Published on August 4, 2026 · The mitza.es team

The EU's NIS2 directive was supposed to be transposed into Spanish law before October 17, 2024. As of 2026, Spain's law on cybersecurity coordination and governance is still working its way through parliament, even though the Council of Ministers already approved the draft bill in January 2025. The law not being published in the official gazette doesn't mean the underlying obligations don't exist — they stem directly from the EU directive, in force since December 2022.
A recent reminder of why this matters
In January 2026, Endesa confirmed a cyberattack on its commercial platform that exposed customer personal data: names, national ID numbers, contact details, contract information and bank account numbers. The company itself told some customers that around 3 million users could have been affected, mainly in the regulated market, although sources tied to the attacker put the figure as high as 20 million records. Spain's national cybersecurity institute, INCIBE, confirmed the public warning. No company, large or small, is exempt from this kind of risk.
Who NIS2 actually applies to
The directive primarily targets companies with more than 50 employees or more than €10 million in revenue in sectors considered essential or important. But the real scope is broader than it looks: if you're a supplier to one of those entities, or if your activity is considered critical to the supply chain of a client that is obligated, you can be pulled in as well.
What Article 21 actually requires
- Documented risk analysis and management.
- An incident management plan and a notification protocol.
- Business continuity measures and backups.
- Supply chain security (suppliers and subcontractors).
- Encryption and access control.
- Multi-factor authentication where applicable.
Why it's not worth waiting for the law to be published
The underlying obligations have been in force at EU level since 2022. Waiting for the final text of the Spanish law before applying basic measures just means arriving late once the rule is formally in force — while also leaving the company exposed in the meantime to incidents like the one at Endesa.
Where to start if you're not sure it applies to you
- Check whether your company, or your main clients, fall under essential or important sectors per the directive.
- Do a basic inventory of where your data lives and who has access to it.
- Check whether you have backups that are actually tested, not just scheduled.
- Review whether access to critical systems requires multi-factor authentication.
- Define a minimum incident response protocol, even a simple one.
From theory to concrete measures
You don't need an in-house security team to start covering the essentials. An initial review and a prioritized plan can eliminate a large share of the real risk. If you want to know where to start, our IT maintenance service includes a basic security review, and for a more complete assessment you can request a tailored audit.