The Cybersecurity Law, ready for its approval in the Council of Ministers

The text was examined on Thursday by the CGSEYS and everything points to the Government sending it to Congress this week.

3 minutes

ilustraciones temas 7

ilustraciones temas 7

Add DEMÓCRATA to Google

Ask FREN

Published

3 minutes

Most read

The Cybersecurity Coordination and Governance Law is ready for approval by the Council of Ministers.

The regulation, which transposes the European Directive 2022/2555, commonly known as NIS2 Directive, arrived last week at the General Commission of Secretaries of State and Undersecretaries (CGSEYS) and all signs point to it being sent to Congress this week.

According to government sources reported to DEMÓCRATA, the text was hand-delivered for examination by this body prior to the deliberation of matters in the Council of Ministers.

Spain has accumulated significant work in transposing the aforementioned directive: it should have already been integrated into the Spanish legal system before October 2024.

What does the directive establish?

It does not dictate precise technical measures but does foresee clear legal obligations for the entities required by the regulation to strengthen their cybersecurity.

Thus, the affected organizations must assess and mitigate security risks of their networks and systems, establish controls and strategies, and have documented procedures for this risk management.

The entities must appoint information security officers and will be required to notify significant incidents to the competent authority.

The draft bill presented by the Government in January 2025 proposed the creation of a National Cybersecurity Center with authority over the entire system, attached to the Cabinet of the Presidency of the Government. This entity would assume the direction and coordination of the entire system and would be responsible for managing major cybersecurity crises.

Who does it affect?

The NIS2 would apply to all public and private entities that have their tax residence in Spain (or in any other member state) and carry out their activities in our country. It does not affect all companies, but it does affect a large majority of them, specifically those classified in sectors considered critical for the normal functioning of the country:

  • Energy (electricity, gas, oil, hydrogen).
  • Transport (air, rail, maritime, roads).
  • Banking and financial markets
  • Health and pharmaceutical products.
  • Drinking water and wastewater.
  • Digital infrastructures and technological services (for example, data centers or DNS services).
  • Public administration entities and the space sector.
  • Nuclear industry.

Likewise, it will require compliance from other less critical sectors, such as postal and messaging services, waste management, food production, processing, and distribution; digital service providers; scientific research and private security.

In general, NIS2 applies to entities that are medium or large companies, that is to say:

  • More than 50 employees.
  • More than 10 million in annual turnover (or balance).

It does not include micro and small enterprises (fewer than 50 employees and lower turnover) except for exceptions, when their activity is critical or they are sole providers of essential services.

The responsibility of senior management

Another of the most sensitive issues will be the determination of the responsibility of senior management. The Government established in the draft law the provision that, although the responsibility for the infringement initially falls on the essential or important entity, the members of its management bodies would be jointly liable for the infringements committed by the entity

Fines of up to 10 million or 2% of total turnover

The draft presented more than a year and a half ago also contemplated significant penalties: between 500,001 to 2 million euros in the case of very serious violations; from 100,001 to 500,000 euros for serious violations, and from 10,000 to 100,000 euros for minor violations.

But, for certain very serious breaches of an essential entity, the penalty could reach 10 million euros or 2% of the global annual turnover, applying the higher figure.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What is the current parliamentary status of the Coordination and Governance of Cybersecurity Law and what are the next steps for its definitive approval?

As of September 21, 2026, the Coordination and Governance of Cybersecurity Law is still not in parliamentary processing phase in the General Courts. The initiative is in the governmental phase as a draft bill, having passed several consultation stages and agreements of the Council of Ministers, but it has not yet been sent to the Congress as a bill.

