Cybersecurity Lawyer in Spain | NIS2, ENS and DORA

The NIS2 Directive is in force and Spain still has to transpose it. Is your company ready?

We advise tech companies and businesses in critical sectors on compliance with the NIS2 Directive, Spain’s National Security Framework (ENS), DORA and the legal handling of cybersecurity incidents. Digital security is not only technical: it has a key legal dimension.

Request a free initial assessment. We’ll review your cybersecurity obligations, identify gaps and propose an action plan.

No commitment · We reply the same day

    YEARS OF EXPERIENCE

    + 0

    CLIENTS ADVISED

    + 0

    PROJECTS COMPLETED

    + 0

    PRACTICE AREAS

    + 0

    WHAT SETS US APART

    We Connect Technical Security with Legal Compliance

    We reply the same day

    CYBERSECURITY LEGAL SERVICES

    What Does Your Company Need?

    Legal advice on cybersecurity, technology risk management and regulatory compliance for companies in critical and technology sectors.

    We implement compliance programmes for the NIS2 Directive, the DORA Regulation (for the financial sector) and Spain’s National Security Framework (ENS). We design risk management policies, cybersecurity governance and incident notification protocols.

    We assess the cybersecurity risk in your supply chain: contracts with third parties that access critical systems, enforceable security requirements, liability clauses and supplier audit mechanisms.

    We draft cybersecurity clauses for technology contracts: security obligations, service levels (SLAs) linked to availability, liability for breaches, cyber insurance and incident resolution mechanisms.

    We manage the legal response to cybersecurity incidents: notification to the AEPD and the relevant CSIRT, communication with those affected, preservation of evidence, coordination with insurers and defence against possible claims.

    We audit your company’s compliance with the ENS, ISO 27001 and the NIS2 obligations. We identify gaps and design the roadmap to reach conformity.

    SECTORS AND COMPANIES

    Does Your Company Operate in a Regulated Sector?

    We advise companies in the following sectors on cybersecurity.

    SaaS and Platforms

    Large-scale processing of user data

    Fintech

    Financial data and credit scoring

    Digital Health

    Clinical and patient data

    eCommerce and Marketplaces

    Purchase and behavioural data

    Startups and Scaleups

    Scaling with data from day one

    PROCESS AND TIMELINES

    How We Work

    From the first call to compliance, in 4 steps

    1 –

    Initial assessment

    We analyse your company: which cybersecurity rules apply to you (NIS2, ENS, DORA), which measures you already have in place and where the gaps are. Free of charge and with no commitment.

    2 –

    Risk assessment

    We identify specific risks: suppliers without security clauses, no incident notification protocol, no risk assessment and undocumented management-body responsibility.

    3 –

    Compliance plan

    We design the compliance programme: cybersecurity policies, incident management protocol, contract clauses with suppliers, training plan and the required technical documentation.

    4 –

    Ongoing support

    We monitor compliance on an ongoing basis. We update the protocols whenever your systems, suppliers or the regulations change, and we give you legal support with any incident.

    REVIEWS AND RATINGS

    What Our Clients Say

    Reviews from real clients and companies about our cybersecurity and risk management services.

    Dimas Pérez
    1 review
    Marta combines impeccable professionalism with a remarkable ability to explain complex legal concepts in simple terms...
    Roberto Fernandez
    3 reviews
    Impeccable personal attention, availability and human touch. Broad knowledge and experience in the sector. Outstanding at solving problems. 100% recommended...
    Alina
    1 review
    I have no words to express my sincere gratitude. Marta is a very dedicated and empathetic professional. She also works fast...
    Gregorio Gigorro
    1 review
    Thank you so much, Marta, for your invaluable advice. Without your knowledge of NFT technology in the art market, a new and promising field but one exposed to a lot of fraud, I would have got myself into serious trouble. Marta …

    REGULATORY FRAMEWORK

    Cybersecurity Regulation in Spain and the EU

    Directive (EU) 2022/2555, known as NIS2, sets cybersecurity obligations for essential and important entities in critical sectors such as energy, transport, banking, health and digital infrastructure. Although Spain is still processing its transposition through the draft Law on the Coordination and Governance of Cybersecurity, the directive has been in force since January 2023 and the transposition deadline expired on 17 October 2024.

    Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS), regulated by Royal Decree 311/2022, sets the security principles and requirements for the Spanish public sector and for the companies that provide it with technology services. The DORA Regulation (EU 2022/2554) imposes digital operational resilience obligations on the financial sector.

    Fines for breaching NIS2 can reach EUR 10 million or 2% of turnover for essential entities. NIS2 also makes management bodies directly responsible for overseeing cybersecurity measures.

    If your company manufactures, imports or distributes products with digital elements, Regulation (EU) 2024/2847, the Cyber Resilience Act, also applies to you: since 11 September 2026 it requires actively exploited vulnerabilities to be reported within 24 hours. We support you in adapting to the Cyber Resilience Act.

    FAQ

    Frequently Asked Questions on Cybersecurity and Legal Compliance

    NIS2 is the EU cybersecurity directive that sets obligations for essential and important entities in sectors such as energy, transport, banking, health, digital infrastructure, postal services and waste management. It affects medium-sized and large companies in these sectors, and also their critical technology suppliers through the supply chain.

    Not directly, yet. A directive is binding on Member States, which must transpose it, and the obligations for companies will come with the Spanish law, whose draft was approved by the Council of Ministers on 14 January 2025. The transposition deadline expired on 17 October 2024, and on 8 July 2026 the European Commission decided to refer Spain to the Court of Justice of the EU over the delay. Preparing now avoids having to implement in weeks measures that take months.

    Regulation (EU) 2022/2554 on digital operational resilience (DORA) sets specific cybersecurity obligations for the financial sector: banks, insurers, investment firms and their technology providers. It has applied since January 2025 and includes requirements on ICT risk management, incident reporting and resilience testing.

    NIS2 provides that management bodies are responsible for approving and overseeing cybersecurity measures. Non-compliance can lead to personal liability for directors, including temporary bans from management functions and financial penalties.

    Activate the incident response protocol, contain the threat, preserve evidence, notify the relevant CSIRT and, if personal data is affected, notify the AEPD within 72 hours at most. Your lawyer handles the legal response: communication with those affected, coordination with insurers and defence against possible claims.

    The ENS is mandatory for the public sector and for companies that provide technology services to it or process public-sector data. If your company develops software, manages infrastructure or processes data for public administrations, you need to obtain ENS certification or bring your systems into line with it.

    REQUEST YOUR ASSESSMENT

    Request a free initial assessment and receive a diagnosis of your cybersecurity obligations, the gaps detected and a clear action plan.