NIS2 Country Guide

NIS2 Spain: Still Not in the BOE, and What That Means

Spain has not transposed the NIS2 Directive. The Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers on 14 January 2025 and, as at 4 August 2026, has still not been published in the Boletín Oficial del Estado. On 8 July 2026 the European Commission referred Spain to the Court of Justice and asked for financial penalties. This page sets out the status, how to verify it yourself, and — more usefully — what already binds you while there is no Spanish law.

Not in the BOE as at 4 Aug 2026 Referred to the CJEU: 8 July 2026 Draft: Ley de Coordinación y Gobernanza de la Ciberseguridad Planned authority: Centro Nacional de Ciberseguridad Last updated: 4 August 2026

Introduction: NIS2 Directive & the Spanish context

Spain already has a relatively advanced national cybersecurity framework, including the National Security Scheme (Esquema Nacional de Seguridad – ENS) and specific rules for 5G networks and services. Until now, however, regulation has been fragmented across several decrees and sectoral rules rather than a single NIS2-aligned law.

Directive (EU) 2022/2555 (NIS2) requires Spain to consolidate and upgrade this framework. The intended vehicle is the Ley de Coordinación y Gobernanza de la Ciberseguridad, which would transpose NIS2, integrate the EU Critical Entities Resilience (CER) rules, and create a new Centro Nacional de Ciberseguridad. That law does not exist yet, and the practical question for a Spanish business is not what it will say but what applies in the meantime.

Important: as at 4 August 2026 the law has still not been published in the BOE, and Spain has been referred to the Court of Justice over the delay. That does not leave Spanish organisations unregulated — see “What binds you right now” below.

Has Spain transposed NIS2 yet?

No. As at 4 August 2026, the Ley de Coordinación y Gobernanza de la Ciberseguridad has not been published in the Boletín Oficial del Estado. It is still an anteproyecto — a pre-draft approved by the Government but not yet enacted. There is no Spanish NIS2 law in force.

QuestionAnswer as at 4 August 2026
Is NIS2 transposed in Spain?No
Is the law published in the BOE?No
Was the draft approved by the Government?Yes — Council of Ministers, 14 January 2025
Has the EU acted?Yes — referred to the Court of Justice on 8 July 2026
What is in force instead?The NIS1 regime — see the next section
How to check this yourself, in under a minute. Search the BOE's own database at boe.es for “coordinación y gobernanza de la ciberseguridad”. If the law has been enacted since this page was updated, it will appear there with a publication date and a BOE reference; if it returns nothing, the position on this page still holds. A law that is not in the BOE is not in force in Spain, and no amount of press coverage changes that. We deliberately do not predict a publication date — see Sources for why.

The infringement chain

StepDate
EU transposition deadline17 October 2024
Letter of formal notice28 November 2024
Reasoned opinion7 May 2025
Referral to the Court of Justice of the EU8 July 2026
Case referenceINFR(2024)0270

The Commission has asked the Court to impose a lump sum plus daily penalty payments, accruing until Spain notifies complete transposition. Spain was referred alongside Ireland, France and the Netherlands in the same decision. The amounts are for the Court to set and none has been fixed.

What binds you right now

This is the section that matters. “No Spanish NIS2 law” is not the same as “no obligations”, and the four channels below already reach most organisations that will eventually be in scope.

