The Cybersecurity Coordination and Governance Law is ready for approval by the Council of Ministers.
The regulation, which transposes the European Directive 2022/2555, commonly known as NIS2 Directive, arrived last week at the General Commission of Secretaries of State and Undersecretaries (CGSEYS) and all signs point to it being sent to Congress this week.
According to government sources reported to DEMÓCRATA, the text was hand-delivered for examination by this body prior to the deliberation of matters in the Council of Ministers.
Spain has accumulated significant work in transposing the aforementioned directive: it should have already been integrated into the Spanish legal system before October 2024.
What does the directive establish?
It does not dictate precise technical measures but does foresee clear legal obligations for the entities required by the regulation to strengthen their cybersecurity.
Thus, the affected organizations must assess and mitigate security risks of their networks and systems, establish controls and strategies, and have documented procedures for this risk management.
The entities must appoint information security officers and will be required to notify significant incidents to the competent authority.
The draft bill presented by the Government in January 2025 proposed the creation of a National Cybersecurity Center with authority over the entire system, attached to the Cabinet of the Presidency of the Government. This entity would assume the direction and coordination of the entire system and would be responsible for managing major cybersecurity crises.
Who does it affect?
The NIS2 would apply to all public and private entities that have their tax residence in Spain (or in any other member state) and carry out their activities in our country. It does not affect all companies, but it does affect a large majority of them, specifically those classified in sectors considered critical for the normal functioning of the country:
- Energy (electricity, gas, oil, hydrogen).
- Transport (air, rail, maritime, roads).
- Banking and financial markets
- Health and pharmaceutical products.
- Drinking water and wastewater.
- Digital infrastructures and technological services (for example, data centers or DNS services).
- Public administration entities and the space sector.
- Nuclear industry.
Likewise, it will require compliance from other less critical sectors, such as postal and messaging services, waste management, food production, processing, and distribution; digital service providers; scientific research and private security.
In general, NIS2 applies to entities that are medium or large companies, that is to say:
- More than 50 employees.
- More than 10 million in annual turnover (or balance).
It does not include micro and small enterprises (fewer than 50 employees and lower turnover) except for exceptions, when their activity is critical or they are sole providers of essential services.
The responsibility of senior management
Another of the most sensitive issues will be the determination of the responsibility of senior management. The Government established in the draft law the provision that, although the responsibility for the infringement initially falls on the essential or important entity, the members of its management bodies would be jointly liable for the infringements committed by the entity
Fines of up to 10 million or 2% of total turnover
The draft presented more than a year and a half ago also contemplated significant penalties: between 500,001 to 2 million euros in the case of very serious violations; from 100,001 to 500,000 euros for serious violations, and from 10,000 to 100,000 euros for minor violations.
But, for certain very serious breaches of an essential entity, the penalty could reach 10 million euros or 2% of the global annual turnover, applying the higher figure.