NIS2 in Spain — a draft still in flight, a CJEU action, and the RD 43/2021 regime carrying on.
Spain has not yet transposed NIS2. The anteproyecto cleared the Consejo de Ministros on 14 January 2025 but has not reached the Boletín Oficial del Estado, and on 8 July 2026 the Court of Justice was seised in the Commission's transposition-delay action against Spain — alongside France and Ireland. Until the law lands, the operative regime remains the NIS1-era Real Decreto 43/2021, with INCIBE-CERT serving private-sector entities and CCN-CERT serving public administration and defence.
The draft's headline proposal matters for planning: a new Centro Nacional de Ciberseguridad. If it survives the parliamentary process, Spain's authority landscape consolidates around a body that does not yet exist — which makes “who will supervise us, and under what thresholds” a genuinely open question for Spanish entities, not a settled fact to look up.
Who it applies to
Entities in the NIS2 sectors operating in Spain. The size-threshold and sector analysis can be done today against the directive itself — most entities that will be essential or important under the Spanish law can determine that position now. What cannot be assumed is timing: registration deadlines, evidence duties and the supervisor of record all wait for the law. INCIBE and CCN guidance under the current regime continues to apply to entities already inside it.
The clock
Competent authority: INCIBE-CERT (private) + CCN-CERT (public/defence) under RD 43/2021 — transposition pending. Transposition: Draft transposition bill (anteproyecto, not yet in the BOE).
| When | What happens |
|---|---|
| 14 Jan 2025 | Anteproyecto approved by the Consejo de Ministros · proposes a Centro Nacional de Ciberseguridad |
| Pending | Draft not yet published in the BOE · parliamentary process open |
| 8 Jul 2026 | Court of Justice seised in the transposition-delay action (with France and Ireland) |
| Today | RD 43/2021 regime continues · INCIBE-CERT (private) and CCN-CERT (public/defence) |
A new authority that does not exist yet
Spain's draft does something none of the settled transpositions did: it proposes to consolidate supervision in a new Centro Nacional de Ciberseguridad. Until the law passes, the dual-track INCIBE/CCN structure inherited from the RD 43/2021 era keeps operating — so a Spanish entity's practical question is double-layered: what the directive will ask of us (answerable now), and who will enforce it and when (answerable only by tracking the bill). TruSecure holds both: the applicability analysis against the directive text today, and the legislative status — anteproyecto stage, Court of Justice action live — as a tracked, dated fact that flips the plan the moment the BOE publishes.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Spain transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Determine scope against the directive now | Applicability engine · sector and threshold analysis, ready for the Spanish text |
| Track the bill and the Court of Justice action | Compliance workspace · legislative status held as a dated, monitored fact |
| Continue RD 43/2021 duties if already inside | Control library · existing obligations credited, not restarted |
| Map INCIBE vs CCN routing under the current regime | Entity profile · routing recorded, updated when the law lands |
| Prepare incident workflow to the directive's clocks | Incident workflow · 24 h / 72 h / 1-month stages pre-built |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Applicability (directive)
- confirmed · projected essential, energy sector
- Current regime
- RD 43/2021 · obligations maintained and evidenced
- Legislative tracking
- anteproyecto since 14 Jan 2025 · CJEU action 8 Jul 2026
- Controls evidenced
- 69/84 · 15 open, each with an owner and a date
- Export
- sealed · sha256:2d8f...9a4c
Where teams usually start
With a demo walked through by TruSecure — your projected scope under the directive, your continuing RD 43/2021 obligations credited and evidenced, and the Spanish bill tracked as a dated fact so the compliance plan moves when the BOE does. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Spain by INCIBE-CERT (private) + CCN-CERT (public/defence) under RD 43/2021 — transposition pending. TruSecure determines applicability against Spain's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.