- The NIS2 Directive expands sectors and obligated entities, strengthens governance and toughens supervision and the sanctions regime.
- Spain is lagging behind in transposition through the future Cybersecurity Coordination and Governance Law.
- Essential and important entities must appoint a security officer, manage risks comprehensively, and report incidents within very strict deadlines.
- The ENS, the new National Cybersecurity Center and the CSIRT ecosystem place Spain in a solid technical position, although the big challenge lies in the adaptation of thousands of SMEs.
The European NIS2 Directive has completely transformed the cybersecurity landscape in Europe, and especially in Spain. This is not just another regulation; it represents a fundamental shift in how companies and public administrations manage digital risks, report incidents, and coordinate with authorities.
Meanwhile, Spain is making steady but clearly delayed progress in its transposition: the official deadline was October 2024, and to this day, the future Cybersecurity Coordination and Governance Law is still going through parliamentary procedures. This situation creates a somewhat peculiar scenario: the Directive is already binding at the European level, but the definitive national legal framework has not yet been approved, leaving many organizations caught between the moral and strategic obligation to prepare and assess their situation and the absence of a fully applicable law.
What is the NIS2 Directive and why does it change the rules of the game?
Directive (EU) 2022/2555, known as NIS2 , replaces the original NIS Directive with the aim of establishing a high common level of cybersecurity for networks and information systems across the European Union. Its purpose is to strengthen resilience against cyber incidents that could affect essential services and the normal functioning of society and the economy.
Unlike its predecessor, NIS2 significantly expands the number of sectors and entities affected , incorporating not only traditional critical infrastructures (energy, transport, water, banking or health), but also areas such as public administration, digital infrastructures, postal and courier services, waste management, advanced manufacturing or food production and distribution.
The Directive establishes a harmonized framework of minimum cybersecurity requirements for the entire EU, with measures for risk management, governance, supply chain protection, business continuity, and early incident notification. Furthermore, it strengthens the monitoring and sanctions regime and explicitly increases the responsibility of senior management.
Another significant development is the clear commitment to cooperation between Member States and the creation or strengthening of national Computer Security Incident Response Teams (CSIRTs) , capable of coordinating at the European level in serious crisis situations. ENISA, the EU Agency for Cybersecurity, plays a key role in this ecosystem, supporting the development of national cybersecurity strategies and promoting best practices.
The financial sector is essentially excluded from the scope of NIS2 , as DORA regulations take precedence as the lex specialis. Even so, the logic of digital operational resilience that drives DORA is fully consistent with the NIS2 philosophy.
Current status of the transposition of NIS2 in Spain
The NIS2 Directive came into force on January 16, 2023 , and set October 17, 2024, as the deadline for its transposition. One year after that deadline, Spain still had not completed the formal incorporation into its internal legal system, placing it in the group of lagging countries.
As a result of this delay, the European Commission opened infringement proceedings against numerous Member States. On 7 May 2025, the Commission sent a reasoned opinion to nineteen countries, including Spain, requiring them to notify the full transposition of the Directive within two months, under the warning that it could refer the matter to the Court of Justice of the EU if the necessary measures were not taken.
In the case of Spain, the major turning point occurred on January 14, 2025, with the approval by the Council of Ministers of the Draft Law on Cybersecurity Coordination and Governance . This law will serve as the fundamental instrument for transposing NIS2 into domestic law and reorganizing the national cybersecurity governance model.
Following its initial approval, the draft bill was made available for public consultation and review between January 16 and February 10, 2025 , allowing citizens, businesses, associations, and other organizations to submit comments and suggestions for improvement. Subsequently, the text was reviewed by the Interministerial Technical Working Group, which consolidated the draft taking into account the feedback received, including that from expert communities such as the ISMS Forum.
Even so, and despite the political momentum, the law remains in the parliamentary process . There has been talk of its submission to the Council of Ministers for approval as a bill around November and of possible parliamentary approval by the end of January or February of the following year, but the reality is that, until the end of 2025, Spain still lacks a fully applicable national law transposing NIS2.
The Draft Law on Cybersecurity Coordination and Governance
The draft bill approved by the Spanish Government is a joint initiative of the Ministries of the Interior, Defense, and Digital Transformation and Public Administration . Its purpose is twofold: firstly, to transpose the NIS2 Directive, and secondly, to organize the coordination and governance of cybersecurity at the national level, strengthening the protection of networks and information systems against cyber threats that could impact critical infrastructure and essential services.
