SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
pendencies create single points of failure. For many Spanish operators, this mapping process reveals vul - nerabilities that have never been formally documented but are central to determining proportionate resilience investments. Supply chain security as a first order obligation. CER treats supply chain security not as a contractual due diligence task but as an integral component of the entity’s own resilience. An essential service provider whose critical supplier fails cannot deliver that service regardless of the strength of its internal controls. CER therefore obliges entities to identify critical suppliers, assess their resilience, impose minimum standards where feasible, and plan for disruption scenarios. In practice, this requires more visibility and contractu - al leverage than many operators currently possess, especially where dependencies are concentrated among a small number of global technology providers. Business continuity as an integrated cyber physical discipline. Critical entities must maintain continuity plans capable of sustaining essential services fol - lowing incidents of any type, including cyber-attacks, physical disruptions, supply chain failures, and cas - cading events. CER’s innovation lies in mandating that these plans be integrated rather than siloed. Cyber recovery, physical fallback procedures, alternative facilities, and manual operations must be designed and tested together. For Spanish operators whose IT disaster recovery and physical emergency plans are separate, CER transposition will likely require consoli - dation into a unified resilience governance framework. Personnel security and insider risk. CER explicitly rec - ognises the human factor as a systemic vulnerability. Entities must address the reliability of personnel with access to sensitive functions, systems, or facilities. In Spain, implementation must be carefully balanced against labour law and data protection requirements. The regulation does not mandate specific screening techniques; instead, it requires that insider risk be assessed and managed as part of the broader resil - ience framework. The role of NIS2 within the CER architecture. For most designated critical entities, CER and NIS2 apply con - currently. Their relationship is complementary, not
parallel. CER establishes the obligation to ensure the resilience of essential services; NIS2 provides the cybersecurity content of that obligation, specifying measures related to ICT risk management, incident handling, backup and recovery, supply chain secu - rity, and authentication. Treating NIS2 as a standalone compliance programme running alongside CER risks duplication and misalignment. A more effective approach is to design the CER resilience framework first and then populate its cybersecurity components with NIS2 requirements. 2.3 Incident Response and Notification Obligations Incident notification in the Spanish critical infrastruc - ture context cannot be treated as a purely administra - tive exercise governed by checklists and deadlines. Under the combined CER and NIS2 framework, noti - fication operates as a governance act: a formal repre - sentation by the entity to public authorities regarding the nature, impact and management of a disruption affecting an essential service. The quality of that noti - fication – its timeliness, internal consistency and ana - lytical credibility – serves as evidence of the maturity of the entity’s resilience framework and is assessed Under the CER framework, notification is required for incidents that have a significant disruptive effect on the provision of essential services. Significance is assessed holistically, taking into account the num - ber of users affected, duration, geographic scope, interdependencies with other essential services, and the economic or social impact of the disruption. This is intentionally not a rigid numerical threshold. The regulatory logic recognises that the same technical incident may be trivial in one context and critical in another. In practice, this means entities must translate high-level significance criteria into operational classifi - cation rules that can be applied rapidly and defensibly during live incidents – when information is incomplete and incentives to under classify are highest. by competent authorities accordingly. Triggering Thresholds: Significance as a Contextual Assessment For entities that are both critical under CER and essen - tial under NIS2, classification is inherently dual. NIS2 applies its own significance criteria focused on disrup -
332 CHAMBERS.COM
Powered by FlippingBook