Experienced an incident?
Dasenda
Get an assessment
CareersPress kit
Part ofDordio & Associates

© 2026 Dasenda

Spain is late with NIS2. Start planning anyway.

On 8 July the European Commission referred Spain to the Court of Justice for failing to transpose NIS2. It is running late, as usual, and that could bring the requirements forward.

All insights
Compliance1 September 2026
Spain is late with NIS2. Start planning anyway.
Jaime Dordio

Author

Jaime Dordio

LinkedIn

On 8 July the European Commission referred Spain to the Court of Justice of the EU for failing to transpose the NIS2 Directive. The deadline ran out in October 2024.

Spain is late. As usual.

That surprises nobody who has been around this a while, and it is no cause for alarm. But the law not being published does not mean there is nothing to do.

The delay is not a grace period

For one thing, much of the obligation is already arriving through another door. Article 21.2(d) of NIS2 requires affected entities to secure the relationship with their direct suppliers, and your Italian, German or Belgian client has been subject to it since 2024. Plenty of Spanish companies have already been asked for this by a client, not by a regulator.

For another, the referral to the Court comes with a request for a daily penalty payment until Spain notifies transposition. A state with that meter running could speed up implementation without granting generous adaptation periods.

The rush is what overwhelms

NIS2 is ten families of measures, plus board-level governance and incident notification deadlines.

Spread over a year, implementing all of that is manageable, but compressed into the quarter after the law is published it turns into a budget all at once, with no prioritisation to allow sustained adoption. What matters most is when you start, not your size or your budget.

A plan that does not compress everything

You do not need to wait for the law to draw one up. In order, it is three phases:

  • Work out whether you are in scope and what you are missing. Eighteen sectors across Annexes I and II, with medium-sized enterprise as the general threshold.
  • The common foundation: asset inventory, access control, backups, a tested incident response procedure and third-party management. It is the same core that ISO 27001, NIS2 and the ENS share, so the work counts three times. And with it, the evidence that those measures work, which is what point (f) of Article 21.2 asks for and what most often gets left out.

Once there is a law, move ahead with registration as an essential or important entity, the formal notification procedure and whatever specific adjustments the Spanish text brings.

Next step

Want to map out the plan before the rush?

We review whether you fall within the scope of NIS2 and the order in which to tackle it, without having to implement everything at once.

Get started