Cybersecurity 2026

SPAIN Trends and Developments Contributed by: Rodrigo González, Vicente Moret, María Teresa Martínez and Cristina Durante, Deloitte Legal

The Register of Information – a detailed inventory of all ICT third-party contractual arrangements – proved particularly demanding, with many entities struggling to gather complete and accurate data from across complex corporate groups and supply chains. The April 2025 deadline for submission of the initial regis - ter to competent authorities – the Banco de España , the Comisión Nacional del Mercado de Valores , and the Dirección General de Seguros y Fondos de Pen- siones , depending on the entity type – required a con - centrated effort that exposed gaps in vendor manage - ment governance. Supervisory focus in 2026 is shifting from implementa - tion to verification. Spanish financial supervisors are conducting their first review cycles, examining wheth - er the policies and procedures adopted in 2024 and 2025 reflect genuine operational practice or merely documentary compliance. Particular attention is being paid to the management of concentration risk in ICT third-party relationships – the risk that critical services are excessively dependent on a small number of pro - viders – and to the adequacy of contractual clauses with ICT vendors, which DORA specifies in consider - able detail. The overlap between DORA and NIS 2 One source of practical complexity for Spanish organ - isations is the interaction between DORA and NIS 2. The European Commission published guidelines in September 2023 clarifying the relationship between the two frameworks: DORA applies as lex specialis to financial entities, effectively displacing many NIS 2 obligations for entities in the financial sector. However, this lex specialis relationship is not absolute. Financial entities that also operate digital infrastructure – for example, large banks running data centre or cloud services – may find themselves subject to both frame - works for different aspects of their operations. The Digital Omnibus package proposed by the Com - mission in November 2025 seeks to address this com - plexity by introducing a single-entry point for incident reporting across NIS 2, DORA, GDPR, eIDAS, and the CER Directive. This “report once, share many” archi - tecture would represent a significant simplification for organisations currently managing multiple, over - lapping notification obligations with different time -

lines, formats, and recipients. However, the Omnibus remains in the early stages of the legislative proce - dure; its final form – and the timeline for its adoption – will depend on negotiations between the European Parliament and the Council of the EU. The Cyber Resilience Act: product security comes of age The Cyber Resilience Act entered into force on 10 December 2024 and introduces a product-focused dimension to EU cybersecurity regulation that was absent from the earlier NIS and GDPR frameworks. The CRA imposes mandatory cybersecurity require - ments – including security-by-design, vulnerabil - ity management, and the maintenance of security updates – on manufacturers, importers, and distribu - tors of products with digital elements. The CRA’s main obligations will not become fully applicable until 11 December 2027, but two ear - lier deadlines matter now. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026 – a date that is already within the operational planning horizon of manufac - turers who are bringing products to the EU market. From mid-December 2025, the European Commission adopted detailed technical descriptions for product categories under Classes I and II and Annex IV, giving manufacturers the information they need to determine whether their products require self-assessment or third-party conformity assessment by a Notified Body. For Spanish companies – including the significant number that manufacture connected devices for industrial, health, and consumer applications – the CRA represents a paradigm shift. Cybersecurity is no longer a post-market consideration but a legal con - dition of market access. Supply-chain accountability extends throughout the product life cycle, from design through to end-of-life. Manufacturers who discover that a product they have placed on the market con - tains an unpatched vulnerability that poses a signifi - cant risk must notify ENISA and the relevant national authority, and must take corrective action – including, where necessary, product recalls.

347 CHAMBERS.COM

Powered by