NIS2 Spain: Still Not in the BOE, and What That Means
Spain has not transposed the NIS2 Directive. The Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers on 14 January 2025 and, as at 4 August 2026, has still not been published in the Boletín Oficial del Estado. On 8 July 2026 the European Commission referred Spain to the Court of Justice and asked for financial penalties. This page sets out the status, how to verify it yourself, and — more usefully — what already binds you while there is no Spanish law.
Introduction: NIS2 Directive & the Spanish context
Spain already has a relatively advanced national cybersecurity framework, including the National Security Scheme (Esquema Nacional de Seguridad – ENS) and specific rules for 5G networks and services. Until now, however, regulation has been fragmented across several decrees and sectoral rules rather than a single NIS2-aligned law.
Directive (EU) 2022/2555 (NIS2) requires Spain to consolidate and upgrade this framework. The intended vehicle is the Ley de Coordinación y Gobernanza de la Ciberseguridad, which would transpose NIS2, integrate the EU Critical Entities Resilience (CER) rules, and create a new Centro Nacional de Ciberseguridad. That law does not exist yet, and the practical question for a Spanish business is not what it will say but what applies in the meantime.
Has Spain transposed NIS2 yet?
No. As at 4 August 2026, the Ley de Coordinación y Gobernanza de la Ciberseguridad has not been published in the Boletín Oficial del Estado. It is still an anteproyecto — a pre-draft approved by the Government but not yet enacted. There is no Spanish NIS2 law in force.
| Question | Answer as at 4 August 2026 |
|---|---|
| Is NIS2 transposed in Spain? | No |
| Is the law published in the BOE? | No |
| Was the draft approved by the Government? | Yes — Council of Ministers, 14 January 2025 |
| Has the EU acted? | Yes — referred to the Court of Justice on 8 July 2026 |
| What is in force instead? | The NIS1 regime — see the next section |
The infringement chain
| Step | Date |
|---|---|
| EU transposition deadline | 17 October 2024 |
| Letter of formal notice | 28 November 2024 |
| Reasoned opinion | 7 May 2025 |
| Referral to the Court of Justice of the EU | 8 July 2026 |
| Case reference | INFR(2024)0270 |
The Commission has asked the Court to impose a lump sum plus daily penalty payments, accruing until Spain notifies complete transposition. Spain was referred alongside Ireland, France and the Netherlands in the same decision. The amounts are for the Court to set and none has been fixed.
What binds you right now
This is the section that matters. “No Spanish NIS2 law” is not the same as “no obligations”, and the four channels below already reach most organisations that will eventually be in scope.
- The NIS1 regime is still in force. Real Decreto-ley 12/2018 and Real Decreto 43/2021 continue to apply to operators of essential services and digital service providers until they are replaced. If you were in scope under NIS1, nothing has lapsed.
- The ENS applies to the public sector and its suppliers. Real Decreto 311/2022 (Esquema Nacional de Seguridad) binds public administrations and, through procurement, a large part of their supply chain. Much of what NIS2 will require is already ENS work.
- DORA applies directly to financial entities. It is a regulation, so it needed no transposition and has applied since January 2025 regardless of Spain's NIS2 delay.
- Your customers' obligations flow down to you. Clients established in the 20-plus member states that have transposed are contractually obliged to manage supply-chain cybersecurity risk. In practice that arrives as security clauses, questionnaires and audit rights in contracts — and it is already the most common way NIS2 reaches a Spanish supplier.
NIS2 implementation in Spain
On 14 January 2025 the Council of Ministers approved the Draft Law on Cybersecurity Coordination and Governance (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad), which is the main legislative vehicle to transpose NIS2 into Spanish law. The draft was published for public consultation in January and is being processed under an urgent parliamentary procedure.
The draft merges NIS2 with the EU Critical Entities Resilience (CER) framework and establishes a national governance model built around a new Centro Nacional de Ciberseguridad, defining the roles of existing bodies such as INCIBE-CERT and CCN-CERT alongside it. The anteproyecto places the centre adscrito al Gabinete de la Presidencia — attached to the Presidency's Cabinet — rather than inside the Ministry of the Interior, which sponsors the bill.
