Checked on September 27, 2026

NIS2 in Spain

How Spain applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.

Transposition status
Draft law, not yet adopted
National law
Draft Law on Cybersecurity Coordination and Governance · Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad
Competent authority
National Cybersecurity Centre (to be created by the draft law, attached to the Presidency of the Government) (Centro Nacional de Ciberseguridad)
Registration
Required

No registration regime in force until the law is published in the BOE.

Incident reporting
Pending the NIS2 law; under current RD-ley 12/2018 (NIS1) private operators report to INCIBE-CERT and public-sector entities to CCN-CERT.
National specifics
  • Draft approved by the Council of Ministers on 14 Jan 2025; still not published in the BOE as of Sept 2026.
  • European Commission referred Spain to the CJEU on 8 Jul 2026 for failure to notify full NIS2 transposition.
  • Royal Decree-law 12/2018 (NIS1) still governs.

Where does your company stand?

The free assessment applies these national rules to your answers and scores every area of the law.

Sources

National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.

NIS2 in other countries

NIS2 in Spain: national law, authority and registration | Parendum