The NIS2 Directive is the European cybersecurity legislation that replaces the 2016 NIS Directive and considerably widens who is bound by it and what they must do. Spain was required to transpose it by 17 October 2024 and, as at 16 September 2026, the law transposing it has still not been published in the BOE (Boletín Oficial del Estado, the official state gazette). That does not mean it has no effect yet on those who work with the public sector: tender specifications already cite it, security officers already use it to demand assurances from their suppliers, and the European Commission is pressing the Spanish Government to pass it. This guide explains what NIS2 in Spain means today, which obligations it will pass on to the public sector’s software suppliers, how it differs from the National Security Framework (Esquema Nacional de Seguridad, ENS) and what is worth doing now.

Where transposition stands as at 16 September 2026

  • Directive (EU) 2022/2555 (NIS2): in force since January 2023, with a transposition deadline of 17 October 2024.
  • Draft Bill on Cybersecurity Coordination and Governance (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad): approved by the Council of Ministers (the Spanish cabinet) on 14 January 2025. It creates the National Cybersecurity Centre (Centro Nacional de Ciberseguridad) as the national authority, divides supervision between the ministries of the Interior, Defence (through the National Cryptologic Centre, CCN) and Digital Transformation, and keeps the ENS as the security framework for the public sector.
  • Infringement procedure: the Commission sent Spain a reasoned opinion on 7 May 2025 and, on 19 May 2026, took the next step, demanding transposition as a matter of urgency.
  • Partial transposition: Royal Decree-Law 7/2025 (Real Decreto-ley 7/2025) brought in some NIS2 measures for the electricity system. The rest is still waiting for the law.

It is therefore advisable to write “pending transposition” in any document that cites NIS2 in Spain, and to review the tender specifications or the contract once the law is published. What is certain is the substance, because the directive sets a minimum standard and the Spanish law cannot go below it.

Who NIS2 binds and why it reaches suppliers

The directive applies to essential and important entities in the sectors listed in its annexes: energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration (central government mandatorily, regional and local government as each Member State decides), space, postal services, waste, chemicals, food, manufacturing, digital providers and research. Size matters: as a general rule, medium-sized and large companies in those sectors, with exceptions for critical services regardless of size.

A custom software supplier is not, simply by virtue of being one, covered by the annexes. NIS2 reaches it by two routes:

  1. Directly, if it provides managed ICT services or managed security services, if it is a digital provider of one of the listed types, or if it exceeds the size threshold in a sector that is covered.
  2. Indirectly, through its clients, which is the usual case. Article 21 obliges essential and important entities to manage the risks in their supply chain, including suppliers of software and ICT services. For a public authority bound by the directive, that translates into contract clauses: security requirements, audit rights, incident notification to the client, secure development, vulnerability management and continuity.

In other words: however long the Spanish law takes, every public body that already knows it is an essential entity will pass these requirements on in its tender specifications, and some are already doing so.

The substantive obligations the directive passes on

There are ten measures in Article 21 that an entity bound by the directive must apply, and that it will end up requiring of its suppliers:

  1. Policies on risk analysis and information system security.
  2. Incident handling.
  3. Business continuity: backups, disaster recovery and crisis management.
  4. Supply chain security, including the relationship with each supplier.
  5. Security in the acquisition, development and maintenance of systems, including vulnerability handling and disclosure.
  6. Assessment of the effectiveness of the measures.
  7. Basic cyber hygiene and training.
  8. Cryptography and encryption.
  9. Human resources security, access control and asset management.
  10. Multi-factor authentication and secure communications.

On top of these come notification of significant incidents in three stages (an early warning within 24 hours, an incident notification within 72 hours and a final report within one month), the accountability of management bodies, which must approve the measures and undergo training, and a penalty regime with fines of up to €10 million or 2% of worldwide turnover for essential entities and of up to €7 million or 1.4% for important ones.