1. Current status of the text

From the available official and journalistic information, the following can be inferred:

  • The Council of Ministers approved the draft Coordination and Governance of Cybersecurity Law on January 14, 2025, at the joint proposal of Interior, Defense, and Digital Transformation. The Ministry of the Interior details this in its press release: Ministry of the Interior note .
  • Since that initial approval, the text has undergone prior public consultation and a specific public hearing and information on the draft, managed by the Ministry of the Interior and also notified in the European Commission's TRIS system. That is, it has had an intense path in the participation and administrative coordination phase.
  • According to various subsequent references (including Order PJC/522/2025, of May 23, on the National Cybersecurity Strategy, published in the BOE: text in BOE), the NIS‑2 Directive is being transposed precisely through this draft, which is mentioned as “in processing” at the governmental level, but not as a law already sent to the Courts.
  • Analytical articles from Demócrata in 2025 and 2026 (“The labyrinth of the Cybersecurity Law…”, “The war in Iran catches Spain with the outdated Cybersecurity Law”) indicate that the draft was still with the Council of State or in the reporting phase, criticizing the delay in its elevation to a bill and the absence of registration in Congress.

Therefore, it is not recorded that it has yet been approved as a bill in the second round of the Council of Ministers nor that it has been officially registered in Congress (something we do see, for example, in the law on critical entities or the law on artificial intelligence governance).

2. What remains before parliamentary processing begins

While it remains a draft, the pending steps within the Government are:

  • Completion of mandatory reports and opinions (other affected ministries, Treasury, National Security Council, Bank of Spain, Spanish Data Protection Agency, among others, as detailed by Interior).
  • Issuance and deliberation of the Council of State's opinion, which is one of the key legal filters.
  • Second round in the Council of Ministers, in which the Government approves the final text as a bill and agrees to send it to the General Courts.
  • Sending and registration in the Congress of Deputies, which is the milestone marking the formal start of parliamentary processing.
3. Expected parliamentary processing once it reaches the Courts

Once the Government sends the Coordination and Governance of Cybersecurity bill to Congress, the standard itinerary will be that of any ordinary bill (unless urgency is granted or special procedures are agreed):

  • Qualification by the Congress Board and publication of the text in the Official Bulletin of the General Courts.
  • Opening of the amendment period to the articles (and, if applicable, total amendments). This period is usually 15 days, although it is common for it to be extended several times.
  • Referral of the bill to the competent committee (likely Interior, National Security, or Economy and Digital Transformation, depending on the distribution agreed by the Board).
  • Appointment of a working group that will draft a report incorporating or rejecting partial amendments, on which the committee will later decide.
  • Committee report, which may approve the text with full legislative competence or elevate it to the Plenary for debate and final vote in Congress.
  • Once approved by Congress, the text is sent to the Senate, where another amendment period opens and it can be approved, amended, or vetoed.
  • If the Senate introduces amendments or issues a veto, the text returns to Congress, which has the final say: it can lift the veto by majority and accept or reject the Senate's amendments.
  • Finally, royal sanction, promulgation, and publication in the BOE take place, after which the law comes into force on the date it establishes or, failing that, 20 days after its publication.

In summary, as of today, the Coordination and Governance of Cybersecurity Law remains in the phase prior to sending to Parliament. Until the Council of Ministers approves it as a bill and it is registered in Congress, amendment periods will not open nor will parliamentary processing properly begin.

What are the competencies of the Council of Ministers regarding the approval of laws and how does it relate to the processing of European directives?

The Council of Ministers is the central Government body that concentrates governmental legislative initiative and the exercise of regulatory power. Regarding laws, it does not replace the General Courts, but it does decide which bills are sent to Parliament, when to resort to royal decree-laws, and how legislative delegations are exercised, in addition to approving much of the regulations that transpose European directives.

1. Basic constitutional and legal framework

The Constitution, in its articles 82 to 88 and 97, and Law 50/1997, on the Government, establish this distribution:

  • The Government directs internal and external policy and exercises executive function and regulatory power (art. 97 CE).
  • The Government's legislative initiative is exercised through bills, which must be approved by the Council of Ministers and sent to the Courts (art. 88 CE and art. 5 of the Government Law, according to Law 50/1997).
  • In cases of extraordinary and urgent necessity, the Government may issue royal decree-laws (art. 86 CE), which the Congress must later validate or repeal.
  • By express delegation from the Courts, the Government may issue royal legislative decrees (art. 82 CE), including consolidated texts.

Law 50/1997 specifies that, as a collegiate body, the Council of Ministers is responsible, among other functions, for approving bills and sending them to Congress, as well as approving royal decree-laws and royal legislative decrees (art. 5.1 a), b) and c), according to the legislative base extract).