The future law will apply to public and private entities operating in sectors such as energy, transport, banking and financial market infrastructure, healthcare, water management, digital infrastructure, technology services, and other critical sectors . It explicitly includes domain name registries , such as Dominios.es (managed by Red.es), which will assume new cybersecurity obligations due to their strategic role in the stability of the digital ecosystem.
In general terms, the draft aligns with the main obligations of the NIS2 Directive and articulates four key axes: strengthening governance and senior management responsibility, general security risk management measures, designation of an information security officer and clear incident reporting obligations.
Furthermore, the Spanish law introduces a significant organizational element: the creation of the National Cybersecurity Center (CNC) . This body will act as a coordinating body for the protection of networks and information systems, harmonizing criteria among different regulatory authorities (Interior, Defense, and Digital Transformation), promoting Computer Security Incident Response Teams (CSIRTs), and facilitating a more cohesive vision of the national cybersecurity ecosystem.
During the public consultation phase, organizations such as ISMS Forum made significant contributions : strengthening the role of the information security officer, separating this position from the Private Security Law, and establishing specific response mechanisms when the non-compliant entity is a public administration, which, by its very nature, cannot be financially penalized. Among the proposals is the possibility of public warnings, in line with the provisions of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) regarding data protection.
Sectors and types of entities affected by NIS2
NIS2 classifies organizations subject to the Directive as essential or important entities , primarily based on the sector in which they operate and their size (medium and large companies, with exceptions based on criticality). The standard generally applies to public or private entities operating in the EU, with the possibility of including smaller organizations when Member States identify them as essential or important due to their relevance.
The sectors of high criticality are listed in Annex I of NIS2, while other critical sectors are listed in Annex II . In Spain, the increase in the number of sectors is somewhat smaller than in other countries, because the transposition of the old NIS was already aligned with Law 8/2011 on the Protection of Critical Infrastructures, which included 12 sectors. Even so, NIS2 incorporates new areas such as postal and courier services, waste management, and several manufacturing categories , and splits others, for example, distinguishing between drinking water and wastewater.
Among the sectors and examples of entities , the following stand out:
- EnergyElectricity supply companies, transport and distribution network managers, producers, NEMO operators, electricity market participants, charging point operators; gas, oil and hydrogen network operators and managers.
- Transport: airlines, airport operators, air traffic control, railway infrastructure managers, railway companies, maritime and river transport entities, port operators, ship traffic services, road authorities and intelligent transport system operators.
- Banking and financial market infrastructure: credit institutions and managers of trading centers, central counterparties, with the nuance that DORA acts as a specific sectoral standard.
- Health sector: healthcare providers, EU reference laboratories, R&D entities for medicines, manufacturers of basic and specialty pharmaceutical products, and manufacturers of essential medical devices in public health emergencies.
- Drinking water and wastewaterSuppliers and distributors of drinking water, and companies responsible for the collection, disposal and treatment of urban, domestic or industrial wastewater.
- digital infrastructureInternet exchange point (IXP) providers, DNS services, top-level domain registries, cloud computing service providers, data centers, content delivery networks (CDNs), trusted service providers, public electronic communications network providers, and public electronic communications services.
- Business-to-business ICT service management: managed service providers and managed security service providers, with a direct impact on the entire technology supply chain.
- Public administrations: entities of the General State Administration and, in certain cases, regional and local entities, when the disruption of their services may significantly impact critical social or economic activities.
- Postal and courier services: suppliers that perform collection, sorting, transport and distribution of postal shipments.
- Waste management: companies dedicated to the collection, transport, recovery and disposal of waste, including landfills.
- Chemical: companies that manufacture, produce and distribute chemical substances and mixtures, as well as produce articles from them.
- Production, processing and distribution of food: food companies dedicated to wholesale distribution and large-scale industrial production and processing.
- advanced manufacturing: manufacturers of health products and in vitro diagnostics, manufacture of computer, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles and other transport equipment.
- Space sector: operators of terrestrial infrastructure that support the provision of space services, except those whose ownership or management corresponds to the EU or to third parties within the framework of its space program.
In all these sectors, large entities are generally classified as essential , while medium-sized entities tend to be important, unless specifically designated otherwise. Small and micro-enterprises are usually excluded due to their size, but may be included if their criticality justifies it.
Governance and senior management responsibilities
One of the most significant shifts in NIS2 and the Spanish draft legislation is the emphasis on cybersecurity governance and the direct responsibility of governing bodies . Article 14 of the draft legislation reinforces this idea: cybersecurity is no longer a purely technical matter, but rather a top-level strategic issue.
