NISDESK · ES
NIS2 Compliance in Spain
Spanish entities across 18 sectors assess NIS2 scope with INCIBE (private) or CCN (public); dual CSIRT structure streamlines sector-specific incident response.
Are you in scope?
NIS2 covers medium and large organisations in 18 sectors. Fines reach €10M or 2% of global turnover. Check your scope, obligations and a readiness score for free.
Get the free NIS2 checklist for Spain
Free PDF delivered to your inbox. No spam — unsubscribe anytime.
National authority & CSIRT
In Spain, NIS2 supervision is handled by INCIBE / CCN (Centro Criptológico Nacional). The national CSIRT is INCIBE-CERT / CCN-CERT. Significant incidents must be reported within 24 h (early warning), 72 h (notification) and one month (final report) per NIS2 Article 23.
NIS2 sectors in Spain
Each sector has specific obligations. Explore them for Spain:
Frequently asked questions
Which sectors are covered by NIS2 in Spain?
NIS2 covers 18 sectors: Annex I (highly critical — energy, transport, banking, financial markets, health, water, digital infrastructure, ICT service management, public administration, space) and Annex II (other critical — postal services, waste management, chemicals, food, manufacturing, digital providers, research). Transposed via Royal Decree-Law 2023; INCIBE covers private-sector entities and CCN covers public-sector entities.
Who supervises NIS2 compliance in Spain?
In Spain, the primary competent authority is INCIBE / CCN (Centro Criptológico Nacional). The national CSIRT is INCIBE-CERT / CCN-CERT, which handles significant incident notifications and cybersecurity coordination.
What are the NIS2 incident reporting deadlines in Spain?
Organisations must submit an early warning to INCIBE-CERT / CCN-CERT within 24 hours of a significant incident, a formal notification within 72 hours, and a final report within one month — per NIS2 Article 23.
What are the NIS2 fines in Spain?
Essential entities face fines up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4% of global annual turnover. Exact enforcement varies by national transposition.
Official sources
- NIS2 Directive (EU) 2022/2555 — EUR-Lex
- DORA Regulation (EU) 2022/2554 — EUR-Lex
- ENISA — EU Agency for Cybersecurity
Last reviewed: 2026-07-03
For decision-support purposes only. Exact scope depends on national transposition — use our free scope checker for a personalised assessment.