  1. The NIS1 regime is still in force. Real Decreto-ley 12/2018 and Real Decreto 43/2021 continue to apply to operators of essential services and digital service providers until they are replaced. If you were in scope under NIS1, nothing has lapsed.
  2. The ENS applies to the public sector and its suppliers. Real Decreto 311/2022 (Esquema Nacional de Seguridad) binds public administrations and, through procurement, a large part of their supply chain. Much of what NIS2 will require is already ENS work.
  3. DORA applies directly to financial entities. It is a regulation, so it needed no transposition and has applied since January 2025 regardless of Spain's NIS2 delay.
  4. Your customers' obligations flow down to you. Clients established in the 20-plus member states that have transposed are contractually obliged to manage supply-chain cybersecurity risk. In practice that arrives as security clauses, questionnaires and audit rights in contracts — and it is already the most common way NIS2 reaches a Spanish supplier.
The legal point, stated plainly. An EU directive that has not been transposed cannot impose obligations or sanctions directly on private parties; the consequence of non-transposition falls on the member state, which is exactly what the CJEU referral is about. So the absence of a Spanish law is genuine and you are not currently exposed to Spanish NIS2 fines. That is a reason to plan calmly, not a reason to do nothing — when the law is published it is expected to enter into force without a long transition period, and the work below takes longer than the gap will last.

NIS2 implementation in Spain

On 14 January 2025 the Council of Ministers approved the Draft Law on Cybersecurity Coordination and Governance (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad), which is the main legislative vehicle to transpose NIS2 into Spanish law. The draft was published for public consultation in January and is being processed under an urgent parliamentary procedure.

The draft merges NIS2 with the EU Critical Entities Resilience (CER) framework and establishes a national governance model built around a new Centro Nacional de Ciberseguridad, defining the roles of existing bodies such as INCIBE-CERT and CCN-CERT alongside it. The anteproyecto places the centre adscrito al Gabinete de la Presidencia — attached to the Presidency's Cabinet — rather than inside the Ministry of the Interior, which sponsors the bill.

Spain missed the transposition deadline of 17 October 2024 and, more than nineteen months after the Government approved the draft, the law is still not in the BOE. Earlier versions of this page said that adoption looked imminent. That has repeatedly proved wrong, and we no longer make the prediction — the status and the verification method above are more useful than a forecast.

Status

Not transposed. The anteproyecto was approved by the Council of Ministers on 14 January 2025 and has not been published in the BOE as at 4 August 2026. Spain was referred to the Court of Justice on 8 July 2026.

Legal structure (planned)

A single Cybersecurity Coordination and Governance Law will transpose NIS2 and CER, define scope, obligations, authorities and sanctions, and sit alongside existing instruments like the ENS for public-sector and critical information systems.

Scope

The draft law follows NIS2 in classifying entities as essential or important, expanding coverage to sectors such as waste management, food, scientific research and public administrations in addition to traditional critical sectors.

Am I in scope in Spain?

Because there is no Spanish law, scope today is a question about the draft and about the NIS1 rules that remain in force. The draft follows the Directive closely, so an assessment done against NIS2 will hold up.

CategoryTest
Essential entities Medium and large organisations in the high-criticality sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, space, public administration.
Important entities Medium and large organisations in the other critical sectors — postal and courier, waste management, chemicals, food, manufacturing, digital providers, research.
Size The draft works from the standard EU thresholds: broadly, 50 or more employees, or annual turnover or balance-sheet total above EUR 10 million, with large-enterprise treatment above EUR 50 million turnover or EUR 43 million balance sheet.
Regardless of size DNS service providers, TLD name registries, trust service providers, and providers of public electronic communications networks or services.
Already regulated today If you are an operator of essential services or a digital service provider under RDL 12/2018 and RD 43/2021, you are in scope of the NIS1 regime now, irrespective of the new law.

The draft provides for autoridades de control to identify and register entities once the law is in force. Until then there is no NIS2 registration duty in Spain, because there is no register.

NIS2 Spain: what you need to know about compliance

Even before the Spanish law is formally adopted, NIS2 gives a clear picture of the obligations that essential and important entities will face. The draft law essentially mirrors those requirements and embeds them into Spain’s legal and institutional landscape.

What changes when the law lands

  • A national register of essential and important entities, run by the autoridades de control, replaces today's NIS1 identification process.
  • A designated responsable de la seguridad de la información, whose appointment and any later change must be notified to the control authority — failing to do so on time is a listed minor infringement.
  • Mandatory training for employees and for management bodies, also a listed infringement if omitted.
  • An incident-management point of contact available 24 hours a day, every day.
  • A sanctions regime with figures attached — see the fine scale below.

