{"id":118366,"date":"2024-09-27T05:30:30","date_gmt":"2024-09-27T03:30:30","guid":{"rendered":"https:\/\/ceadigilaw.org\/transposicion-de-la-directiva-nis2-en-espana-estado-actual-proceso-legislativo-y-retos-regulatorios\/"},"modified":"2026-07-17T17:02:21","modified_gmt":"2026-07-17T15:02:21","slug":"transposicion-de-la-directiva-nis2-en-espana-estado-actual-proceso-legislativo-y-retos-regulatorios","status":"publish","type":"post","link":"https:\/\/ceadigilaw.org\/en\/blog\/transposicion-de-la-directiva-nis2-en-espana-estado-actual-proceso-legislativo-y-retos-regulatorios\/","title":{"rendered":"Transposition of the NIS2 Directive in Spain: Current Status, Legislative Process and Regulatory Challenges"},"content":{"rendered":"<p><span style=\"color: #000000\"><strong><a style=\"color: #000000\" href=\"\/staff\/antonio-tejeda-encinas-2\/\" target=\"_blank\" rel=\"noopener\">Antonio Tejeda Encinas<\/a><\/strong> Ph.D EU Law. President Comit\u00e9 Euro Americano de Derecho Digital &#8211;<strong><a style=\"color: #000000\" href=\"\/en\/\" target=\"_blank\" rel=\"noopener\">CEA Digital Law<\/a><\/strong>.  <\/span><span style=\"color: #000000\">European Representative for Latin America in Cybersecurity and Digital Transformation\u201d<\/span><\/p>\n<p><strong><span style=\"color: #000000\">1. Introduction and context<\/span><\/strong><br \/>\n<span style=\"color: #000000\">Cybersecurity has become a central element for the stability of critical infrastructures and data protection in Europe. In this context, the NIS2 Directive, formally known as Directive (EU) 2022\/2555 of the European Parliament and of the Council, updates the NIS1 Directive (Directive 2016\/1148) with the aim of improving the resilience and security of the network and information systems of the Member States. This update arises in response to the growing complexity and frequency of cyber threats affecting sectors essential to the European economy and society.<\/span><\/p>\n<p><span style=\"color: #000000\">The NIS2 Directive was formally adopted in December 2022 and entered into force in January 2023, with a maximum transposition deadline for Member States of October 17, 2024, and its effective application from October 18, 2024.<\/span><\/p>\n<p><span style=\"color: #000000\">We will analyze the status of the transposition of this Directive in Spain, the existing regulatory framework and the legislative procedure to be followed to ensure its correct implementation.<\/span><\/p>\n<p><strong><span style=\"color: #000000\">2. Pre-existing legal framework in Spain:<\/span><\/strong><br \/>\n<span style=\"color: #000000\">Before the NIS2 Directive, Spain already had a cybersecurity regulatory framework adapted to the NIS1 Directive:<\/span><\/p>\n<p><span style=\"color: #000000\">** Royal Decree-Law 12\/2018, of September 7: Transposed the NIS1 Directive into Spanish legislation, establishing a set of cybersecurity measures for operators of essential services and digital service providers. RDL 12\/2018 defined the categories of services and the security and incident notification obligations.<\/span><\/p>\n<p><span style=\"color: #000000\">** Royal Decree 311\/2022, of May 3: Regulates the National Security Scheme (ENS), an instrument that harmonizes the minimum security requirements in the public sector and which, in many respects, was already aligned with the new requirements of NIS2. The ENS is mandatorily applicable to all public sector entities and to the providers that render services to those entities.<\/span><\/p>\n<p><strong><span style=\"color: #000000\">Why did the NIS1 Directive and the ENS coexist?<\/span><\/strong><br \/>\n<span style=\"color: #000000\">The ENS was created before the NIS1 Directive with the aim of unifying and standardizing security measures for Spanish public sector entities. Its existence responds to the need for Public Administrations to maintain a minimum level of cybersecurity and information protection. Therefore, although the NIS1 Directive focused on operators of essential services and digital service providers, the ENS covered exclusively public sector entities and their providers.<\/span><\/p>\n<p><span style=\"color: #000000\">When NIS1 was implemented in 2018, it was necessary to create a specific framework to cover essential private operators that were not subject to the ENS. In this way, the obligations of the NIS1 Directive and the ENS coexisted, but applied to different subjects. With the arrival of NIS2, the ENS is being updated to harmonize its requirements and extend its scope to private entities in critical sectors, eliminating part of this segmentation.<\/span><\/p>\n<p><span style=\"color: #000000\">The pre-existing framework therefore lays the foundations for the incorporation of NIS2, which expands and redefines the categories of entities subject to the regulation and establishes more rigorous security obligations, as well as a stricter sanctioning regime.<\/span><\/p>\n<p><strong><span style=\"color: #000000\">3. Objectives and scope of the NIS2 Directive:<\/span><\/strong><br \/>\n<span style=\"color: #000000\">NIS2 aims to create a high common level of cybersecurity in the European Union. To this end, it is structured around the following principles:<\/span><\/p>\n<p><span style=\"color: #000000\">Expansion of the scope of application: It includes new sectors considered highly critical (energy, transport, healthcare, digital infrastructures) and of critical importance (waste management, chemical and food manufacturing).<\/span><\/p>\n<p><span style=\"color: #000000\">Classification of entities as essential and important: Based on the criticality of the sector and the size of the entity. Security and notification obligations are stricter for essential entities.