SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
as critical under CER to a broader population of digi - tal operators whose network and information systems underpin economic activity. For entities designated as critical under CER, the overlap with NIS2 is substantial. In practice, most criti - cal entities will also qualify as essential entities under NIS2. The two instruments are complementary: CER establishes the duty to ensure resilience of essen - tial services, while NIS2 specifies the cybersecurity measures required to support that resilience, including ICT risk management, incident handling, backup and recovery, supply chain security and authentication. Scope Uncertainties and Practical Implications The principal uncertainty for operators in Spain arises from timing. While CER and NIS2 define the EU level scope, domestic transposition remains underway. This creates a transitional period in which entities may fall within the EU intended scope but are not yet subject to fully articulated national obligations. This uncertain - ty does not eliminate compliance risk. Groups oper - ating across borders may already be subject to NIS2 aligned requirements in other member states, and supervisory expectations increasingly reflect the EU framework rather than legacy domestic boundaries. Practical Takeaway For operators, the key is not to treat CER and NIS2 as separate scoping exercises. The effective perimeter should be mapped once, at the entity level, assess - ing whether the organisation (i) provides an essential service likely to trigger CER designation, (ii) qualifies as an essential or important entity under NIS2, or (iii) both. Designing resilience governance around the entity centric model now reduces the risk of com - pressed and disruptive implementation once domes - tic transposition is finalised. 2.2 Critical Infrastructure Cybersecurity Requirements The cybersecurity obligations applicable to critical entities in Spain cannot be understood as a checklist of technical controls extracted from individual regu - latory instruments. What the Critical Entities Resil - ience Directive introduces – and what structurally distinguishes it from earlier frameworks – is a model of resilience as an integrated governance responsi -
bility borne by the entity itself, rather than a set of safeguards applied to isolated assets. The regulatory focus has shifted: it is no longer the pipeline, power plant, or data centre that holds the obligation, but the organisation delivering the essential service, in all its operational, human, digital, and supply chain dimen - sions. Governance and accountability at entity level. Under CER, ultimate responsibility for resilience lies with the governing body of the critical entity and can - not be delegated. This represents a significant shift in the Spanish landscape, where physical security and cybersecurity have traditionally been treated as operational matters managed below board level. CER requires governing bodies not only to approve poli - cies, but to understand the organisation’s exposure, oversee the adequacy of resilience measures, and ensure resources are sufficient to maintain and test them. For listed companies, this obligation increas - ingly aligns with corporate disclosure expectations and with the recognition of operational resilience as a material governance issue. Risk assessment as the foundation of resilience. CER grounds all substantive obligations in a comprehen - sive, entity level risk assessment. Its importance lies not in methodology but in breadth: critical entities must evaluate not only cyber threats, but natural haz - ards, public health emergencies, insider risks, and hybrid threats that combine physical and digital vec - tors. This integrated approach departs from legacy models in which physical and cyber risks were exam - ined separately by distinct teams. The quality of this assessment is decisive. It is not a mere compliance exercise; it dictates how subsequent controls are cali - brated, and weaknesses at this stage will systemati - cally undermine downstream resilience measures. Asset and dependency mapping beyond ICT inven - tories. To support a meaningful risk assessment, CER requires entities to identify the full operational foot - print that underpins the provision of essential services, including physical assets, ICT systems, personnel, processes, and third party dependencies. This goes beyond traditional ICT asset inventories. Critical enti - ties must understand how non-digital assets can trig - ger digital failures and vice versa, and where interde -
331 CHAMBERS.COM
Powered by FlippingBook