities will need to maintain integrated resilience plans that combine physical security, cybersecurity, business continuity and crisis management within a single governance framework, under the oversight of the competent authority. NIS2 as the Cybersecurity Dimension of the Resilience Model Within this entity centric architecture, NIS2 functions not as a parallel regime but as the instrument that provides technical and organisational substance to the cybersecurity aspects of resilience. NIS2 dis - tinguishes between essential and important enti - ties across critical and important sectors, deploying a general size cap rule with targeted inclusions for certain digital service providers regardless of size. Its scope therefore extends beyond entities designated

330 CHAMBERS.COM

Powered by