In brief: The Cybersecurity Coordination and Governance Law is the instrument through which Spain transposes the NIS2 Directive. As of July 2026 it is still going through the legislative process: the Council of Ministers approved the preliminary bill on 14 January 2025, but it has not yet been published in the Official State Gazette (BOE). It creates the National Cybersecurity Centre as the national authority, splits supervision between several ministries, and will coexist with the ENS. Here I explain what it adds to the directive, what deadlines it sets, and what you should do in the meantime.

Spain was required to transpose the NIS2 Directive by 17 October 2024, and it failed to do so. The chosen instrument is the Cybersecurity Coordination and Governance Law, whose preliminary bill was approved by the Council of Ministers in January 2025 and which, as of July 2026, is still awaiting parliamentary approval. The law does not simply copy the directive: it creates the National Cybersecurity Centre as the single national authority, splits sector supervision between the Ministries of the Interior, Defence, and Digital Transformation, sets up a registry of essential and important entities, and establishes a penalty regime with fines of up to 10 million euros. Until it is published, the applicable reference remains the NIS1 framework currently in force and, for the public sector and its suppliers, the ENS (Spanish National Security Framework).

Every few weeks someone asks me the same question: "Is NIS2 already mandatory in Spain?" The short answer is that the European directive has set the direction since 2022, but the entity that will actually demand concrete things from you — registering, notifying incidents, holding you personally liable if you're a director — is the Spanish law that transposes it. And that law, the Cybersecurity Coordination and Governance Law, has been in the works for more than a year. Here's where it really stands, what it adds to the directive, and why sitting back and waiting for it to be published is the worst possible strategy.

What is the Cybersecurity Coordination and Governance Law?

It is the law through which Spain incorporates Directive (EU) 2022/2555, known as NIS2, into its domestic legal system. NIS2 replaces the original Network and Information Security directive. The name is no accident: it describes its two objectives. On one hand, coordination, because until now cybersecurity powers were split between bodies that didn't always talk to each other; on the other, governance, meaning defining who is in charge, who supervises, and who is accountable.

The preliminary bill is a joint proposal from three ministries — the Interior, Defence, and Digital Transformation and Public Function — which already hints at the power-sharing arrangement you'll see further below. Compared with the original NIS directive, which focused on essential-service operators in a handful of specific sectors, this one broadens the scope to many more organisations and, for the first time, fully reaches medium-sized private companies that previously never expected to be regulated.

Has the law been passed? Status of Spain's NIS2 transposition (July 2026)

No, it has not been passed yet. Here is the real status, with dates, so you don't have to rely on headlines:

  • 17 October 2024: the deadline set by the directive for all member states to have completed transposition. Spain missed it.
  • 14 January 2025: the Council of Ministers approves the preliminary bill in its first reading and opts for urgent processing.
  • May 2025: the European Commission sends Spain a reasoned opinion for failing to notify full transposition, as part of infringement case INFR(2024)0270.
  • May 2026: with no progress made, the Commission takes a further step with a new formal notice, the stage before referring the State to the Court of Justice of the EU, with possible financial penalties.
  • July 2026: the bill is still going through parliamentary proceedings and has not been published in the BOE. It is expected to enter into force at some point in 2026, most likely the day after publication and without a lengthy transitional period.

It's worth being clear on a legal distinction that is often overlooked: until the law is published, NIS2's specific obligations are not directly enforceable against most private companies, because a directive needs transposition to take effect on individuals and businesses. What does remain in force is the framework of the original NIS directive — transposed at the time through Royal Decree-Law 12/2018 and Royal Decree 43/2021 — which will keep applying until the new law replaces it. In other words: there is no legal vacuum, but there is an imminent change of scale.

What the Spanish law adds to the NIS2 Directive

A directive sets the "what" and leaves the "how" to each country. That's where this law contributes. The directive requires designating authorities, setting up response teams, and imposing penalties; the Spanish law fills in those pieces with names attached:

What the NIS2 Directive requiresHow the Spanish law implements it
Designate one or more competent national authoritiesCreates the National Cybersecurity Centre (CNC) as the single national authority and point of contact
Supervise compliance by sectorSplits supervision between the Ministries of the Interior, Defence, and Digital Transformation
Identify essential and important entitiesEstablishes a national registry of entities subject to the law
Incident response teams (CSIRTs)Relies on existing CSIRTs: CCN-CERT and INCIBE-CERT
An "effective and dissuasive" penalty regimeSets specific amounts and holds management bodies liable
Cybersecurity crisis managementAssigns the CNC the role of national crisis-management authority

The real value of the law lies in that right-hand column: without it, NIS2's obligations remain up in the air, because there's no one to enforce them, nowhere to register, and no clarity on what happens if you fail to comply.

National Cybersecurity Centre: the planned national authority

The centrepiece of the law is the National Cybersecurity Centre (CNC), attached to the Office of the Prime Minister. Under the preliminary bill, it will be the sole competent national authority responsible for directing, driving, and coordinating all the activity set out in the law, as well as acting as the single point of contact with EU institutions and as the national cybersecurity crisis-management authority. Important: the CNC does not exist yet; this future law is what creates it. Until then, those liaison functions are handled by the National Security Department.

Who will supervise each sector?

The law does not concentrate all oversight in a single body. It splits sector supervision between three ministries, each through its specialised arm:

  • Ministry of the Interior, through the Cybersecurity Coordination Office.
  • Ministry of Defence, through the National Cryptologic Centre (CCN), which is already the technical reference for the public sector.
  • Ministry for Digital Transformation and the Civil Service, through the competent secretariats of state.

