SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
tion of network and information systems, financial loss and data compromise. A single incident – such as a cyber-attack degrading industrial control systems – may therefore trigger parallel notification duties under both regimes. Treating these as separate exercises risks delay and inconsistency; effective compliance depends on integrated internal classification protocols that assess CER and NIS2 triggers together at the point of initial assessment. Notification Architecture and Timelines CER establishes a tiered notification model that bal - ances speed with analytical depth. An early notifica - tion is required without undue delay and, in any event, within 24 hours of becoming aware of the incident. Its purpose is situational awareness rather than com - pleteness: it should provide a preliminary description of the incident, an initial impact assessment and an indication of suspected malicious intent. Authorities use this initial stage to determine whether co-ordi - nation, support or escalation mechanisms should be activated. A more detailed notification must follow within 72 hours, providing information on likely causes, affect - ed systems and services, mitigation measures taken or planned, and any potential cross border effects. A final report, due within one month, becomes the formal supervisory record, documenting the incident timeline, root cause analysis, response effectiveness and corrective measures. In supervisory practice, this final report is central to evaluating whether the entity’s resilience framework functioned as intended. Notification Channels and Parallel Regimes In Spain, notification pathways depend on the nature of the entity and the incident. Private sector critical entities notify CNPIC as the competent authority for critical infrastructure, with parallel notification to INCIBE CERT for the cybersecurity dimension. Public sector entities notify CCN CERT. Where the incident affects a regulated financial entity, DORA notification obligations apply in parallel, with significantly shorter timelines (initial notification within four hours of clas - sification as a major ICT incident). If personal data is affected, GDPR breach notification to the AEPD within 72 hours is also required.
The compliance risk is therefore not simply missing a deadline, but creating incoherent narratives across authorities. Supervisory bodies do compare notifi - cations. Entities that operate fragmented notifica - tion processes – where legal, security and regulatory teams act in isolation – are exposed to enforcement risk even when timelines are met. Operational Takeaway Effective incident response under the Spanish frame - work requires a single, integrated incident govern - ance model: one classification decision point, one internally agreed factual narrative, and co-ordinated outward reporting tailored to the requirements of each authority. Organisations that invest in this integra - tion – through predefined decision trees, rehearsed escalation processes and multidisciplinary incident exercises – are consistently better positioned both operationally and in subsequent supervisory scrutiny. 2.4 State Responsibilities and Obligations The obligations that CER and NIS2 impose on the Spanish state are an essential – though often under‑examined – component of the EU resilience framework. Private‑sector compliance is intended to function within a public architecture of risk assess - ment, co-ordination, and threat‑intelligence sharing. It is this state‑led structure that ultimately determines whether individual organisational efforts translate into systemic resilience. Under CER, Spain must conduct and regularly update national risk assessments that identify threats to the provision of essential services, using those assess - ments to designate critical entities and prioritise resilience measures. At the strategic level, this work is co-ordinated by the Departamento de Seguridad Nacional , while CNPIC maintains sector‑specific intel - ligence relevant to critical‑infrastructure designation. The quality and rigour of this assessment function directly shape the effectiveness of the overall frame - work. Threat‑intelligence sharing constitutes another core public obligation. CCN‑CERT and INCIBE‑CERT operate as the primary national channels for public‑ and private‑sector entities respectively, supported by additional sector‑specific information‑sharing mecha -
333 CHAMBERS.COM
Powered by FlippingBook