NIS2 and the ENS: different and complementary

This is the most common confusion in tender specifications, so it is worth separating the two:

National Security Framework (ENS)NIS2
NatureRoyal Decree 311/2022 (Real Decreto 311/2022), in force and enforceable todayEuropean directive, awaiting a transposing law in Spain
Who it bindsThe public sector and its suppliers, for the systems that serve the public sectorEssential and important entities in the annex sectors, both public and private
What it setsA catalogue of specific measures by category (basic, medium, high) and a certification system with a conformity markObligations on risk management, incident notification, supply chain and management accountability; the specific measures are left to standards and guidance
How compliance is demonstratedDeclaration or certification of conformity by an accredited body, renewed every two yearsSupervision by the national authority; no certificate of its own, although national rules may rely on existing schemes
RelationshipThe Spanish draft bill keeps the ENS as the security framework for the public sectorNIS2 adds governance, notification and supply chain obligations on top of the ENS

For a public sector supplier the practical consequence is clear: the ENS is today’s requirement and will remain so; NIS2 will add, through contracts, incident notification and secure development obligations that a well-built management system already covers. We explain the ENS in what the ENS is and why your supplier must have it and how to check that a certificate is valid in expired ENS certificates: how to check your supplier’s.

What a public sector supplier should be doing now

Without waiting for the BOE, because tender specifications are already asking for it:

  1. Keep its ENS conformity current in the category that corresponds to the systems it provides, with the conformity mark published and verifiable.
  2. A security management system that covers the ten measures of Article 21. ISO 27001 is the natural route and most of its controls map onto them; we explain it in how to implement ISO 27001 step by step.
  3. A procedure for notifying incidents to the client within the directive’s deadlines, even if the contract does not yet require them, and with a security point of contact.
  4. Documented secure development: code review, dependency management, security testing, vulnerability management and a coordinated disclosure policy.
  5. Its own supply chain: an inventory of suppliers and third-party components, with their assurances.
  6. Management involvement: approval of the measures, training and assigned responsibility.
  7. Clauses ready to respond to what tender specifications will ask for: audit rights, notification, continuity, subcontracting and exit.

These requirements do not favour large integrators over mid-sized companies: they favour whoever has them documented and certified. We compare the two in large integrator or mid-sized company.

What a public authority bound by NIS2 should do

  • Determine whether it is an essential or important entity under the Spanish law once it is published, and in the meantime assume that central government is.
  • Draw up an inventory of software and ICT service suppliers and classify them by criticality.
  • Build supply chain clauses into tender specifications: current ENS conformity, incident notification, secure development, audit, continuity and exit. Our guide on how to prepare technical specifications with ENS requirements is a good starting point.
  • Prepare the internal procedure for notification within 24 hours, 72 hours and one month, and training for the management body.

Frequently asked questions about NIS2 in Spain

Is NIS2 in force in Spain?

The directive is in force in the European Union, but Spain has not published the law that transposes it. The Draft Bill on Cybersecurity Coordination and Governance was approved on 14 January 2025 and, as at 16 September 2026, is not in the BOE, with an infringement procedure opened by the European Commission. In the meantime, entities are already passing its requirements on in their contracts.

Does NIS2 replace the ENS?

No. The ENS, governed by Royal Decree 311/2022, remains mandatory for the public sector and its suppliers, and the Spanish draft bill keeps it as the public sector’s security framework. NIS2 adds obligations on governance, incident notification, supply chain and management accountability that sit on top of the ENS.

Is a custom software company bound by NIS2?

Directly, only if it provides managed ICT or managed security services, is a digital provider of one of the listed types or exceeds the size threshold in a sector that is covered. Indirectly, almost always: those of its clients that are bound by the directive must manage the security of their supply chain, and they do so through contract clauses.

What incident notification deadlines does NIS2 set?

An early warning within 24 hours of becoming aware of the significant incident, a full notification within 72 hours and a final report within one month. Entities bound by the directive will pass on matching deadlines to their suppliers so that they can meet them.

What penalties does NIS2 provide for?

Fines of up to €10 million or 2% of worldwide annual turnover for essential entities, and of up to €7 million or 1.4% for important ones, in addition to the liability of management bodies. The specific amounts in Spain will be set by the transposing law.

Conclusion

NIS2 in Spain is a pending law whose content is already known: risk management, incident notification, supply chain security and management accountability, on top of an ENS that remains today’s requirement. For a public sector supplier, preparing means having current ENS conformity, a certified management system, and documented notification and secure development procedures before the tender specifications ask for them. If you are looking for a supplier that already works this way, write to us via our contact page.