Senior management must approve and oversee the implementation of cybersecurity risk management measures , ensuring they are proportionate to the organization's context and the identified risks. Furthermore, the governing bodies will bear ultimate responsibility for any non-compliance, which links to the enhanced sanctions regime.
Another key point is regular cybersecurity training for management . Simply delegating isn't enough: leaders must be trained to understand the risks, make informed decisions, and support the spread of a strong security culture throughout the organization. In turn, they will be responsible for promoting regular training programs for the rest of the staff.
Article 20 of NIS2 reinforces this view by expressly requiring governing bodies to be aware of their obligations, approve the measures, ensure their implementation and be able to respond, in extreme situations, even with personal consequences (such as the possible separation of functions in certain cases).
In this context, the relationship between management and the information security officer (CISO or equivalent) becomes critical: a fluid, constant dialogue based on objective risk and compliance criteria is expected.
Risk management measures required by NIS2
Article 15 of the Spanish draft law establishes that cybersecurity risk management measures must be based on national, European and international technical standards , integrating, at a minimum, the requirements set out in Article 21 of NIS2 and developed in Implementing Regulation (EU) 2024/2690.
Among the measures that essential and important entities must implement , the following stand out:
- Security policies and risk analysis of the information systems, with periodic reviews.
- Incident Management, including clear detection, response and recovery procedures.
- Business continuity, backups, disaster recovery, and crisis managementensuring operational resilience.
- Supply chain security and of the relationships with suppliers and direct service providers, which involves imposing contractual requirements and approval and audit controls.
- vulnerability management in the acquisition, development and maintenance of networks and information systems, including patches and updates.
- Policies for evaluating the effectiveness of cybersecurity measuresthrough audits, metrics, and periodic reviews.
- Basic cyber hygiene practices and training of employees, adapted to the different profiles.
- Cryptography and encryption policies to guarantee the confidentiality and integrity of the information.
- Human Resources SecurityAccess control and asset management policies.
- Multi-factor or continuous authentication, protection of voice communications and emergency communications.
In Spain, many of these measures were already included in the National Security Framework (ENS) , especially for public administrations and their suppliers. In fact, the State Agency for Digital Administration and the National Cryptologic Center have presented to the EU the strong alignment of the ENS with NIS2, highlighting its potential as a European benchmark and its contribution to the resilience of the national digital ecosystem.
However, NIS2 raises the bar for a much broader range of organizations, including SMEs affected by size or criticality . For mature organizations, many of these requirements align with existing practices; for thousands of companies with no cybersecurity background, they represent a significant leap in maturity, resources, and internal organization.
The Chief Information Security Officer (CISO) and their functions
Article 16 of the draft bill establishes that all essential and important entities must appoint an information security officer . This role, inspired by Spain's previous experience with the original NIS, becomes the central point for coordinating everything related to the protection of systems and data.
Its main functions include:
- Define and implement the organization's cybersecurity strategy, aligned with risks, business and regulatory obligations.
- Evaluate, mitigate, and continuously review risks, maintaining an up-to-date view of the entity's exposure.
- Manage evidence, policies, and records necessary to demonstrate compliance of the obligations arising from NIS2 and national regulations.
- Promote a cybersecurity culture in coordination with senior management, training and raising awareness among all staff.
- Ensure compliance with incident reporting obligations, coordinating the reports to the competent authorities.
Spain was one of the first countries to explicitly introduce the role of Chief Information Security Officer (CISO) in the transposition of the former NIS. However, experience showed that a significant number of key operators never formally appointed this role and, even so, were not penalized. NIS2, combined with the future Spanish law and a stricter sanctions regime, seeks to correct this laxity and give the CISO a more robust and recognized position.
Looking ahead, a massive increase in obligated entities is expected : from approximately 400 current essential operators to an estimated 5.000 to 50.000 essential and important entities. This will imply a significant demand for cybersecurity professionals, both in-house and outsourced, especially for SMEs that have never previously had this role.
Incident reporting and vulnerability management obligations
The NIS2 Directive places paramount importance on the early notification of security incidents with significant impact . Article 18 of the Spanish draft legislation elaborates on this obligation, aligning with the timelines and content established by the Directive.
When an entity suffers an incident that could cause serious disruptions to the provision of its services or considerable damage to itself or to third parties, it must comply with the following reporting scheme:
- Initial notification: within a maximum of 24 hours after the incident is detected, providing the basic information available.
