Checked on September 27, 2026
NIS2 in Spain
How Spain applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- Draft law, not yet adopted
- National law
- Draft Law on Cybersecurity Coordination and Governance · Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad
- Competent authority
- National Cybersecurity Centre (to be created by the draft law, attached to the Presidency of the Government) (Centro Nacional de Ciberseguridad)
- Registration
- Required
No registration regime in force until the law is published in the BOE.
- Incident reporting
- Pending the NIS2 law; under current RD-ley 12/2018 (NIS1) private operators report to INCIBE-CERT and public-sector entities to CCN-CERT.
- National specifics
- Draft approved by the Council of Ministers on 14 Jan 2025; still not published in the BOE as of Sept 2026.
- European Commission referred Spain to the CJEU on 8 Jul 2026 for failure to notify full NIS2 transposition.
- Royal Decree-law 12/2018 (NIS1) still governs.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.