Skip to main content
NIS2 · SPAIN

NIS2 in Spain — a draft still in flight, a CJEU action, and the RD 43/2021 regime carrying on.

Spain has not yet transposed NIS2. The anteproyecto cleared the Consejo de Ministros on 14 January 2025 but has not reached the Boletín Oficial del Estado, and on 8 July 2026 the Court of Justice was seised in the Commission's transposition-delay action against Spain — alongside France and Ireland. Until the law lands, the operative regime remains the NIS1-era Real Decreto 43/2021, with INCIBE-CERT serving private-sector entities and CCN-CERT serving public administration and defence.

The draft's headline proposal matters for planning: a new Centro Nacional de Ciberseguridad. If it survives the parliamentary process, Spain's authority landscape consolidates around a body that does not yet exist — which makes “who will supervise us, and under what thresholds” a genuinely open question for Spanish entities, not a settled fact to look up.

Who it applies to

Entities in the NIS2 sectors operating in Spain. The size-threshold and sector analysis can be done today against the directive itself — most entities that will be essential or important under the Spanish law can determine that position now. What cannot be assumed is timing: registration deadlines, evidence duties and the supervisor of record all wait for the law. INCIBE and CCN guidance under the current regime continues to apply to entities already inside it.

The clock

Competent authority: INCIBE-CERT (private) + CCN-CERT (public/defence) under RD 43/2021 — transposition pending. Transposition: Draft transposition bill (anteproyecto, not yet in the BOE).

NIS2 in Spain · timeline
WhenWhat happens
14 Jan 2025Anteproyecto approved by the Consejo de Ministros · proposes a Centro Nacional de Ciberseguridad
PendingDraft not yet published in the BOE · parliamentary process open
8 Jul 2026Court of Justice seised in the transposition-delay action (with France and Ireland)
TodayRD 43/2021 regime continues · INCIBE-CERT (private) and CCN-CERT (public/defence)

A new authority that does not exist yet

Spain's draft does something none of the settled transpositions did: it proposes to consolidate supervision in a new Centro Nacional de Ciberseguridad. Until the law passes, the dual-track INCIBE/CCN structure inherited from the RD 43/2021 era keeps operating — so a Spanish entity's practical question is double-layered: what the directive will ask of us (answerable now), and who will enforce it and when (answerable only by tracking the bill). TruSecure holds both: the applicability analysis against the directive text today, and the legislative status — anteproyecto stage, Court of Justice action live — as a tracked, dated fact that flips the plan the moment the BOE publishes.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Spain transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Spain requirements · how TruSecure answers them
What the law asksWhere it is answered
Determine scope against the directive nowApplicability engine · sector and threshold analysis, ready for the Spanish text
Track the bill and the Court of Justice actionCompliance workspace · legislative status held as a dated, monitored fact
Continue RD 43/2021 duties if already insideControl library · existing obligations credited, not restarted
Map INCIBE vs CCN routing under the current regimeEntity profile · routing recorded, updated when the law lands
Prepare incident workflow to the directive's clocksIncident workflow · 24 h / 72 h / 1-month stages pre-built

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Spain NIS2 readiness file · excerptSample data
Applicability (directive)
confirmed · projected essential, energy sector
Current regime
RD 43/2021 · obligations maintained and evidenced
Legislative tracking
anteproyecto since 14 Jan 2025 · CJEU action 8 Jul 2026
Controls evidenced
69/84 · 15 open, each with an owner and a date
Export
sealed · sha256:2d8f...9a4c

Where teams usually start

With a demo walked through by TruSecure — your projected scope under the directive, your continuing RD 43/2021 obligations credited and evidenced, and the Spanish bill tracked as a dated fact so the compliance plan moves when the BOE does. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Spain by INCIBE-CERT (private) + CCN-CERT (public/defence) under RD 43/2021 — transposition pending. TruSecure determines applicability against Spain's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Do private companies in Spain report to INCIBE or CCN?
Private-sector entities generally report to INCIBE; public-sector and defence-adjacent entities to CCN — Spain's dual-track structure means TruSecure's applicability engine routes your entity to the correct authority based on sector, not just size.