Skip to main content

NIS2 in Spain: Early election delays law again, but companies should not wait

The calling of a general election for 29 November 2026 has suspended the legislative process for the law intended to transpose the NIS2 directive. Spain is already almost two years behind schedule, and the European Commission has referred Spain to the Court of Justice of the EU.

CybersecuritySeintec team3 min read
NIS2 in Spain: Early election delays law again, but companies should not wait

News summary

According to Red Seguridad, bringing forward the general election to 29 November 2026 halts the legislative process for pending cybersecurity laws, including the one intended to transpose the NIS2 directive. The European deadline for transposition expired on 17 October 2024.

The draft Cybersecurity Coordination and Governance Bill was approved by the Council of Ministers on 14 January 2025 but has not yet been published in the BOE. The European Commission referred Spain to the Court of Justice of the EU on 8 July 2026 for failing to complete the transposition.

The absence of a national law does not mean NIS2 has no effect. The obligations are already established: risk management, incident reporting within 24 and 72 hours, and direct liability for senior management. Many large companies are already passing these requirements on to their suppliers through questionnaires and contractual clauses.

For a Spanish SME, the practical consequence is that the legislative delay provides some leeway, not an exemption. Businesses supplying essential or important sectors will likely have to demonstrate specific measures before a Spanish regulation is in force.

Source: Red Seguridad — 9 October 2026

Frequently Asked Questions

Is NIS2 already mandatory for Spanish companies?
The Spanish law to transpose it is not yet in force. However, the directive sets out clear obligations, and many clients are already contractually requiring them from their suppliers.
What will happen to the law after the election?
The legislative process is suspended following the dissolution of Parliament. The new Government and Parliament will need to resume work on the bill, and there is currently no known date.

Concepts mentioned in this article: Cybersecurity

Preparing for NIS2 doesn't depend on the political calendar. At Seintec, we help you organise risks, procedures, and evidence to meet your clients' requirements. Speak with our team.

Contact Seintec

Related service

Cybersecurity compliance and governance

Technical guidance to prepare your infrastructure for NIS2, ENS, ISO 27001, or your customers' requirements.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.