Spain's NIS2 transposition remains at the executive-approval stage.
The Consejo de Ministros approved the Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad in its first round on 14 January 2025 and ordered urgent processing so a second-round approval and formal remission to the Cortes Generales as a Proyecto de Ley can follow; as of September 2026 no second-round approval or Boletin Oficial de las Cortes Generales entry was located, Spain notified the text to the European Commission under the technical-regulations procedure on 21 February 2025, and the Commission sent Spain a reasoned opinion in May 2025 over the overdue transposition of Directive (EU) 2022/2555.
Pending enactment, Real Decreto-ley 12/2018, de 7 de septiembre (transposing the original NIS Directive, Directive (EU) 2016/1148) and its implementing Real Decreto 43/2021, de 26 de enero, remain in full force: they require an operator of essential services and a digital service provider (an online marketplace, online search engine or cloud computing service, with a micro- or small-enterprise exemption for the latter) to adopt proportionate security measures for their networks and information systems and to notify a significant incident to the competent authority through a CSIRT, on a severity-tiered clock that Real Decreto 43/2021's own national incident-notification instruction sets out (an interim notification within 24 to 48 hours and a final report within 20 days for a CRITICAL-severity incident, 72 hours and 40 days for a VERY HIGH-severity incident), rather than the fixed 24-hour and 72-hour clock Directive (EU) 2022/2555 itself sets.
No Spanish instrument imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
The Esquema Nacional de Seguridad (Real Decreto 311/2022) binds the public sector in full and extends to a private-sector entity only when, under a contractual relationship, it provides services to a public-sector entity for that entity's own exercise of its competencies; it does not impose a general private-sector duty and is a Government Accountability matter rather than a finding for this topic.
Both the still-enforced 2018 regime and the pending Anteproyecto bind a wider class of essential and important entity by sector and designation that no activity in this vocabulary expresses; only the digital-provider slice of that class (an online marketplace, online search engine or cloud computing service) is flagged here, and the broader sector classes are recorded as law the lint does not yet reach rather than flagged on a guess.
Spain's breach-notification duty for personal data, General Data Protection Regulation (GDPR) Articles 33 and 34 read with Ley Organica 3/2018 (LOPDGDD) Article 69, sits in the privacy topic and is not restated here.