2. Competencies of the Council of Ministers in law approval

a) Bills

According to explanatory notes from La Moncloa about “Bills: what they are and how they are prepared”, the cycle is:

  • The competent ministry prepares a draft bill, with reports (regulatory impact, budgetary, gender, etc.).
  • Public consultations, reports, and opinions (Council of State, other bodies) are gathered.
  • The draft is submitted to the Council of Ministers, which may:
    • Approve it as a draft “in the first round,” ordering further procedures.
    • Or, once completed, approve it as a bill and send it to the Courts.

As Demócrata also reminds in “From the Council of Ministers to the BOE”, approval in the Council of Ministers does not make the norm a law: it only authorizes its submission to Congress, where parliamentary processing begins.

b) Royal decree-laws

The Moncloa note “Royal decree-law, royal legislative decree and bill: what they are and how they differ” details that:

  • The Council of Ministers approves the royal decree-law in cases of extraordinary and urgent necessity.
  • It comes into force immediately after its publication in the BOE.
  • It must be submitted to Congress within 30 days for validation or repeal; the Senate does not intervene.
  • Congress may decide to process it later as a bill, allowing amendments.

c) Royal legislative decrees and consolidated texts

The Courts, through a framework law or an ordinary delegation law, authorize the Government to issue norms with the force of law (art. 82 CE). Based on Moncloa's explanation:

  • The Government prepares the royal legislative decree within the limits of the delegation.
  • The text is submitted to the Council of Ministers, which approves it definitively.
  • No subsequent parliamentary validation is required, because the Courts' intervention already occurred in the delegation law.

d) Regulations and other provisions

Law 50/1997 assigns the Council of Ministers the approval of regulatory royal decrees and agreements with normative content. These are the typical instruments to develop laws and, especially, to transpose directives when regulatory rank suffices.

3. Relationship with the processing of European directives

EU directives set mandatory objectives but leave each State the choice of form and means to achieve them. The European Parliament Office in Spain recalls that a very relevant part of Spanish legislative production derives from European norms: in 2024, 46% of the laws approved originated from EU directives or decisions, and the Council of Ministers also approved about twenty regulatory norms transposing directives (note from the EP Office).

In practice, the relationship between the Council of Ministers and European directives is structured as follows:

  • The Government incorporates in its Annual Regulatory Plan the initiatives necessary to transpose directives; many of them reach the Council as draft bills or royal decrees, as highlighted by several Demócrata pieces on the regulatory plan and sectoral bills.
  • When the directive requires the rank of law, the Council of Ministers approves the draft and then the bill that adapts domestic law, and sends it to the Courts. This happens, for example, with bills on maritime fishing or digital services that “adapt Spanish legislation to European regulations.”
  • When a regulation suffices, the Council of Ministers can transpose through royal decrees or other provisions without passing a new law, as reflected in the data of the “other 20 regulations approved by the Council of Ministers in 2024” to transpose directives.
  • The Ministry of the Presidency exercises a “regulatory quality” control over these texts, verifying, as Demócrata explains, that no excesses occur in transposition beyond what the directive provides.

Additionally, the European Commission monitors delays in transposition and can open infringement procedures when the Government does not approve the necessary laws or regulations on time, something both the Commission itself and Demócrata frequently document. Thus, the Council of Ministers is the entry point for much of European law into the Spanish legal system, either by generating bills that the Courts will convert into norms or by directly approving transposition regulations.

What legal requirements must Member States meet to transpose Directive NIS2 and what are the consequences of not doing so on time?

Directive (EU) 2022/2555, known as Directive NIS2, is a minimum harmonization directive that strengthens cybersecurity in the EU. As a directive, it is not directly applicable like a regulation: Member States must transpose it into their internal legal systems, in principle no later than October 17, 2024, the deadline set by NIS2 itself to adopt and publish the necessary provisions, which must be applied from October 18, 2024.

