Cybersecurity 2026

SPAIN Trends and Developments Contributed by: Rodrigo González, Vicente Moret, María Teresa Martínez and Cristina Durante, Deloitte Legal

on digital security matters (adaptation of companies to the new European and national regulatory framework – DORA Regulation, NIS 2 Directive, DREC, ENS, etc), preparation of legal risk maps, development of ICT policies and procedures, development of governance strategies, adaptation and advisory services for national and international companies regarding personal data protection, and other issues.

Deloitte Legal (Deloitte Abogados y Asesores Tributarios, S.L.U.) Plaza Pablo Ruiz Picasso 1 28020 Madrid Spain Tel: +34 915 145 000 Email: rgonzalezruiz@deloitte.es Web: www2.deloitte.com/es

Spain in the Eye of the Regulatory Storm: Navigating the EU Cybersecurity Framework in 2026 Introduction: a defining moment for cybersecurity law Spain enters 2026 at a critical inflection point in its cybersecurity regulatory journey. After years of build - ing digital infrastructure and enacting sector-specific rules, the country now faces the full force of a sweep - ing European regulatory framework – simultaneously and, in several respects, before its own national imple - mentation is complete. The NIS 2 Directive, the Digital Operational Resilience Act (DORA), the Cyber Resil - ience Act (CRA), and the Critical Entities Resilience (CER) Directive are reshaping the legal obligations of thousands of organisations across virtually every sec - tor of the Spanish economy. This article analyses the principal trends and develop - ments defining cybersecurity law in Spain as of early 2026. It examines the state of Spain’s transposition of NIS 2 and the political and institutional dynamics involved; the live application of DORA to the finan - cial sector and its practical consequences; the com -

ing obligations under the CRA as its first deadlines approach; the interaction between the new EU cyber - security framework and the National Security Frame - work ( Esquema Nacional de Seguridad , or ENS); the emerging liability of corporate boards for cyberse - curity governance; and the potential impact of the European Commission’s Digital Omnibus package. Together, these developments constitute a structural shift that goes well beyond compliance – they repre - sent a new legal and strategic paradigm for digital risk management in Spain. Spain and NIS 2: still transposing, already binding The NIS 2 Directive required EU member states to transpose its provisions into national law by 17 Octo - ber 2024. Spain did not meet that deadline. As of the time of writing, the Draft Law on Cybersecurity Coordination and Governance (Preliminary Draft Bill on the Coordination and Governance of Cybersecu - rity), approved by the Council of Ministers in January 2025, has completed its public consultation phase but remains pending formal parliamentary adoption. Fol - lowing infringement proceedings initiated by the Euro - pean Commission in November 2024, the Spanish

345 CHAMBERS.COM

Powered by