Directive (EU) 2022/2555, known as NIS2, sets cybersecurity obligations for essential and important entities in critical sectors such as energy, transport, banking, health and digital infrastructure. Although Spain is still processing its transposition through the draft Law on the Coordination and Governance of Cybersecurity, the directive has been in force since January 2023 and the transposition deadline expired on 17 October 2024.
Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS), regulated by Royal Decree 311/2022, sets the security principles and requirements for the Spanish public sector and for the companies that provide it with technology services. The DORA Regulation (EU 2022/2554) imposes digital operational resilience obligations on the financial sector.
Fines for breaching NIS2 can reach EUR 10 million or 2% of turnover for essential entities. NIS2 also makes management bodies directly responsible for overseeing cybersecurity measures.
If your company manufactures, imports or distributes products with digital elements, Regulation (EU) 2024/2847, the Cyber Resilience Act, also applies to you: since 11 September 2026 it requires actively exploited vulnerabilities to be reported within 24 hours. We support you in adapting to the Cyber Resilience Act.