{"id":38551,"date":"2024-09-30T13:07:35","date_gmt":"2024-09-30T13:07:35","guid":{"rendered":"https:\/\/metachannelcorp.com\/nis2-directive-transposition-spain-status\/"},"modified":"2026-08-03T11:35:52","modified_gmt":"2026-08-03T11:35:52","slug":"nis2-directive-transposition-spain-status","status":"publish","type":"post","link":"https:\/\/metachannelcorp.com\/en\/perspectives\/nis2-directive-transposition-spain-status\/","title":{"rendered":"Transposition of the NIS2 Directive in Spain: Current Status, Legislative Process and Regulatory Challenges"},"content":{"rendered":"<p><strong>1. Introduction and context<\/strong><br \/>\nCybersecurity has become central to the stability of critical infrastructure and data protection in Europe. In this context, the NIS2 Directive, formally known as Directive (EU) 2022\/2555 of the European Parliament and of the Council, updates the NIS1 Directive (Directive 2016\/1148) with the aim of improving the resilience and security of the networks and information systems of the Member States. This update arises in response to the increasing complexity and frequency of cyber threats that impact essential sectors for the European economy and society.<\/p>\n<p>The NIS2 Directive was formally adopted in December 2022 and entered into force in January 2023, with a maximum transposition period for Member States until October 17, 2024 and its effective application from October 18, 2024.<\/p>\n<p>We are going to analyze the status of the transposition of this Directive in Spain, the existing regulatory framework and the legislative procedure to follow to guarantee its correct implementation.<\/p>\n<p><strong>2. Pre-existing legal framework in Spain:<\/strong><br \/>\nBefore the NIS2 Directive, Spain already had a cybersecurity regulatory framework adapted to the NIS1 Directive:<\/p>\n<p>** Royal Decree-Law 12\/2018, of September 7: Transposed the NIS1 Directive into Spanish legislation, establishing a set of cybersecurity measures for essential service operators and digital service providers. RDL 12\/2018 defined the categories of services and security and incident notification obligations.<\/p>\n<p>** Royal Decree 311\/2022, of May 3: Regulates the National Security Scheme (ENS), an instrument that harmonizes the minimum security requirements in the public sector and which, in many aspects, was already aligned with the new requirements of the NIS2. The ENS is mandatory for all public sector entities and the suppliers that provide services to said entities.<\/p>\n<p><strong>Why did the NIS1 Directive and the ENS coexist?<\/strong><br \/>\nThe ENS was created before the NIS1 Directive with the objective of unifying and standardizing security measures for Spanish public sector entities. Its existence responds to the need for Public Administrations to maintain a minimum level of cybersecurity and information protection. Therefore, although the NIS1 Directive focused on essential service operators and digital service providers, the ENS exclusively covered public sector entities and their suppliers.<\/p>\n<p>When NIS1 was implemented in 2018, it was necessary to create a specific framework to cover essential private operators that were not subject to the ENS. In this way, the obligations of the NIS1 Directive and the ENS coexisted, but applied to different subjects. With the arrival of the NIS2, the ENS is being updated to harmonize its requirements and extend its reach to private entities in critical sectors, eliminating part of this segmentation.<\/p>\n<p>The pre-existing framework, therefore, lays the foundations for the incorporation of the NIS2, which expands and redefines the categories of entities subject to the regulations and establishes more rigorous security obligations, as well as a stricter sanctioning regime.<\/p>\n<p><strong>3. Objectives and scope of the NIS2 Directive:<\/strong><br \/>\nThe NIS2 aims to create a high common level of cybersecurity in the European Union. To do this, it is structured around the following principles:<\/p>\n<p>Expansion of the scope of application: Includes new sectors considered highly critical (energy, transportation, healthcare, digital infrastructure) and critically important (waste management, chemical and food manufacturing).<\/p>\n<p>Classification of entities into essential and important: Based on the criticality of the sector and the size of the entity. Security and notification obligations are stricter for essential entities.<\/p>\n<p>Strengthened obligations: Introduces more demanding obligations regarding risk management, governance and resilience. Specific requirements are established for supply chain security and crisis management.<\/p>\n<p>More severe sanctioning regime: Sanctions for non-compliance can reach up to \u20ac10 million or 2% of annual turnover for essential entities, and \u20ac7 million or 1.4% of annual turnover for important entities.<\/p>\n<p><strong>4. Transposition process of the NIS2 Directive in Spain:<\/strong><br \/>\nThe transposition of the NIS2 Directive in Spain is being carried out through a Royal Decree-Law, which will allow the Government to comply with the deadline imposed by the EU (October 17, 2024). The use of the RDL is justified due to the extraordinary and urgent need to adapt the regulations in a timely manner to avoid sanctions by the European Commission and guarantee the security of critical infrastructures.<\/p>\n<p>The Royal Decree-Law (RDL): Allows the immediate entry into force of the NIS2 measures, but requires ratification by Parliament within a period of 30 days. This legislative tool is used to comply with the European calendar, ensuring formal transposition in time, but does not imply the definitive approval of the text as law.<\/p>\n<p>Debate and approval by the Cortes Generales: Once ratified, the RDL will be the subject of a complete parliamentary debate to become a definitive Law, at which time adjustments and modifications may be introduced according to the considerations of the parliamentary groups and social agents affected. This process allows for greater participation and transparency, although it subjects the content of the RDL to possible modifications.<\/p>\n<p><strong>5. Current status of the transposition:<\/strong><br \/>\nCurrently, the transposition of the NIS2 Directive is in an advanced phase, with the drafting of the Royal Decree-Law almost complete and its approval expected in the Council of Ministers before the deadline (October 17, 2024). According to unofficial sources and the analysis of the regulatory framework, the main modifications are expected to focus on:<\/p>\n<p>Update of cybersecurity requirements for the public and private sector.<\/p>\n<p>Expansion of ENS coverage to include new sectors and important entities according to the NIS2 classification.<\/p>\n<p>Coordination between authorities: The National Cryptological Center (CCN), together with the Ministry of Economic Affairs and Digital Transformation, will be responsible for supervising compliance with the regulations and coordinating with the corresponding CSIRTs (Computer Security Incident Response Teams).<\/p>\n<p><strong>6. Potential problems and challenges of transposition:<\/strong><br \/>\nParliamentary approval: Although the RDL guarantees the entry into force of the obligations of the NIS2, the lack of parliamentary consensus could delay the final approval of the law, generating regulatory uncertainty.<\/p>\n<p>Adaptation of affected entities: Entities that were not previously subject to NIS1 (for example, waste management services and food manufacturing) will need to quickly adapt to the new requirements.<\/p>\n<p>Effective implementation of the sanctioning regime: Ensuring that sanctions are proportionate and effective will require strong coordination between regulatory bodies and competent authorities.<\/p>\n<p>This analysis aims to offer a comprehensive vision of the current situation and the implementation process of the NIS2 Directive in the Spanish legislative context.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction and context Cybersecurity has become central to the stability of critical infrastructure and data protection in Europe. In&#8230;<\/p>\n","protected":false},"author":12,"featured_media":32658,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[1845],"tags":[],"class_list":["post-38551","post","type-post","status-publish","format-standard","has-post-thumbnail","category-regulation-and-compliance"],"menu_order":0,"_links":{"self":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/comments?post=38551"}],"version-history":[{"count":1,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38551\/revisions"}],"predecessor-version":[{"id":39031,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38551\/revisions\/39031"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media\/32658"}],"wp:attachment":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media?parent=38551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/categories?post=38551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/tags?post=38551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}