Core obligations (expected)

  • Implement risk-management measures covering governance, policies, asset management, network and system security, access control, vulnerability management, backup and recovery.
  • Maintain incident-preparedness and business continuity plans, including disaster recovery and crisis-communication procedures.
  • Report significant cyber incidents and certain cyber threats on tight deadlines (initial notification within 24 hours, followed by more detailed reports).
  • Manage supply-chain cybersecurity risk, including contractual requirements for key providers and due diligence on ICT and security suppliers.
  • Ensure that senior management is directly responsible for cybersecurity governance, approves policies and receives regular training and reporting.

Practical approach

In practice, Spanish organisations are advised to treat NIS2 as the “north star” and use the draft law as an interpretive guide, aligning controls with recognised frameworks such as ISO/IEC 27001 or NIST CSF and integrating them with ENS requirements where applicable.

Key message: the text can still change in Parliament, so treat every figure on this page as draft. What will not change is the Directive underneath it — an assessment run against NIS2 Article 21 will survive whatever Spain finally enacts, which is why the gap is best spent on the assessment rather than on watching the BOE.

Competent authorities & CSIRTs (planned)

Spain already has strong operational capability in INCIBE-CERT and CCN-CERT. The draft adds a new coordinating centre above them. None of this is in force yet — the table below describes what the anteproyecto proposes.

Role Authority Notes
Planned national cybersecurity authority & Single Point of Contact Centro Nacional de Ciberseguridad A new body which the anteproyecto places adscrito al Gabinete de la Presidencia — attached to the Presidency's Cabinet, not inside the Ministry of the Interior, which sponsors the bill. It would coordinate national cybersecurity policy, act as single point of contact for EU cooperation and sit above the existing CSIRTs. The draft fixes no acronym for it, and it does not yet exist.
National CSIRT for citizens & enterprises INCIBE-CERT (within INCIBE) Handles incident reporting and support for businesses and citizens, issues alerts, and provides guidance and awareness-raising materials on cybersecurity.
National CSIRT for public sector & classified information CCN-CERT (part of the National Cryptologic Centre, CNI) Focuses on public administrations and systems handling sensitive or classified information, working closely with other authorities for major incidents.
Sectoral supervision Autoridades de control — to be designated The anteproyecto refers to autoridades de control throughout and gives them the job of identifying and supervising entities, but it does not name individual regulators in the way many summaries suggest. We do not list specific bodies here — see Sources for why.

Incident reporting in Spain

Two regimes to keep straight: the one that applies today under NIS1, and the one the anteproyecto would introduce.

Today, under RD 43/2021

Operators of essential services and digital service providers already notify incidents through their reference CSIRT — INCIBE-CERT for private-sector entities, CCN-CERT for the public sector. This obligation is live and unaffected by the NIS2 delay.

Under the draft law

An alerta temprana (early warning), then a fuller notification, then a final report within one month of that notification. Entities would have to keep an incident-management contact reachable 24 hours a day, every day. The control authority or CSIRT owes a response to the early warning.

Reporting failures are separately punishable under the draft. Notifying without including the information the law requires, and sending incomplete, inaccurate or unduly delayed information to the control authority or CSIRT, are both listed as infracciones leves — carrying EUR 10,000 to EUR 100,000. Failing to ask the national CSIRT for specialised help when you cannot resolve an incident yourself is listed as a more serious breach.