<\/span><\/p>\n<p><span style=\"color: #000000\">Reinforced obligations: It introduces more demanding obligations regarding risk management, governance and resilience. Specific requirements are established for supply chain security and crisis management.<\/span><\/p>\n<p><span style=\"color: #000000\">A more severe sanctioning regime: Penalties for non-compliance can reach up to 10 million euros or 2% of annual turnover for essential entities, and 7 million euros or 1.4% of annual turnover for important entities.<\/span><\/p>\n<p><strong><span style=\"color: #000000\">4. Process of transposing the NIS2 Directive in Spain:<\/span><\/strong><br \/>\n<span style=\"color: #000000\">The transposition of the NIS2 Directive in Spain is being carried out by means of a Royal Decree-Law, which will allow the Government to meet the deadline imposed by the EU (October 17, 2024). The use of the RDL is justified by the extraordinary and urgent need to adapt the regulations in due time and form, to avoid sanctions from the European Commission and to guarantee the security of critical infrastructures.<\/span><\/p>\n<p><span style=\"color: #000000\">The Royal Decree-Law (RDL): It allows the immediate entry into force of the NIS2 measures, but it must be ratified by Parliament within 30 days. This legislative tool is used to comply with the European timetable, ensuring formal transposition on time, but it does not imply the definitive approval of the text as a law.<\/span><\/p>\n<p><span style=\"color: #000000\">Debate and approval by the Cortes Generales: Once ratified, the RDL will be the subject of a full parliamentary debate to become a definitive Law, at which point adjustments and modifications may be introduced according to the considerations of the parliamentary groups and the social stakeholders affected. This process allows for greater participation and transparency, although it subjects the content of the RDL to possible modifications.<\/span><\/p>\n<p><strong><span style=\"color: #000000\">5. Current status of the transposition:<\/span><\/strong><br \/>\n<span style=\"color: #000000\">Currently, the transposition of the NIS2 Directive is at an advanced stage, with the drafting of the Royal Decree-Law almost complete and its approval scheduled in the Council of Ministers before the deadline (October 17, 2024). According to unofficial sources and the analysis of the regulatory framework, the main modifications are expected to focus on:<\/span><\/p>\n<p><span style=\"color: #000000\">Updating the cybersecurity requirements for the public and private sectors.<\/span><\/p>\n<p><span style=\"color: #000000\">Expanding the coverage of the ENS to include new sectors and important entities according to the NIS2 classification.<\/span><\/p>\n<p><span style=\"color: #000000\">Coordination between authorities: The National Cryptologic Center (CCN), together with the Ministry of Economic Affairs and Digital Transformation, will be in charge of supervising compliance with the regulations and coordinating with the corresponding CSIRTs (Computer Security Incident Response Teams).<\/span><\/p>\n<p><strong><span style=\"color: #000000\">6. Potential problems and challenges of the transposition:<\/span><\/strong><br \/>\n<span style=\"color: #000000\">Parliamentary approval: Although the RDL guarantees the entry into force of the NIS2 obligations, the lack of parliamentary consensus could delay the definitive approval of the law, generating regulatory uncertainty.<\/span><\/p>\n<p><span style=\"color: #000000\">Adaptation of the affected entities: Entities that were not previously subject to NIS1 (for example, waste management services and food manufacturing) will have to adapt quickly to the new requirements.<\/span><\/p>\n<p><span style=\"color: #000000\">Effective implementation of the sanctioning regime: Ensuring that penalties are proportionate and effective will require solid coordination between regulatory bodies and the competent authorities.<\/span><\/p>\n<p><span style=\"color: #000000\">This analysis aims to offer a comprehensive view of the current situation and the implementation process of the NIS2 Directive in the Spanish legislative context.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Antonio Tejeda Encinas Ph.D EU Law. President Comit\u00e9 Euro Americano de Derecho Digital &#8211;CEA Digital Law. European Representative for Latin America in Cybersecurity and Digital Transformation\u201d 1. Introduction and context Cybersecurity has become a central element for the stability of critical infrastructures and data protection in Europe. In this context, the NIS2 Directive, formally known [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":112286,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wds_primary_category":0,"wds_primary_cea_women":0,"footnotes":""},"categories":[1110],"tags":[],"cea_women":[],"class_list":["post-118366","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/comments?post=118366"}],"version-history":[{"count":2,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118366\/revisions"}],"predecessor-version":[{"id":119259,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118366\/revisions\/119259"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media\/112286"}],"wp:attachment":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media?parent=118366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/categories?post=118366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/tags?post=118366"},{"taxonomy":"cea_women","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/cea_women?post=118366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}