Cybersecurity 2026

SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal

authorities. Beyond monetary penalties, reputational consequences and potential prohibitions on market access may in practice be equally impactful. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Cybersecurity certification in Spain and the EU is best understood as a regulatory lever for market access rather than merely a voluntary assurance mechanism. Although many certification schemes are formally optional, their interaction with sector specific regu - lations and public procurement requirements means they often become mandatory in practice – particu - larly for providers operating in sensitive or regulated sectors. Product, Service and Entity Certification: Different Tools for Different Purposes A key distinction in the EU framework is between product certification, service certification, and entity- level certification. • Product certification assesses whether a specific hardware or software artefact meets defined secu - rity requirements at a specific point in time. • Service certification evaluates the security gov - ernance and operational controls of an ongoing service, such as cloud computing. • Entity-level certification examines an organisation’s overall cybersecurity posture, including govern - ance, technical controls, incident response capa - bilities, and supply chain management. These instruments are not interchangeable; each addresses different regulatory risks and assurance needs. The EU Cybersecurity Act and EU Level Schemes The EU Cybersecurity Act establishes the EU wide cer - tification framework and defines ENISA’s role. Under the CSA, certification is generally voluntary unless required by EU or national law. In practice, however, certification is frequently embedded into regulatory

expectations or procurement criteria, especially for critical or high assurance environments. The EUCC scheme provides structured, Common Cri - teria-based evaluation for products and is increasingly relevant for use in high assurance contexts. Mean - while, the upcoming EUCS scheme focuses on cloud services and assesses governance, infrastructure, processes, personnel, and subcontractor manage - ment. At higher assurance levels, EUCS introduces requirements related to third country access risks, making it particularly significant for regulated out - sourcing and financial sector resilience assessments. Interaction With Sectoral Regulation Certification directly supports compliance with a range of cybersecurity obligations. Under NIS2, member states may require essential entities to use certified products or services. In the financial sector, DORA drives institutions to treat certification as a practical signal of ICT outsourcing risk management. The Cyber Resilience Act further reinforces this dynamic by link - ing CE marking and conformity assessment for prod - ucts with digital elements to security requirements – creating renewed demand for credible evaluation mechanisms that certification schemes can fulfil. The Spanish Dimension: ENS as a Market Gatekeeper Spain applies an additional national layer through the Esquema Nacional de Seguridad . ENS is a binding cybersecurity standard for public sector information systems and, by contractual extension, for private sector suppliers providing ICT services to the pub - lic administration. ENS certification at the applicable level is therefore a de facto requirement for market access for many technology providers. Unlike product focused schemes, ENS assesses gov - ernance, technical measures, incident response, and supply chain security in an integrated manner. ENS now serves as a practical benchmark for cybersecu - rity maturity in Spain, especially in public sector and regulated environments. Although alignment with EU schemes (EUCC for products and EUCS for cloud services) is progressing, providers must still navigate parallel assurance expectations in the short term.

340 CHAMBERS.COM

Powered by