NIS2 timeline & key dates (Spain)

3 May 2022 — Royal Decree 311/2022 updates the National Security Scheme (ENS), strengthening cybersecurity requirements for Spanish public-sector systems.
14 December 2022 — NIS2 Directive adopted at EU level, setting 17 October 2024 as the transposition deadline for Member States.
17 October 2024 — EU deadline passes; Spain has not yet transposed NIS2, triggering European Commission infringement steps.
14 January 2025 — Council of Ministers approves the Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, announcing urgent processing and the creation of a Centro Nacional de Ciberseguridad.
January–February 2025 — Public consultation on the draft law; stakeholders provide comments on scope, obligations and governance model.
28 November 2024 — European Commission sends Spain a letter of formal notice for failure to notify transposition.
7 May 2025 — Commission issues a reasoned opinion, the second stage of the infringement procedure.
8 July 2026 — Commission refers Spain to the Court of Justice of the EU, case INFR(2024)0270, asking for a lump sum and daily penalty payments. Ireland, France and the Netherlands are referred in the same decision.
4 August 2026 — The Ley de Coordinación y Gobernanza de la Ciberseguridad has still not been published in the BOE. The NIS1 regime under RDL 12/2018 and RD 43/2021 remains the law in force.

Sector-specific notes for Spain

  • Energy: electricity, gas and oil operators, as well as major grid and generation assets, are expected to be classified as essential entities with strict resilience obligations, especially after recent large-scale outages.
  • Transport: rail, air, maritime and road transport operators, ports and airports will fall in scope, reflecting Spain’s role as a key logistics hub in Europe and the Mediterranean.
  • Digital infrastructure & telecom: electronic communications networks, data centres, cloud and major digital platform providers will face strong requirements on uptime, incident reporting and continuity planning.
  • Finance & DORA interplay: banks and financial market infrastructures will need to align NIS2 obligations with existing EU financial ICT-risk frameworks such as DORA, avoiding duplicated controls.
  • Public administration & services: central, regional and local administrations, as well as certain public entities, will be explicitly covered, building on ENS and extending obligations to broader digital services.
  • Waste, food & research: sectors newly highlighted by NIS2 (waste management, food supply, scientific research) will also be affected, particularly where they operate critical facilities or support essential services.

How Spain's draft differs from the NIS2 Directive

Four differences worth knowing before the law lands, because they change what a Spanish programme has to budget for. All of them are draft and can change in Parliament.

  1. A three-tier fine scale with minimums. The Directive sets ceilings only. The anteproyecto grades infringements as leves, graves and muy graves and puts a floor under each — from EUR 10,000 up to EUR 2,000,000 — reserving the Directive's EUR 10 million and EUR 7 million ceilings for two specific categories of very serious breach.
  2. Public naming in the BOE as an accessory sanction. For serious and very serious infringements the fine may be accompanied by a public reprimand published in the Boletín Oficial del Estado, identifying the responsible person and the nature of the breach. For most organisations that is a bigger deterrent than the fine.
  3. Public-sector bodies cannot be fined at all. Under Article 43 of the draft, infringements by public sector bodies are not sanctioned. The competent body instead orders corrective measures, notifies those affected and may propose disciplinary proceedings. Several member states fine public entities; Spain proposes not to.
  4. NIS2 and CER in one instrument. The draft transposes the Critical Entities Resilience Directive alongside NIS2, so physical and cyber resilience arrive together rather than in two separate laws — a consolidation most member states did not attempt.
The largest difference is the one nobody plans for: Spain has no law at all, while its customers, suppliers and competitors across the EU have been operating under one for up to two years. The practical consequence is that Spanish entities are meeting NIS2 through other people's contracts before they ever meet it through Spanish law.

Penalties and the draft fine scale

No Spanish NIS2 fine can be imposed today, because there is no law. What follows is the scale in Article 42 of the anteproyecto, which is more detailed than the Directive and than most published summaries of it. Treat every figure as draft.