Spain missed the transposition deadline of 17 October 2024 and, more than nineteen months after the Government approved the draft, the law is still not in the BOE. Earlier versions of this page said that adoption looked imminent. That has repeatedly proved wrong, and we no longer make the prediction — the status and the verification method above are more useful than a forecast.
Status
Not transposed. The anteproyecto was approved by the Council of Ministers on 14 January 2025 and has not been published in the BOE as at 4 August 2026. Spain was referred to the Court of Justice on 8 July 2026.
Legal structure (planned)
A single Cybersecurity Coordination and Governance Law will transpose NIS2 and CER, define scope, obligations, authorities and sanctions, and sit alongside existing instruments like the ENS for public-sector and critical information systems.
Scope
The draft law follows NIS2 in classifying entities as essential or important, expanding coverage to sectors such as waste management, food, scientific research and public administrations in addition to traditional critical sectors.
Am I in scope in Spain?
Because there is no Spanish law, scope today is a question about the draft and about the NIS1 rules that remain in force. The draft follows the Directive closely, so an assessment done against NIS2 will hold up.
| Category | Test |
|---|---|
| Essential entities | Medium and large organisations in the high-criticality sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, space, public administration. |
| Important entities | Medium and large organisations in the other critical sectors — postal and courier, waste management, chemicals, food, manufacturing, digital providers, research. |
| Size | The draft works from the standard EU thresholds: broadly, 50 or more employees, or annual turnover or balance-sheet total above EUR 10 million, with large-enterprise treatment above EUR 50 million turnover or EUR 43 million balance sheet. |
| Regardless of size | DNS service providers, TLD name registries, trust service providers, and providers of public electronic communications networks or services. |
| Already regulated today | If you are an operator of essential services or a digital service provider under RDL 12/2018 and RD 43/2021, you are in scope of the NIS1 regime now, irrespective of the new law. |
The draft provides for autoridades de control to identify and register entities once the law is in force. Until then there is no NIS2 registration duty in Spain, because there is no register.
NIS2 Spain: what you need to know about compliance
Even before the Spanish law is formally adopted, NIS2 gives a clear picture of the obligations that essential and important entities will face. The draft law essentially mirrors those requirements and embeds them into Spain’s legal and institutional landscape.
What changes when the law lands
- A national register of essential and important entities, run by the autoridades de control, replaces today's NIS1 identification process.
- A designated responsable de la seguridad de la información, whose appointment and any later change must be notified to the control authority — failing to do so on time is a listed minor infringement.
- Mandatory training for employees and for management bodies, also a listed infringement if omitted.
- An incident-management point of contact available 24 hours a day, every day.
- A sanctions regime with figures attached — see the fine scale below.
Core obligations (expected)
- Implement risk-management measures covering governance, policies, asset management, network and system security, access control, vulnerability management, backup and recovery.
- Maintain incident-preparedness and business continuity plans, including disaster recovery and crisis-communication procedures.
- Report significant cyber incidents and certain cyber threats on tight deadlines (initial notification within 24 hours, followed by more detailed reports).
- Manage supply-chain cybersecurity risk, including contractual requirements for key providers and due diligence on ICT and security suppliers.
- Ensure that senior management is directly responsible for cybersecurity governance, approves policies and receives regular training and reporting.
Practical approach
In practice, Spanish organisations are advised to treat NIS2 as the “north star” and use the draft law as an interpretive guide, aligning controls with recognised frameworks such as ISO/IEC 27001 or NIST CSF and integrating them with ENS requirements where applicable.
Incident reporting in Spain
Two regimes to keep straight: the one that applies today under NIS1, and the one the anteproyecto would introduce.
Today, under RD 43/2021
Operators of essential services and digital service providers already notify incidents through their reference CSIRT — INCIBE-CERT for private-sector entities, CCN-CERT for the public sector. This obligation is live and unaffected by the NIS2 delay.