- interim report: within a maximum of 72 hours from detection, with an initial assessment of the impact and severity.
- Final report: within a maximum period of one month from the first notification, including a detailed description of the incident, its impact, severity and the measures taken.
Furthermore, NIS2 strengthens vulnerability management and communication : it is not only about reporting completed incidents, but also about sharing relevant information on vulnerabilities that may have a systemic impact, facilitating the coordination of responses at national and European levels.
In Spain, the response ecosystem relies on three major reference CSIRTs : the CCN-CERT (for public administration, strategic companies, and classified systems), INCIBE-CERT (private sector and citizens), and the MCCE (defense sector). These are complemented by the csirt.es network, which brings together dozens of specialized teams and connects with international networks such as FIRST, as well as the National SOC Network.
Essential and important entities must report their incidents to the competent CSIRTs , in accordance with sector regulations and the guidelines of the future National Cybersecurity Centre, which will act as a coordinating element and liaison with ENISA and the rest of the Member States.
Sanctions regime and European pressure
The NIS2 Directive establishes a significantly stricter penalty regime than the previous NIS Directive . For essential entities, the most serious infringements can result in fines of up to €10 million or 2% of the group's global turnover, while for major entities, penalties can reach up to €7 million or 1,4% of global turnover.
Currently, no sanctions based on NIS2 have yet been seen in Spain , partly because the transposition law is not yet in force and the supervisory authority has not been formally designated. In other Member States, transposition is recent, so it is still too early to expect widespread sanctions.
Even so, experts agree that when countries like France or Germany begin to apply sanctions , Spain cannot afford to lag behind if it wants to maintain harmonization and credibility at the European level. The Commission's pressure, through infringement procedures and reasoned opinions, is aimed at achieving this.
In addition to the financial penalties, NIS2 explicitly introduces, for the first time, the responsibility of senior management in cybersecurity . The disconnect between management and the CISO is no longer an option: the governing body must be involved, informed, and make the necessary decisions.
The biggest challenge, according to specialists like those at ISMS Forum, lies within the network of SMEs that, without being fully aware of it, will be bound by NIS2 . Many lack sufficient resources, processes, or cybersecurity culture, and will be "pushed" both by the law and by the demands of their large clients in the supply chain, who will have to demand contractual guarantees to comply with the Directive.
Support initiatives, studies and the role of the ENS
Alongside legislative progress, Spain is promoting technical and knowledge initiatives to facilitate the adaptation of the business sector to NIS2. ISMS Forum, for example, is working on a Study of the Impact of NIS2 on Spanish Companies, under the Extraordinary Chair of Cybersecurity and Data Protection at the UCM.
This project has a dual objective: to build an unofficial census of companies affected by NIS2 and to measure their cybersecurity maturity level. In the first phase, the census will be compiled using comprehensive databases (commercial registry, DIRCE/INE, sector-specific databases, etc.), with results expected around November 2025. In the second phase, a short questionnaire will be sent to a representative sample of companies (targeting 1.000 responses) to assess their level of preparedness, with results expected by May 2026.
The analysis will include segmentations by sector, size, geographical distribution and type of entity (essential or important) , presenting the conclusions in an aggregate executive report, without individual data, that serves both companies and authorities.
At the same time, organizations like ISMS Forum and various public agencies are conducting outreach events across the country , with a particular focus on SMEs. The goal is to "evangelize," clearly explaining what NIS2 entails, why having a CISO (internal or external) is essential, how to define basic cybersecurity policies, and how to prepare for the future law and its supplementary regulations.
In strictly regulatory terms, the National Security Framework (ENS) has been presented in Europe as one of Spain's greatest strengths . The State Agency for Digital Administration and the National Cryptologic Center (CCN) have shared the ENS's accumulated experience, its compliance profiles, and its integration with the European certification schemes of Regulation (EU) 2019/881 (Cybersecurity Act) with the NIS2 Cooperation Group. The positive reception of this presentation reinforces Spain's image as a proactive actor committed to robust, coherent, and harmonized cybersecurity.
In this context, Spain's adaptation to NIS2 is navigating the pressure of deadlines, the technical robustness of instruments like the National Security Scheme (ENS), and the enormous challenge of incorporating thousands of new entities into an advanced cybersecurity culture. Organizations that get ahead, conduct situational assessments, and begin aligning their practices with the Directive now will be better positioned to minimize risks, avoid future penalties, and demonstrate a proactive and mature approach to cyber threats.

