ITER/ESSpain
What the record establishes for Spain: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Agencia Española de Protección de Datos reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | INCIBE-CERT, the CSIRT of reference for the private sector under Real Decreto-ley 12/2018 reported | Under the earlier act, the Plataforma Nacional de Notificación y Seguimiento de Ciberincidentes, run by the CCN-CERT with INCIBE-CERT and ESPDEF-CERT under article 11 of Real Decreto 43/2021. No NIS2 recipient is designated, and the platform is recorded as the existing regime's channel and not as discharging the NIS2 duty | es rd 43 2021 · incibe faq nis2 |
| Financial supervisorDORA, article 19 | Banco de España reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Comisión Nacional del Mercado de Valores (CNMV) reported | — | esma mar nca |
Transposition of NIS2 unresolved
| Act | Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad. A draft, approved by the Council of Ministers on 14 January 2025 and not published in the Boletín Oficial del Estado when this was read |
|---|---|
| In force | not in force |
| Recipient | not recorded, see Divergence |
| Moves a term | No. None found in the terms. The FAQ gives the Directive's three stages, «una alerta temprana en las primeras 24 h», «antes de 72 h ... una notificación del incidente», «informe final, a más tardar un mes después de presentar la notificación del incidente», all «desde el conocimiento del mismo». The divergence is elsewhere: the page does not say who receives them. «Tanto los CSIRT de referencia y las autoridades competentes como el punto de contacto único se conocerán con la trasposición de la norma a la legislación española.» |
| Standing | An organization in Spain therefore holds the terms and not the recipient. What exists is the regime that transposed the first Directive: Real Decreto-ley 12/2018 and Real Decreto 43/2021, whose article 11 has the CCN-CERT, with INCIBE-CERT and ESPDEF-CERT, run the «Plataforma Nacional de Notificación y Seguimiento de Ciberincidentes». That platform is the channel for operators of essential services under the earlier act, with its own deadlines by severity, and it is recorded in the authorities table as that and not as the NIS2 duty. This record leaves the NIS2 recipient unwritten rather than naming a body the source does not name |
| Source | incibe faq nis2 · dsn anteproyecto ciberseguridad · es rd 43 2021 |
An event in Spain
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