Under the draft law
An alerta temprana (early warning), then a fuller notification, then a final report within one month of that notification. Entities would have to keep an incident-management contact reachable 24 hours a day, every day. The control authority or CSIRT owes a response to the early warning.
NIS2 timeline & key dates (Spain)
Sector-specific notes for Spain
- Energy: electricity, gas and oil operators, as well as major grid and generation assets, are expected to be classified as essential entities with strict resilience obligations, especially after recent large-scale outages.
- Transport: rail, air, maritime and road transport operators, ports and airports will fall in scope, reflecting Spain’s role as a key logistics hub in Europe and the Mediterranean.
- Digital infrastructure & telecom: electronic communications networks, data centres, cloud and major digital platform providers will face strong requirements on uptime, incident reporting and continuity planning.
- Finance & DORA interplay: banks and financial market infrastructures will need to align NIS2 obligations with existing EU financial ICT-risk frameworks such as DORA, avoiding duplicated controls.
- Public administration & services: central, regional and local administrations, as well as certain public entities, will be explicitly covered, building on ENS and extending obligations to broader digital services.
- Waste, food & research: sectors newly highlighted by NIS2 (waste management, food supply, scientific research) will also be affected, particularly where they operate critical facilities or support essential services.
How Spain's draft differs from the NIS2 Directive
Four differences worth knowing before the law lands, because they change what a Spanish programme has to budget for. All of them are draft and can change in Parliament.
- A three-tier fine scale with minimums. The Directive sets ceilings only. The anteproyecto grades infringements as leves, graves and muy graves and puts a floor under each — from EUR 10,000 up to EUR 2,000,000 — reserving the Directive's EUR 10 million and EUR 7 million ceilings for two specific categories of very serious breach.
- Public naming in the BOE as an accessory sanction. For serious and very serious infringements the fine may be accompanied by a public reprimand published in the Boletín Oficial del Estado, identifying the responsible person and the nature of the breach. For most organisations that is a bigger deterrent than the fine.
- Public-sector bodies cannot be fined at all. Under Article 43 of the draft, infringements by public sector bodies are not sanctioned. The competent body instead orders corrective measures, notifies those affected and may propose disciplinary proceedings. Several member states fine public entities; Spain proposes not to.
- NIS2 and CER in one instrument. The draft transposes the Critical Entities Resilience Directive alongside NIS2, so physical and cyber resilience arrive together rather than in two separate laws — a consolidation most member states did not attempt.
Penalties and the draft fine scale
No Spanish NIS2 fine can be imposed today, because there is no law. What follows is the scale in Article 42 of the anteproyecto, which is more detailed than the Directive and than most published summaries of it. Treat every figure as draft.
| Tier | Range |
|---|---|
| Infracciones leves | EUR 10,000 – EUR 100,000 |
| Infracciones graves | EUR 100,001 – EUR 500,000 |
| Infracciones muy graves | EUR 500,001 – EUR 2,000,000 |
For the two most serious categories of breach specifically, the draft applies the Directive's ceilings instead:
- Essential entity: up to EUR 10,000,000 or 2% of total global annual turnover in the previous financial year, whichever is higher.
- Important entity: up to EUR 7,000,000 or 1.4% of total global annual turnover, whichever is higher.
The draft's infracciones leves include failing to notify the appointment or replacement of the information security officer on time, failing to train employees and management bodies, and sending incomplete or inaccurate information to the control authority — so the lowest tier is not reserved for trivia.
How to prepare for NIS2 in Spain
- Check if you are likely in scope: map your business against NIS2 Annex I & II sectors and Spanish critical sectors; consider size, revenue and the essential nature of your services.
- Check the BOE rather than the headlines: search boe.es for “coordinación y gobernanza de la ciberseguridad”. Publication there is the only event that changes your legal position, and it is a one-minute check you can repeat monthly.
- Confirm your NIS1 position first: if you are an operator of essential services or a digital service provider under RDL 12/2018 and RD 43/2021, you have live obligations today that the NIS2 delay does not suspend.
- Run a NIS2 readiness assessment: benchmark your current cybersecurity governance, controls, incident response and documentation against NIS2 Article 21 and the obligations outlined in the draft law.
