Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, Incident Reporting Obligations
Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Proposed: draft date not recorded.
Approved by the executive for transmission to the legislature, dated 14 January 2025, as of 12 September 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
Where it has got to
The text described here is Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad text approved by the Consejo de Ministros for the audiencia e informacion publica consultation, published 14 January 2025.
Locally, this stage is approval of the Anteproyecto de Ley by the Consejo de Ministros in its first round (primera vuelta), with tramitacion de urgencia (urgent processing) ordered so a second-round approval and remission to the Cortes Generales as a Proyecto de Ley can follow.
The stage above is recorded at www.interior.gob.es.
Spain notified this same text to the European Commission on 21 February 2025 under Directive (EU) 2015/1535 (TRIS notification 2025/0104/ES). No later Consejo de Ministros second-round approval or Boletin Oficial de las Cortes Generales entry was located as of September 2026.
What it requires
- This duty does not yet bind: as of September 2026 the Consejo de Ministros has approved only the Anteproyecto de Ley in its first round (14 January 2025) and ordered urgent processing; the text has not been approved in a second round or introduced as a Proyecto de Ley before the Cortes Generales.
- Once enacted, it will reach your service where you are classified as an essential or important entity under the future Act's sector criteria; the wider sector classes it also reaches are not raised here for the reason given on this jurisdiction's companion risk-management row.
- Expect a duty, once enacted, to notify the competent authority of a significant incident affecting the provision of your service, whether on your own networks or a third-party provider's.
- Expect a duty to communicate to the recipients of your service, as soon as possible, a significant cyberthreat that could affect them and any mitigating measures they can take.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Anteproyecto's own Capitulo VII (arts. 35 to 44) would create an administrative infringement and sanction regime classifying infractions as muy graves, graves or leves, with no criminal offence created by an infringement of this duty.
Who enforces it
Enforcement body
One of the sector control authorities the Anteproyecto would designate: the Ministerio del Interior through the Oficina de Coordinacion de Ciberseguridad, the Ministerio de Defensa through the Centro Criptologico Nacional, and the Ministerio para la Transformacion Digital y de la Funcion Publica; the Centro Nacional de Ciberseguridad would coordinate incident response nationally.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.dsn.gob.es/en/node/24160
- Guidance body
- Departamento de Seguridad Nacional (DSN), Presidencia del Gobierno
- Open questions
- Will the Anteproyecto's incident-notification clock and thresholds, once enacted, replace Real Decreto 43/2021's severity-tiered national instruction, or will the existing instruction continue in a modified form under the new Act?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Anteproyecto would require an essential or important entity to notify a significant incident affecting the provision of its service, on its own networks or a third party's, to the competent authority, and to communicate to the recipients of its service, as soon as possible, a significant cyberthreat that could affect them along with any mitigating measures available to them, mirroring NIS2 Article 23.
The information security officer the Anteproyecto would create manages an entity's cybersecurity incidents as one of its named functions. This duty does not yet bind: the Consejo de Ministros approved only the Anteproyecto's first round on 14 January 2025 and ordered urgent processing for a second round and parliamentary debate to follow, and no later approval or introduction as a Proyecto de Ley before the Cortes Generales was located as of September 2026.
When LexLint raises it
operates_social_platform
Read the law
Anteproyecto de Ley (draft bill text)
Ministerio del Interior, published for the audiencia e informacion publica consultation following the 14 January 2025 Consejo de Ministros approval not yet introduced as a Proyecto de Ley