NIS2 in Spain: Not Transposed, and Now Before the Court of Justice

NIS2 in Spain: Not Transposed, and Now Before the Court of Justice
On 8 July 2026, the European Commission did something it doesn't do often: it referred four EU governments to the Court of Justice over the same directive, on the same day. Ireland, Spain, France and the Netherlands had all missed the deadline to transpose NIS2 into national law. The Commission asked the Court for financial sanctions — a lump sum plus daily penalties — until each country notifies complete transposition.
One of the four has since fixed it. The Netherlands' Cyberbeveiligingswet entered into force on 15 August 2026, a month after the referral landed. Spain has not moved. As of this writing, there is still no NIS2 transposition law in the Boletín Oficial del Estado.
If you advise Spanish organisations, or your clients elsewhere in the EU have Spanish suppliers or subsidiaries, that gap matters. Here's what actually governs cybersecurity obligations in Spain right now, why the gap doesn't mean anyone gets a pass, and what to check today instead of waiting for a law that has been "coming" since January 2025.
Where the 27 Member States Actually Stand
NIS2 was supposed to be law everywhere by 17 October 2024. Almost two years later, the picture is still uneven. Most member states have transposed. A handful haven't, and the reasons differ:
- Netherlands — done. Cyberbeveiligingswet in force since 15 August 2026.
- Austria — done, but phased. The NISG 2026 was published in December 2025; its main obligations only start applying from 1 October 2026.
- Ireland — still legislating. No cybersecurity bill has reached the parliamentary register.
- France — still legislating. A bill has been before the National Assembly since March 2025 with no plenary vote yet.
- Spain — still at draft-bill stage, with no date for parliamentary submission.
Ireland, France and Spain are the three still without a transposition law on the books, and all three are now named in the same CJEU referral.
The other 24 member states have notified transposition measures, several of them years behind the original October 2024 deadline. That matters for anyone running a multi-country compliance programme: "NIS2 applies here" is no longer a single EU-wide date, it's a country-by-country checklist, and Spain currently sits at the bottom of it.
NIS2 Implementation Status by Country (2025–2026)
Fully in force
BelgiumCroatiaHungaryLithuaniaLatviaItaly6 countriesAdopted — late 2025
GermanyCzech RepublicFinland3 countriesIn progress — expected 2026
NetherlandsFranceSpainPolandAustriaSwedenIreland7 countries
What Actually Governs NIS2-Equivalent Cybersecurity in Spain Right Now
No NIS2 law doesn't mean no law. Spanish organisations already sit under several overlapping regimes:
NIS1 is still in force. Real Decreto-ley 12/2018 and its implementing Real Decreto 43/2021 transposed the original NIS Directive, and neither has been repealed. Operators of essential services and digital service providers designated under that regime keep their existing obligations — incident notification, security measures, supervision by their sector regulator.
The Esquema Nacional de Seguridad (ENS) applies to the public sector and to any private supplier processing data or running systems for a public administration. It predates NIS2 but covers similar ground: risk management, incident handling, technical controls.
DORA applies directly to Spanish banks, insurers and other financial entities, because it's an EU regulation rather than a directive — no national transposition step needed.
Incident reporting already has a home. Entities under the existing regime report through their reference CSIRT: INCIBE-CERT for the private sector, CCN-CERT for public administration and classified systems. There is no separate NIS2 registration process in Spain yet, because there's no NIS2 register to register with.
None of this is a substitute for NIS2 — the sector list is narrower, the Article 21 measures are more specific than what RD-ley 12/2018 requires, and the governance duties on management bodies are new. But "Spain hasn't transposed NIS2" and "Spain has no cybersecurity law" are two very different statements, and treating them as the same one is the mistake to avoid in a gap analysis.
The Bill That's Been Waiting Since January 2025
Spain's answer to NIS2 is the Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — the Cybersecurity Coordination and Governance Law. Spain's Council of Ministers approved the draft on 14 January 2025. It's designed to transpose NIS2 and the Critical Entities Resilience (CER) Directive together, in a single instrument.
