Alessandro AleddaInsider Threat and Risk

ITER/ESSpain

What the record establishes for Spain: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
None recorded
NIS2
Not in force
Terms moved
No
Sources cited
6
Last read
4 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Agencia Española de Protección de Datos reportededpb members
CSIRT or competent authorityNIS2, article 23INCIBE-CERT, the CSIRT of reference for the private sector under Real Decreto-ley 12/2018 reported

Under the earlier act, the Plataforma Nacional de Notificación y Seguimiento de Ciberincidentes, run by the CCN-CERT with INCIBE-CERT and ESPDEF-CERT under article 11 of Real Decreto 43/2021. No NIS2 recipient is designated, and the platform is recorded as the existing regime's channel and not as discharging the NIS2 duty

es rd 43 2021 · incibe faq nis2
Financial supervisorDORA, article 19Banco de España reportedeba competent authorities
Market authorityMAR, article 17Comisión Nacional del Mercado de Valores (CNMV) reportedesma mar nca

Transposition of NIS2 unresolved

ActAnteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad. A draft, approved by the Council of Ministers on 14 January 2025 and not published in the Boletín Oficial del Estado when this was read
In forcenot in force
Recipientnot recorded, see Divergence
Moves a termNo. None found in the terms. The FAQ gives the Directive's three stages, «una alerta temprana en las primeras 24 h», «antes de 72 h ... una notificación del incidente», «informe final, a más tardar un mes después de presentar la notificación del incidente», all «desde el conocimiento del mismo». The divergence is elsewhere: the page does not say who receives them. «Tanto los CSIRT de referencia y las autoridades competentes como el punto de contacto único se conocerán con la trasposición de la norma a la legislación española.»
StandingAn organization in Spain therefore holds the terms and not the recipient. What exists is the regime that transposed the first Directive: Real Decreto-ley 12/2018 and Real Decreto 43/2021, whose article 11 has the CCN-CERT, with INCIBE-CERT and ESPDEF-CERT, run the «Plataforma Nacional de Notificación y Seguimiento de Ciberincidentes». That platform is the channel for operators of essential services under the earlier act, with its own deadlines by severity, and it is recorded in the authorities table as that and not as the NIS2 duty. This record leaves the NIS2 recipient unwritten rather than naming a body the source does not name
Sourceincibe faq nis2 · dsn anteproyecto ciberseguridad · es rd 43 2021

An event in Spain

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.