TierRange
Infracciones levesEUR 10,000 – EUR 100,000
Infracciones gravesEUR 100,001 – EUR 500,000
Infracciones muy gravesEUR 500,001 – EUR 2,000,000

For the two most serious categories of breach specifically, the draft applies the Directive's ceilings instead:

  • Essential entity: up to EUR 10,000,000 or 2% of total global annual turnover in the previous financial year, whichever is higher.
  • Important entity: up to EUR 7,000,000 or 1.4% of total global annual turnover, whichever is higher.
Publication in the BOE as an accessory sanction. Fines for serious and very serious infringements may be accompanied by a public reprimand published in the Boletín Oficial del Estado, naming the responsible person and the nature of the infringement.
Public-sector bodies are not fined. Under Article 43, infringements by public sector organs, bodies and entities are not subject to sanction. Instead the competent authority orders measures to stop and correct the effects of the infringement, notifies the body and anyone affected, and may propose disciplinary proceedings.

The draft's infracciones leves include failing to notify the appointment or replacement of the information security officer on time, failing to train employees and management bodies, and sending incomplete or inaccurate information to the control authority — so the lowest tier is not reserved for trivia.

How to prepare for NIS2 in Spain

  1. Check if you are likely in scope: map your business against NIS2 Annex I & II sectors and Spanish critical sectors; consider size, revenue and the essential nature of your services.
  2. Check the BOE rather than the headlines: search boe.es for “coordinación y gobernanza de la ciberseguridad”. Publication there is the only event that changes your legal position, and it is a one-minute check you can repeat monthly.
  3. Confirm your NIS1 position first: if you are an operator of essential services or a digital service provider under RDL 12/2018 and RD 43/2021, you have live obligations today that the NIS2 delay does not suspend.
  4. Run a NIS2 readiness assessment: benchmark your current cybersecurity governance, controls, incident response and documentation against NIS2 Article 21 and the obligations outlined in the draft law.
  5. Align with ENS where applicable: if you already fall under the National Security Scheme (ENS), align your NIS2 preparations with ENS requirements to avoid duplicated work.
  6. Strengthen detection & incident reporting: make sure you can detect, investigate and classify incidents quickly, and that you have processes to notify authorities within 24 hours when required.
  7. Address supply-chain risk: identify critical suppliers and update contracts with clear cybersecurity, audit and incident-notification clauses consistent with NIS2 expectations.
  8. Use recognised frameworks: build or refine your information security management system using ISO/IEC 27001, NIST CSF or similar to structure your compliance roadmap.
  9. Engage leadership early: inform boards and senior management about expected obligations and sanctions so they can allocate funding, set risk appetite and support a multi-year roadmap.

Operating in more than one EU country?

DNS service providers, TLD name registries, cloud computing, data centre and content delivery network providers, managed service and managed security service providers, and online marketplaces, search engines and social networking platforms answer to the regulator where their main establishment sits, rather than in every member state they serve.

Spain's delay creates a specific trap for those entity types. If your main establishment is in Spain, there is currently no Spanish authority to register with and no Spanish supervisor — but that does not move your main establishment somewhere else, and it does not exempt you. Meanwhile Implementing Regulation (EU) 2024/2690 applies to you directly, because it is a regulation and needs no transposition. For those entity types the technical requirements are already binding in Spain even though the Spanish law is not.

If Spain is one of several markets, the neighbouring pages are further ahead and show what is coming: Portugal has been in force since April 2026, Italy and Belgium are running registration and conformity programmes, and France and Ireland were referred to the Court alongside Spain.