The bill would create a new Centro Nacional de Ciberseguridad, sitting under the Office of the Presidency, as the single national authority coordinating cybersecurity policy across sectors. INCIBE-CERT and CCN-CERT would keep their operational roles underneath it.
Twenty months on from Council of Ministers approval, the draft still hasn't gone to a parliamentary vote. There's no published date for when it will.
The Commission Just Escalated — What That Actually Changes
We flagged the referral risk back in June; by July it was official. The CJEU referral doesn't fine Spanish companies. It's a state-to-state enforcement mechanism: the Commission asks the Court to impose financial penalties on the Spanish government, not on any organisation operating there. Formal notice went out in November 2024, a reasoned opinion followed in May 2025, and the referral itself came in July 2026 — the standard escalation ladder under EU infringement procedure, now at its final rung before a ruling.
What it signals is pressure, not a new private-sector obligation. Once the Court rules against Spain — and referrals like this rarely go the other way — the clock on daily penalties starts running against the state treasury, which tends to move legislative priorities faster than a strongly worded letter.
NIS2 Penalty Escalation — Beyond the Fine
!Trigger event
Non-Compliance Detected or Incident Occurs
A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements
Authorities can impose▼Non-Monetary Penalties1Compliance orders with binding deadlines
2Mandatory security audits at your expense
3Public disclosure of violations
4Binding instructions on specific security measures
Escalates to▼Operational & Personal Consequences1Suspension of certifications or operating licences
2Temporary ban on management functions for individuals
3Public naming of responsible natural persons
TriggerNon-monetaryOperational / personal
Does the Gap Mean Anyone Gets a Pass?
No. Three groups in particular don't get to wait for the Spanish law:
Anything already covered under NIS1 stays covered. The old obligations don't lapse just because a new directive is stuck in committee.
Suppliers to obligated entities elsewhere in the EU are pulled in through the customer's jurisdiction, not their own. If a Dutch or German essential entity relies on a Spanish supplier, supply chain security puts that risk squarely on the Dutch or German entity's own register — and its due diligence obligations don't pause because the supplier's home country hasn't transposed yet.
Spanish financial entities are already directly bound by DORA, transposition gap or not.
The mistake we see most often is a consultant marking a Spanish entity "not in scope yet" and moving on. That's true only in the narrow sense that Spain has no NIS2 registration duty to fulfil today. It says nothing about whether that entity's biggest customer, three regions over, is already required to vet it as a supplier.
What to Actually Do With a Spanish Client Right Now
Waiting for the Ley de Coordinación y Gobernanza is not a plan — nobody can tell you when it lands. A more useful approach for consultants and MSPs with Spanish clients or Spanish links in a client's supply chain:
Run the gap analysis against the EU Directive's Article 21 measures directly, rather than against a Spanish statute that doesn't exist yet. The ten measures don't change once national law catches up; only the enforcement and registration mechanics do.
Document what's already covered under RD-ley 12/2018, RD 43/2021 or the ENS as your baseline, so the client isn't starting from zero once Spanish law does arrive.
If the client is a supplier into a transposed member state, treat that customer relationship as the actual compliance driver today — not Spain's legislative calendar.
A readiness assessment mapped to the Article 21 measures gives you that baseline in minutes, regardless of which country's transposition clock is running.
The Takeaway
Spain not having a NIS2 law yet is a legislative fact, not a compliance holiday. NIS1 obligations, ENS requirements, DORA and supply chain due diligence from customers in other member states all still apply. The CJEU referral raises the pressure on Madrid to finish the job — it doesn't lower the bar for anyone doing business with Spanish entities in the meantime.
Build the gap analysis around the directive, not the delay, and the client's compliance posture won't need a rewrite the day the Ley de Coordinación y Gobernanza finally clears parliament.
Still have a question?
Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.
