What is happening in Spain with the NIS2 Directive?

Feb 10, 2026 | Strategy

Read the original in Spanish →

What is happening in Spain with the NIS2 Directive?

The country that boasted of cybersecurity and cannot pass its own law

There is something deeply ironic about the current situation. Spain occupies “Tier 1” in the ITU Global Cybersecurity Index. We are, on paper, a power in this matter. We have talent, leading companies and organizations with international prestige such as the CCN-CERT. And yet, we are unable to approve the law that Europe requires of us from October 2024.

The NIS2 Directive is not a bureaucratic whim of Brussels. It is the legal shield that requires protecting hospitals, electrical networks, water and transportation systems against increasingly sophisticated cyber attacks. All the countries around us already apply it. Germany, Portugal, France. We continue arguing who is in charge.

Three wars in a single law

The blockage of the NIS2 in Spain does not have a single cause. It is a “perfect storm” with three fronts open simultaneously, and none has to do with cybersecurity itself.

1. The war for the “red button”

The Government has decided to create a new National Cybersecurity Center (CNC) reporting directly to Moncloa. The movement has strategic logic, but it has displaced the actors who historically controlled this terrain: the CNI (through the CCN-CERT) and the Ministry of the Interior (through the CNPIC).

The reading is clear: we move from cybersecurity managed by the military and spies to one piloted by civilian technocrats under presidential command. The appointment of Ariel Waissbein, an academic and technical profile, as a key figure of the CNC symbolizes that changing of the guard. A change that has not exactly been peaceful. For months in 2024, the drafts of the preliminary project bounced between ministries with cross-corrections that delayed the process until it became unviable.

2. Parliamentary blackmail: cybersecurity as a bargaining chip

When the text reached Congress, it ran into parliamentary arithmetic. PNV and Junts have identified this law as an opportunity to expand powers. They demand that the Ertzaintza and the Mossos have direct access to European alert channels, exclusive capacity to investigate cyber attacks in their territories and “equal to equal” coordination with the State, not subordination.

Junts has threatened to overturn the law if its “red lines” are not accepted. And the ghost of Pegasus contaminates everything: the distrust of the pro-independence parties towards any state cyber intelligence structure turns every article on information exchange into a political battle.

The cybersecurity of 47 million people, hostage to parliamentary arithmetic. It is difficult to find a starker example of how partisan politics can hijack an issue of general interest.

3. The silent lobby of the Ibex 35

This is where you have to follow the money. NIS2 introduces something that terrifies boards of directors: personal and direct responsibility of managers. No more “I didn’t know anything about IT” when a security breach occurs. CEOs may face temporary disqualifications and financial penalties.

The CEOE and AMETIC have been pushing for months to soften this article. Meanwhile, D&O (Director and Executive) insurance premiums are skyrocketing. The delay gives them precious time to protect themselves and negotiate discounts. Every lawless month is another month of “plausible deniability” for the corporate elite.

418 million euros in the air

But there is a figure that could unlock all this at once: 418 million euros. This is what Spain is playing for in NextGenerationEU funds linked to Milestone 245 of the Recovery Plan. The European Commission has already issued a reasoned opinion against Spain – the second formal step before the Court of Justice – and has the power to freeze payments.

Financial pressure is, paradoxically, the best ally of Spanish cybersecurity. When the Treasury sees hundreds of millions in danger, internal resistance tends to evaporate remarkably quickly.

The sector that loses the most: 3,000 million turnover in stand-by

The Spanish cybersecurity industry has a turnover of more than 3,000 million euros annually and employs 180,000 professionals. Companies like Indra, S2 Grupo or GMV see the NIS2 as a historic opportunity: thousands of companies forced to hire audits, managed SOCs and compliance consulting.

But promises don’t pay salaries. Every month of delay means unsigned contracts and frozen projects. And when the law finally comes out, demand will skyrocket, creating a talent bottleneck that could take years to resolve.

When will it be approved?

The most likely scenario involves a powers pact with PNV and Junts: recognizing the regional police forces as “competent authorities” for medium and low level incidents, reserving the management of national crises and dialogue with Europe to the State. A semantic formula to save furniture.

The most optimistic date: May or June 2026. Just before summer, forced by financial pressure from European funds.

The real threat

The most worrying thing about this whole matter is not the fines from Brussels, nor the 418 million at risk, nor even the international ridicule of a “Tier 1” country incapable of passing its own law.

The truly dangerous thing is that, while politicians, spies and lobbyists negotiate in closed offices who is in charge and who pays, Spanish critical infrastructures operate without the legal framework that Europe demands. No obligation to report incidents within 24 hours. Without a dissuasive sanctioning regime. Without a clear single interlocutor.

Cyberattackers are not waiting for Congress to resolve their differences. And in this particular digital game of thrones, the biggest risk for Spain is not losing a parliamentary vote, but rather that the next big digital crisis catches us arguing about who has the authority to pick up the phone.

← Previous Cloud security myths: why default settings do not protect you Next → Enshittification and the pyramid of cuts
← Return to blog Back to top ↑