Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management Measures
Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Proposed: draft date not recorded.
Approved by the executive for transmission to the legislature, dated 14 January 2025, as of 12 September 2026.
A sector security regimes rule binding public and private bodies.
As of 12 September 2026.
Where it has got to
The text described here is Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad text approved by the Consejo de Ministros for the audiencia e informacion publica consultation, published 14 January 2025.
Locally, this stage is approval of the Anteproyecto de Ley by the Consejo de Ministros in its first round (primera vuelta), with tramitacion de urgencia (urgent processing) ordered so a second-round approval and remission to the Cortes Generales as a Proyecto de Ley can follow.
The stage above is recorded at www.interior.gob.es.
Spain notified this same text to the European Commission on 21 February 2025 under Directive (EU) 2015/1535 (TRIS notification 2025/0104/ES). No later Consejo de Ministros second-round approval or Boletin Oficial de las Cortes Generales entry was located as of September 2026; unofficial trackers describe the bill as still moving through the legislative procedure with no text yet published in the Boletin Oficial del Estado.
What it requires
- This duty does not yet bind: as of September 2026 the Consejo de Ministros has approved only the Anteproyecto de Ley in its first round (14 January 2025) and ordered urgent processing; the text has not been approved in a second round or introduced as a Proyecto de Ley before the Cortes Generales.
- Once enacted, it will reach your service where you are classified as an essential or important entity under the future Act's sector criteria, which track NIS2's own classification of an online marketplace, online search engine and cloud computing service among the digital providers it names; the wider sector classes the Anteproyecto also reaches (energy, transport, banking, health, water, digital infrastructure, public administration and others) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Expect a duty, once enacted, to carry out an individualised risk assessment and put in place technical, operational and organisational measures, proportionate to the risk, to secure the networks and information systems you use and to prevent or minimise the impact of an incident.
- Expect a duty to designate a responsable de la seguridad de la informacion (information security officer) as point of contact and technical coordinator, with an accredited-personnel requirement where your entity is classified as essential.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Anteproyecto's own Capitulo VII (arts. 35 to 44) would create an administrative infringement and sanction regime classifying infractions as muy graves, graves or leves, with no criminal offence created by an infringement of this duty.
Who enforces it
Enforcement body
One of the sector control authorities the Anteproyecto would designate: the Ministerio del Interior through the Oficina de Coordinacion de Ciberseguridad, the Ministerio de Defensa through the Centro Criptologico Nacional, and the Ministerio para la Transformacion Digital y de la Funcion Publica through its Secretaria de Estado de Telecomunicaciones e Infraestructuras Digitales y de Digitalizacion e Inteligencia Artificial, coordinated by the proposed Centro Nacional de Ciberseguridad as single national competent authority.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.dsn.gob.es/en/node/24160
- Guidance body
- Departamento de Seguridad Nacional (DSN), Presidencia del Gobierno
- Open questions
- Will the Anteproyecto's sector list, penalty tiers and information-security-officer regime survive unchanged through the pending second-round Consejo de Ministros approval and the Cortes Generales' debate, given the European Commission's continuing infringement pressure over Spain's overdue NIS2 transposition?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Anteproyecto, jointly proposed by the Interior, Defence and Digital Transformation ministries, would require an entity classified as essential or important under the future Act's sector list to carry out an individualised risk assessment and put in place technical, operational and organisational measures to secure the networks and information systems it uses and to prevent or minimise the impact of an incident, transposing NIS2 Article 21.
It would create the figure of the responsable de la seguridad de la informacion (information security officer) as the entity's point of contact and technical coordinator, with an accredited-personnel requirement for an essential entity's officer, and would create a single national competent authority, the Centro Nacional de Ciberseguridad attached to the Presidency of Government, alongside sector control authorities at the Interior, Defence and Digital Transformation ministries.
This duty does not yet bind: the Consejo de Ministros approved only the Anteproyecto's first round on 14 January 2025 and ordered urgent processing for a second round and parliamentary debate to follow, and no later approval or introduction as a Proyecto de Ley before the Cortes Generales was located as of September 2026.
When LexLint raises it
operates_social_platform
Read the law
Anteproyecto de Ley (draft bill text)
Ministerio del Interior, published for the audiencia e informacion publica consultation following the 14 January 2025 Consejo de Ministros approval not yet introduced as a Proyecto de Ley