1. Basic legal requirements for transposition

Legally, transposition requires that the Member State adopt internal norms (laws, decrees, or other valid instruments according to its Constitution) that:

  • Reproduce the mandatory content of Directive NIS2, ensuring that its objectives are achieved with clarity, precision, and legal certainty for the addressees (companies, administrations, critical operators, etc.).
  • Identify the covered entities, distinguishing between:
    • Essential entities (e.g., energy, transport, health, digital infrastructures, drinking and wastewater, banking, public critical infrastructures).
    • Important entities (other digital service providers, R&D, postal and courier services, waste collection, manufacturing of certain critical products, etc.).
    The State must set criteria and procedures to identify and notify these entities.
  • Establish cybersecurity risk management obligations for these entities, including:
    • Technical and organizational measures proportionate to the risk (security governance, access control policies, encryption, business continuity, testing and audits, etc.).
    • Integration of risk management in governing bodies, with explicit responsibilities and possible personal sanctions in case of serious non-compliance.
  • Regulate significant incident notification procedures:
    • Early notification (within 24 hours) to the competent authority or CSIRT.
    • More detailed subsequent reports (e.g., within 72 hours and at the closure of incident management).
  • Designate at least:
    • A competent authority or more, responsible for supervision and enforcement.
    • A national CSIRT with defined functions (incident management, early warning, support to affected entities).
    • A single point of contact for cooperation with other States and with the Commission/ENISA.
  • Create an effective, proportionate, and dissuasive sanctioning regime, including:
    • Maximum administrative fines at least equivalent to the levels provided in NIS2 (e.g., higher thresholds for essential entities than for important ones).
    • Corrective measures: remediation orders, mandatory audits, temporary activity restrictions in extreme cases.
  • Establish supervision mechanisms (inspections, information requests, audits) and administrative cooperation with other Member States and EU bodies, integrating into the cooperation frameworks established by NIS2.

All this must be done respecting the principle of equivalence and effectiveness: national measures cannot empty the Directive's objectives of content nor make it practically more difficult to exercise the rights derived from it.

2. Consequences of not transposing NIS2 on time

If a Member State does not transpose NIS2 correctly and within the deadline, several important legal consequences arise:

  • EU infringement procedure: the European Commission may initiate proceedings against the Member State for failure to fulfill its obligations (Articles 258 et seq. TFEU).
    • First, a formal notice (letter of formal notice) and, if insufficient correction, a reasoned opinion.
    • If non-compliance persists, the Commission may bring the State before the EU Court of Justice (CJEU).
  • Fines and financial sanctions: the CJEU may impose:
    • A lump sum for the delay in transposition.
    • A daily penalty payment until correct transposition.
    These sanctions are set considering the severity, duration of non-compliance, and the State's economic capacity.
  • State liability towards individuals (Francovich doctrine):
    • If the lack or incorrect transposition causes damage to individuals or companies (e.g., due to absence of minimum cybersecurity obligations or supervision mechanisms), they could claim compensation from the State.
    • For this, the CJEU's requirements must be met: the directive confers rights on individuals, the content of those rights is identifiable, and there is a causal link between State non-compliance and the damage.
  • Application of vertical direct effect of certain clear provisions:
    • Once the transposition deadline has passed, individuals may invoke before national courts the NIS2 provisions that are sufficiently clear, precise, and unconditional, against the State or public entities.
    • This may force administrative and judicial bodies to directly apply parts of NIS2 against the administration, even if there is no specific national norm.
  • Legal uncertainty and practical risks:
    • Affected companies and entities lack a clear national framework on obligations, sanctions, and competent authorities, generating uncertainty and possible interpretative conflicts.
    • Cross-border cooperation in cybersecurity is hindered, weakening the overall protection level in the EU.

In summary, Member States must adapt their legislation to fully and coherently incorporate NIS2 obligations, including entity identification, technical and organizational obligations, incident notification, competent authorities, and sanctioning regime. Failure to meet the deadline exposes the State not only to EU infringement procedures and fines but also to liability towards individuals and increasing pressure from operators who need regulatory certainty in cybersecurity.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

Which body will be responsible for the direction and coordination of the national cybersecurity system according to the draft law?

Question 1 of 3

What is the maximum penalty provided for certain very serious breaches by an essential entity according to the draft law?

Question 2 of 3

Which entities are generally excluded from the application of NIS2 except for exceptions?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?