Official links & resources

FAQ: NIS2 in Spain

Has Spain fully transposed NIS2?
No. As at 4 August 2026 the Ley de Coordinación y Gobernanza de la Ciberseguridad has not been published in the BOE, so there is no Spanish NIS2 law in force. The Council of Ministers approved the anteproyecto on 14 January 2025, and on 8 July 2026 the European Commission referred Spain to the Court of Justice over the delay. You can confirm the current position yourself by searching boe.es.
What law will implement NIS2 in Spain?
The future Cybersecurity Coordination and Governance Law (Ley de Coordinación y Gobernanza de la Ciberseguridad) is the main instrument that will transpose NIS2 and the CER Directive into Spanish law.
Who will be the main NIS2 authority?
The draft creates a Centro Nacional de Ciberseguridad, which the anteproyecto places adscrito al Gabinete de la Presidencia — attached to the Presidency's Cabinet — as the national authority and single point of contact, working alongside INCIBE-CERT and CCN-CERT. The draft fixes no acronym for it, and the body does not exist yet. Note that CNCS is Portugal's national cybersecurity centre, not Spain's; the two are frequently confused.
Should we wait for the law to be approved before acting?
No — but be clear about why. You are not currently exposed to Spanish NIS2 fines, because an untransposed directive cannot sanction private parties. You are, however, already covered by the NIS1 regime if it applied to you, by the ENS if you serve the public sector, by DORA if you are a financial entity, and by your customers' supply-chain obligations. The law is also expected to enter into force without a long transition period once published, and a gap assessment takes longer than that.
How high can fines be?
None can be imposed today, because there is no law. The draft sets a three-tier scale with minimums — EUR 10,000 to 100,000 for minor infringements, EUR 100,001 to 500,000 for serious ones and EUR 500,001 to 2,000,000 for very serious ones — and reserves the Directive's EUR 10 million / 2% and EUR 7 million / 1.4% ceilings for two specific categories of very serious breach. Serious and very serious fines may also carry a public reprimand published in the BOE.
Is ISO 27001 mandatory?
ISO/IEC 27001 is not expected to be mandatory by name, but the law will require robust, risk-based security measures. Aligning with ISO 27001 or similar frameworks is a practical way to structure and evidence compliance in Spain.

Sources & verification

Spain is the hardest country on this site to write about accurately, because the most-repeated facts are about a law that does not exist. Everything below is taken from the anteproyecto text itself, from the Departamento de Seguridad Nacional, or from the European Commission's infringement record.

SourceUsed forChecked
Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — full text published by the Ministerio del Interior The three-tier fine scale and its minimums (Article 42), the BOE public-reprimand sanction, the public-sector exemption (Article 43), the list of minor infringements (Article 41), the placement of the Centro Nacional de Ciberseguridad, the reporting stages and the 24-hour contact duty 4 August 2026
Departamento de Seguridad Nacional — official note The centre's official name, its role as single national competent authority and point of contact, and the 14 January 2025 Council of Ministers approval 4 August 2026
European Commission infringement record The 17 October 2024 deadline, the 28 November 2024 letter of formal notice, the 7 May 2025 reasoned opinion, the 8 July 2026 referral to the Court of Justice, case INFR(2024)0270, and the request for a lump sum plus daily penalties 4 August 2026
Boletín Oficial del Estado Confirming that the law has not been published 4 August 2026

What this page deliberately does not state

  • Any predicted adoption or BOE publication date. An earlier version of this page said that “all signals point to adoption in the short term”. That was written in January 2025 and has been wrong for more than nineteen months. We now give the status, the date we checked it and the method for checking it again, and make no forecast.
  • An acronym for the Centro Nacional de Ciberseguridad. The anteproyecto fixes none. This page previously used “CNCS”, which is Portugal's national cybersecurity centre; some commentary uses “CNC”. Neither is official, so we use the full name.
  • Named sectoral regulators. This page previously listed the CNMC and the CNMV as NIS2 sectoral authorities for Spain. Neither appears anywhere in the 80-page anteproyecto, which refers only to autoridades de control to be designated. The claim has been removed rather than repeated.
  • Any fine figure as final. Every euro amount on this page comes from a draft that Parliament can still amend. They are given because they are more precise than the Directive's ceilings and useful for budgeting, not because they are settled law.
  • A count of entities in scope. No official Spanish estimate has been published.
Information provided for general guidance. Spain has not yet transposed NIS2; always check the Boletín Oficial del Estado for the current legal position, and consult INCIBE-CERT, CCN-CERT and Spanish legal counsel for definitive requirements.