- Align with ENS where applicable: if you already fall under the National Security Scheme (ENS), align your NIS2 preparations with ENS requirements to avoid duplicated work.
- Strengthen detection & incident reporting: make sure you can detect, investigate and classify incidents quickly, and that you have processes to notify authorities within 24 hours when required.
- Address supply-chain risk: identify critical suppliers and update contracts with clear cybersecurity, audit and incident-notification clauses consistent with NIS2 expectations.
- Use recognised frameworks: build or refine your information security management system using ISO/IEC 27001, NIST CSF or similar to structure your compliance roadmap.
- Engage leadership early: inform boards and senior management about expected obligations and sanctions so they can allocate funding, set risk appetite and support a multi-year roadmap.
Operating in more than one EU country?
DNS service providers, TLD name registries, cloud computing, data centre and content delivery network providers, managed service and managed security service providers, and online marketplaces, search engines and social networking platforms answer to the regulator where their main establishment sits, rather than in every member state they serve.
Spain's delay creates a specific trap for those entity types. If your main establishment is in Spain, there is currently no Spanish authority to register with and no Spanish supervisor — but that does not move your main establishment somewhere else, and it does not exempt you. Meanwhile Implementing Regulation (EU) 2024/2690 applies to you directly, because it is a regulation and needs no transposition. For those entity types the technical requirements are already binding in Spain even though the Spanish law is not.
If Spain is one of several markets, the neighbouring pages are further ahead and show what is coming: Portugal has been in force since April 2026, Italy and Belgium are running registration and conformity programmes, and France and Ireland were referred to the Court alongside Spain.
Official links & resources
FAQ: NIS2 in Spain
Has Spain fully transposed NIS2?
What law will implement NIS2 in Spain?
Who will be the main NIS2 authority?
Should we wait for the law to be approved before acting?
How high can fines be?
Is ISO 27001 mandatory?
Sources & verification
Spain is the hardest country on this site to write about accurately, because the most-repeated facts are about a law that does not exist. Everything below is taken from the anteproyecto text itself, from the Departamento de Seguridad Nacional, or from the European Commission's infringement record.
| Source | Used for | Checked |
|---|---|---|
| Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — full text published by the Ministerio del Interior | The three-tier fine scale and its minimums (Article 42), the BOE public-reprimand sanction, the public-sector exemption (Article 43), the list of minor infringements (Article 41), the placement of the Centro Nacional de Ciberseguridad, the reporting stages and the 24-hour contact duty | 4 August 2026 |
| Departamento de Seguridad Nacional — official note | The centre's official name, its role as single national competent authority and point of contact, and the 14 January 2025 Council of Ministers approval | 4 August 2026 |
| European Commission infringement record | The 17 October 2024 deadline, the 28 November 2024 letter of formal notice, the 7 May 2025 reasoned opinion, the 8 July 2026 referral to the Court of Justice, case INFR(2024)0270, and the request for a lump sum plus daily penalties | 4 August 2026 |
| Boletín Oficial del Estado | Confirming that the law has not been published | 4 August 2026 |
What this page deliberately does not state
- Any predicted adoption or BOE publication date. An earlier version of this page said that “all signals point to adoption in the short term”. That was written in January 2025 and has been wrong for more than nineteen months. We now give the status, the date we checked it and the method for checking it again, and make no forecast.
- An acronym for the Centro Nacional de Ciberseguridad. The anteproyecto fixes none. This page previously used “CNCS”, which is Portugal's national cybersecurity centre; some commentary uses “CNC”. Neither is official, so we use the full name.
- Named sectoral regulators. This page previously listed the CNMC and the CNMV as NIS2 sectoral authorities for Spain. Neither appears anywhere in the 80-page anteproyecto, which refers only to autoridades de control to be designated. The claim has been removed rather than repeated.
- Any fine figure as final. Every euro amount on this page comes from a draft that Parliament can still amend. They are given because they are more precise than the Directive's ceilings and useful for budgeting, not because they are settled law.
- A count of entities in scope. No official Spanish estimate has been published.
