Home · Radar · NIS2 in Spain

Regulation · NIS2 in Spain

Spain is late on NIS2 (and why you shouldn't wait for the law)

The EU cybersecurity directive was meant to become Spanish law in October 2024. By mid-2026 it still isn't. Here's where things stand — and why the companies ahead of the curve aren't waiting for the official gazette.

14 July 2026 · 4 min read · Sources below

Before the detail, the floor we start from: protecting your company's data is not optional. The GDPR already requires every company handling data to have security measures in place (art. 32). That is already cybersecurity. NIS2 is a layer added on top depending on your sector, your size and your clients.

1.The EU deadline passed in October 2024 — and Spain missed it

The NIS2 directive set 17 October 2024 as the deadline for each country to turn it into national law. Spain didn't, and is now over eighteen months late.

In plain terms: The directive is already in force at EU level. What's missing is the Spanish law that lands it — not the underlying obligation, which already exists.

2.The law has existed in draft since January 2025 — but it's still in the pipeline

In January 2025 the Council of Ministers approved the draft Cybersecurity Coordination and Governance Act, the law transposing NIS2. It creates the National Cybersecurity Centre as the authority and will coexist with the ENS. By mid-2026 it still hasn't been published in the official gazette.

In plain terms: The expectation is that, once published, it will take effect almost immediately and without a long grace period. Starting the day it lands is starting late.

3.Brussels is already pushing

With no progress, the European Commission has taken formal steps against Spain for late transposition. The next rung is the Court of Justice of the EU, with possible fines for the State.

In plain terms: Political pressure speeds up the timeline. When the law lands, it will land in a hurry and in the press — exactly when everyone wants to catch up at once.

4.Large companies already apply it — and pass it down to you

Many large companies and multinationals already comply with NIS2 under the EU directive, without waiting for the Spanish law. And through the cascade effect, they require it from their suppliers by contract.

In plain terms: Even if the law doesn't bind you directly yet, your regulated clients can already ask for it. That's where the delay stops protecting you: it hits you first commercially, not legally.

What actually changes

The legal delay doesn't change the substance: attacks are rising, clients already audit and the rule is coming. Waiting for the gazette to start is the most expensive way to do it — you'll have to rush, with everyone rushing at once.

Does NIS2 apply to you (or will they require it)?

Take the free check-up —2 minutes, no sign-up, we don't even ask for your email— and you'll know which regulations affect you and where to start.

Take the free check-up

Sources: Directive (EU) 2022/2555 (NIS2); draft Cybersecurity Coordination and Governance Act (Council of Ministers, January 2025); European Commission transposition tracking. Status and dates as of July 2026; the process may change. We don't include specific fine amounts as they depend on the final text of the law.