SPAIN Trends and Developments Contributed by: Rodrigo González, Vicente Moret, María Teresa Martínez and Cristina Durante, Deloitte Legal
are both tools of compliance and potential objects of cybersecurity risk in their own right. Spain’s National Cybersecurity Forum ( Foro Nacion- al de Ciberseguridad ) – in which Deloitte Legal has actively participated – has identified AI governance as a priority theme for 2026, reflecting the growing recog - nition that organisations need integrated frameworks for managing AI-related cyber risk that are coherent with their NIS 2 and DORA compliance programmes. Regulatory sandboxes provided for under the AI Act offer an opportunity for Spanish companies to test AI-based security tools in a supervised environment, potentially accelerating innovation while managing regulatory risk. Supply-chain security: the hidden compliance frontier Supply-chain security has become one of the most operationally complex aspects of the new cyberse - curity framework. NIS 2 explicitly requires essential and important entities to address cybersecurity risks in their supply chains and vendor relationships, includ - ing by assessing the security practices of their direct suppliers and service providers. DORA goes further, imposing detailed contractual requirements on ICT third-party arrangements for financial entities and establishing a supervisory framework for critical ICT third-party providers at EU level. In practice, this means that cybersecurity compliance is no longer confined to the internal perimeter of an organisation. It extends upstream to technology ven - dors, cloud providers, software developers, and man - aged service providers – and, in many cases, requires these suppliers to demonstrate their own compliance with relevant frameworks as a condition of maintain - ing commercial relationships. Spanish organisations in the financial sector have experienced this most acute - ly under DORA, where the Register of Information exercise revealed the extent and complexity of ICT supply chains that had not previously been mapped with legal rigour. The CRA adds a product-focused dimension to sup - ply-chain security by imposing obligations on manu - facturers to document and assess the cybersecurity of components incorporated into their products with
digital elements, including open-source software components. This is generating significant discussion in the software industry, where the widespread use of open-source components – including commercially embedded and OEM offerings – creates complex questions about responsibility for vulnerability dis - closure and patching across distributed development communities. Organisations navigating supply-chain security obli - gations in Spain should invest in three capabilities: comprehensive supplier mapping (including sub- processors and sub-contractors where relevant), contractual frameworks that embed cybersecurity requirements and audit rights, and ongoing monitoring processes that can identify and respond to emerging risks in the supply chain on a continuous basis rather than at annual review points. Conclusion: from compliance to resilience strategy The cybersecurity regulatory landscape facing Span - ish organisations in 2026 is more demanding, more interconnected, and more strategically consequential than at any previous point. NIS 2, DORA, the CRA, and the ENS are not parallel tracks to be managed sepa - rately by different functions within an organisation. They are components of a single, integrated European regulatory architecture designed to shift the culture of cybersecurity – from a technical discipline managed in the background to a strategic governance priority managed at the highest organisational levels. Spain’s delayed NIS 2 transposition creates short- term legal uncertainty but does not reduce the compli - ance obligations of organisations in scope. If anything, it increases the risk of a compressed implementation timeline once the law is adopted, with regulatory expectations and enforcement activity arriving in close succession. The organisations that will be best posi - tioned – legally, operationally, and reputationally – are those that have used the transposition period to build genuine cybersecurity capabilities rather than waiting for the final text to initiate their programmes. The convergence of cybersecurity, data protection, and AI regulation also demands a different kind of legal advisory model – one that combines deep regulatory expertise with operational insight and technological
350 CHAMBERS.COM
Powered by FlippingBook