Until the law comes into force, the provisional map is the one already in place: the single point of contact sits with the National Security Council through the National Security Department, the CCN and its CCN-CERT cover the public sector, and INCIBE-CERT serves the business community. This division of powers is also one of the model's regular criticisms: the more actors involved, the more it matters that coordination — the very word the law is named after — actually works.

Deadlines and penalties under the cybersecurity law

This is the part that generates the most questions, because it directly affects the company's finances and the personal liability of whoever runs it.

What penalties does it set for companies?

The penalty regime follows the ranges set by NIS2, which distinguishes two categories of entities:

  • Essential entities: fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher.
  • Important entities: fines of up to 7 million euros or 1.4% of total worldwide annual turnover, whichever is higher.

Beyond the amounts, there's a deeper shift: the liability of management bodies. The regulation makes directors responsible for approving and overseeing cybersecurity measures, with the possibility of personal liability. Cybersecurity stops being "an IT matter" and becomes a board-level obligation. If you want an overview of how all this fits together with the GDPR and DORA, you'll find it in my guide to cybersecurity regulation in Spain.

What happens while the law is not yet passed?

Two things are happening at once. For the State, the clock is ticking: the European Commission's infringement case could end up at the Court of Justice of the EU, with fines against the Kingdom of Spain for the delay. For companies, uncertainty is no excuse not to prepare, because once the law is published it is expected to enter into force almost immediately, without the years of lead time other regulations have accustomed us to. Anyone who starts on publication day will already be late.

How the cybersecurity law, NIS2 and the ENS relate to each other

This is the most common confusion I see, so let me clear it up from the ground up. These are three complementary layers, not alternatives to choose between:

  • NIS2 is the European directive: the common framework that requires Spain to legislate.
  • The Cybersecurity Coordination and Governance Law is its transposition: it turns that framework into obligations enforceable here, for both the public sector and a broad group of private companies.
  • The ENS, the National Security Framework regulated by Royal Decree 311/2022, is the security framework for the public sector and the companies that provide it services.

The good news if you already work with the ENS: many of its controls overlap with the risk-management measures required by Article 21 of NIS2 (risk analysis, incident management, continuity, supply-chain security, encryption, access control). It's not an automatic equivalence, but a system aligned with the ENS leaves you a good part of the way there for NIS2. If you're a supplier to the Administration, this overlap matters especially to you, because your ENS conformity already covers requirements the new law will reinforce. And if you operate in the financial sector, remember that the DORA regulation also applies there, with its own rules on operational resilience.

What your company should do while the law is being passed

Preparing now isn't getting ahead of yourself for the sake of it: it's the only way to be ready in time once the text is published. These are the steps I recommend, in order:

  • Find out if it affects you. The first filter is knowing whether you'll be an essential or important entity based on your sector and size. I put together a quick test to check whether NIS2 applies to you that settles the question in a few minutes.
  • Do a serious risk analysis. It's the foundation for everything else and the first evidence you'll be asked for. If you don't know where to start, a security master plan helps prioritise without overspending.
  • Set up your incident-notification protocol. NIS2 works with tight deadlines — an early warning within 24 hours, notification within 72, and a final report within a month — so you need the internal process defined beforehand, not during the crisis.
  • Review your supply chain. Your technology providers are part of your risk analysis; it's worth having their security commitments in writing.
  • Involve senior management. Since liability falls on governing bodies, cybersecurity needs to be on the board's agenda, with a budget and someone accountable.
  • Build on what you already have. If you hold ENS conformity or ISO 27001 certification, reuse those controls: they're the most reliable shortcut toward NIS2.

Conclusion: an imminent law you shouldn't wait for

The Cybersecurity Coordination and Governance Law has spent too long in limbo, but that doesn't make it any less serious: once passed, it will bring a national registry, an authority with sanctioning powers, and personal liability for directors, and it will do so with little room to adapt. The legislative process is being delayed; the threats are not. The companies using this time to put their risks and procedures in order will be the ones that comply from day one; the ones waiting for the BOE will be the ones left scrambling.

If you're not sure whether your company falls within NIS2's scope or where to start preparing, tell me about your case and we'll look at it together, with no obligation. And if you'd prefer a comprehensive approach, take a look at my cybersecurity consultancy service for companies that want to comply with the regulation without over-engineering it.

I handle marketing consultancy and regulatory compliance projects from Aranda de Duero (Burgos), with in-person coverage in Valladolid, Burgos, Palencia and all of Castilla y León. Also from Las Palmas de Gran Canaria and the whole Canary archipelago. If your organisation is based anywhere else in Spain, we can also work together remotely.

Frequently asked questions about NIS2 in Spain

What is the Cybersecurity Coordination and Governance Law?

It is the law through which Spain incorporates Directive (EU) 2022/2555, known as NIS2, into its domestic legal system. NIS2 replaces the original Network and Information Security directive. The name is no accident: it describes its two objectives. On one hand, coordination, because until now cybersecurity powers were split between bodies that didn't always talk to each other; on the other, governance, meaning defining who is in charge, who supervises, and who is accountable.

Who will supervise each sector?

The law does not concentrate all oversight in a single body. It splits sector supervision between three ministries, each through its specialised arm:

What penalties does it set for companies?

The penalty regime follows the ranges set by NIS2, which distinguishes two categories of entities:

What happens while the law is not yet passed?

Two things are happening at once. For the State, the clock is ticking: the European Commission's infringement case could end up at the Court of Justice of the EU, with fines against the Kingdom of Spain for the delay. For companies, uncertainty is no excuse not to prepare, because once the law is published it is expected to enter into force almost immediately, without the years of lead time other regulations have accustomed us to. Anyone who starts on publication day will already be late.

Sources

Content prepared by Ángel Ortega Castro for angelortegacastro.com. This is informational content; for any legal obligation, always check the current text of the law in the BOE once it is published, and the NIS2 Directive on EUR-Lex.