Cybersecurity 2026

SPAIN Trends and Developments Contributed by: Rodrigo González, Vicente Moret, María Teresa Martínez and Cristina Durante, Deloitte Legal

Key considerations for Spanish manufacturers and importers Organisations in Spain preparing for the CRA should focus on three immediate priorities. First, scope deter - mination: the CRA applies to virtually all products with digital elements, with limited exceptions for products regulated by sector-specific rules such as medical devices or civil aviation equipment. Companies need to assess their product portfolio systematically against the regulatory categories and identify whether any products qualify as Class I or Class II important prod - ucts (requiring either standard or enhanced conformity assessment) or as critical products under Annex IV (requiring third-party assessment by a Notified Body). Second, governance and process integration: compli - ance with the CRA is not a one-time certification exer - cise. It requires the integration of cybersecurity into product development life cycles, the establishment of vulnerability disclosure and co-ordinated vulnerability management processes, and the contractual mapping of obligations across supply chains. Third, the inter - play with existing legal frameworks – GDPR where the product processes personal data, NIS 2 where the manufacturer is itself a covered entity, and the AI Act where artificial intelligence is embedded in the product – requires an integrated legal strategy rather than a framework-by-framework approach. The National Security Framework: a cornerstone of Spanish cybersecurity While European regulation captures most of the head - lines, the Esquema Nacional de Seguridad (ENS) remains an indispensable reference point for cyber - security in Spain, particularly for public sector enti - ties and private companies that provide services to public administrations. The ENS – updated by Royal Decree 311/2022 – establishes a comprehensive set of security requirements and certification categories applicable to information systems used by the pub - lic sector, with alignment to international standards including ISO/IEC 27001. The relationship between the ENS and the incoming NIS 2 transposition law is an area of active regulatory development. Spain’s draft law explicitly recognises the ENS as a key compliance mechanism for public sector entities falling within NIS 2’s scope, effectively

leveraging the existing national framework to meet European obligations. For private sector entities that are already ENS-certified as part of their public sector supply relationships, this creates a valuable compli - ance bridge – though one that does not eliminate the need for gap analysis against the specific risk man - agement and incident reporting requirements of NIS 2. In practice, many Spanish companies providing cloud computing, software, cybersecurity services, and managed services to public authorities are simulta - neously managing ENS certification requirements, NIS 2 obligations (or preparations for them), and – if they serve financial sector clients – DORA-derived contractual requirements. This convergence of frame - works, while complex, also creates an opportunity for organisations that invest in integrated compliance architecture to compete more effectively for public and regulated-sector contracts. Board liability and cybersecurity governance: the accountability revolution One of the most consequential – and least discussed – aspects of the new EU cybersecurity framework is the explicit imposition of personal accountability on the management bodies of covered organisations. NIS 2 requires that management bodies not only approve cybersecurity risk management measures but actively oversee their implementation and bear personal liabil - ity for infringements attributable to their failure to do so. Spain’s draft transposition law preserves and, in some respects, reinforces this approach. This is a structural change in how cybersecurity gov - ernance is conceived in Spanish corporate law. Pre - viously, cybersecurity was predominantly a matter delegated to IT or information security functions, with board oversight limited to annual reporting or occa - sional briefings. The new framework treats cyber risk as a category of strategic business risk that demands the same level of board attention as financial risk or regulatory compliance in other domains. Management bodies must receive adequate training to understand and assess cybersecurity risks, must formally approve the organisation’s risk management measures, and must ensure that dedicated internal resources and processes exist to implement and maintain them.

348 CHAMBERS.COM

Powered by