Cybersecurity 2026

SPAIN Trends and Developments Contributed by: Rodrigo González, Vicente Moret, María Teresa Martínez and Cristina Durante, Deloitte Legal

government has accorded urgent status to the draft, but an entry into force date in 2026 remains uncertain. This situation creates a distinctive legal tension. While Spain lacks a fully transposed national NIS 2 law, the Directive itself is binding on EU member states from the date of expiry of the transposition dead - line. National courts and regulators are expected to interpret existing Spanish law in conformity with the Directive where possible. Organisations in scope can - not use Spain’s legislative delay as a shield against compliance expectations; the substantive obliga - tions of NIS 2 – risk management measures, incident reporting, supply-chain security, and management accountability – already frame the standard against which cybersecurity governance will be assessed. When finally adopted, the Spanish law will introduce several features that go beyond the Directive’s mini - mum requirements. Most notably, it establishes the Centro Nacional de Ciberseguridad (CNCS) as a new, centralised supervisory authority attached to the Pres - idency of the government, exercising co-ordination powers over sector-specific authorities and over exist - ing national bodies such as CCN-CERT (for the public sector) and INCIBE-CERT (for the private sector). This architectural choice – inspired by models like France’s ANSSI – signals an ambition for Spain to develop a genuinely integrated national cybersecurity govern - ance structure. The draft law also expands the scope of covered enti - ties relative to the Directive’s baseline. In addition to the medium and large enterprises in the 18 sectors defined by NIS 2, Spain’s draft includes universities and research centres, large municipalities, private security companies, entities with a bearing on national defence, and foreign companies with a permanent establishment in Spain meeting certain operational criteria. This expansion is significant: whereas under the original NIS Directive Spain regulated fewer than 1,000 entities, the new regime is expected to bring approximately 12,000 organisations into scope. Practical implications for organisations in Spain For organisations that are, or are likely to be, classified as essential or important entities, the legislative delay offers a limited window of opportunity – not com -

placency. The substantive compliance programme required under NIS 2 is substantial: a documented risk management framework, multi-factor authentication, encryption of data in transit and at rest, business con - tinuity planning, supply-chain security assessments, and a tested incident response capability. Manage - ment bodies – not just IT departments – are personally liable for approving and overseeing these measures under the Directive, and the Spanish draft preserves and reinforces this accountability. The sanctions regime deserves particular attention. Essential entities face fines of up to EUR10 million or 2% of global annual turnover (whichever is higher). Important entities face fines of up to EUR7 million or 1.4% of turnover. Unlike the original NIS Directive, these figures are not theoretical: the new supervisory powers include on-site inspections, audits, and the ability to impose provisional measures including the suspension of relevant certifications or authorisations. The reputational dimension – publicly available super - visory decisions – adds an additional layer of incentive to treat compliance as a strategic priority rather than a technical exercise. DORA in force: operational resilience becomes a legal standard While Spain’s NIS 2 transposition is still in progress, the Digital Operational Resilience Act became fully applicable on 17 January 2025, without any national implementation required. As an EU Regulation rather than a Directive, DORA applies directly and uniformly across all member states, removing any ambiguity about its binding force in Spain. DORA establishes a comprehensive framework for ICT risk management, incident classification and report - ing, digital operational resilience testing, and – most distinctively – the management of ICT third-party risk, including for critical ICT third-party service providers (CTPPs). The scope covers banks, investment firms, payment institutions, insurance companies, crypto- asset service providers, and a broad range of other financial entities, many of which are headquartered or have significant operations in Spain. The first year of DORA’s application has revealed sev - eral pressure points in the Spanish financial sector.

346 CHAMBERS.COM

Powered by