Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers
Real Decreto-ley 12/2018 de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 9 September 2018.
A sector security regimes rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds an operator of essential services designated under Ley 8/2011's critical-infrastructure regime and a digital service provider that is an online marketplace, online search engine or cloud computing service established in Spain, with its EU main establishment in Spain, or that has designated a Spain-based EU representative; a digital service provider that is a micro or small enterprise under Commission Recommendation 2003/361/EC is exempt, and so is an electronic-communications or trust-service operator not separately designated a critical operator.
- Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards.
- If designated an operator of essential services, designate a responsable de la seguridad de la informacion within three months of your designation, notify the competent authority of the appointment, and file a Declaracion de Aplicabilidad of the security measures you apply within six months of designation, reviewing it at least every three years.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Titulo VII (arts. 35 to 42) creates an administrative infringement and fine regime rather than a criminal offence; article 28.6 separately preserves the ordinary duty to report facts that may constitute a crime to the criminal-justice authorities under the Ley de Enjuiciamiento Criminal, independent of this Real Decreto-ley's own notification duty.
Penalty structure
Article 37 tiers the fine to the infraction's classification under article 36: a muy grave infraction (including a failure to remedy a security deficiency that left the operator vulnerable to a significantly disruptive incident) draws a fine of EUR 500,001 to 1,000,000; a grave infraction draws EUR 100,001 to 500,000; a leve infraction draws a warning or a fine of up to EUR 100,000. The figure recorded here as fixed_cap is the top of the muy grave tier; the schema has no separate field for the lower tiers, which this note carries.
- Rule
- Fixed only
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 1,000,000
Who enforces it
Enforcement body
The competent authority varies by sector: the Secretaria de Estado de Seguridad (Ministerio del Interior, through the Centro Nacional de Proteccion de Infraestructuras y Ciberseguridad) for most designated critical operators of essential services, the Secretaria de Estado de Digitalizacion e Inteligencia Artificial (Ministerio de Asuntos Economicos y Transformacion Digital) for digital service providers, and the Centro Criptologico Nacional (Ministerio de Defensa) for public-sector operators and digital service providers within the scope of Ley 40/2015.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.dsn.gob.es/en/node/24160
- Guidance body
- Departamento de Seguridad Nacional (DSN), Presidencia del Gobierno
- Open questions
- Will Real Decreto-ley 12/2018 and Real Decreto 43/2021 be repealed outright once the Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad is enacted, or will parts of Real Decreto 43/2021's operational detail (the security-officer designation, the Declaracion de Aplicabilidad, the notification instruction) be carried forward under the new Act's implementing regulations?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 16 requires an operator of essential services (an undertaking designated in the energy, transport, banking, financial-market-infrastructure, health, drinking-water or digital-infrastructure sectors under Ley 8/2011's critical-infrastructure regime) and a digital service provider under this Real Decreto-ley to adopt technical and organisational measures, proportionate to the risk, to manage the risks to the networks and information systems used to provide the service, even where that management is outsourced.
A digital service provider must additionally address, at minimum, the security of its systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with international standards.
Real Decreto 43/2021 develops this duty: an operator of essential services must designate a responsable de la seguridad de la informacion within three months of its designation and file a Declaracion de Aplicabilidad of the security measures it applies with the competent authority within six months, reviewed at least every three years.
This transposes the original NIS Directive (Directive (EU) 2016/1148) and, according to the Departamento de Seguridad Nacional, remains in full effect and covers the most critical operators within the State pending the NIS2 transposition described on this jurisdiction's Anteproyecto rows.
When LexLint raises it
operates_social_platform
Read the law
BOE, consolidated text (ELI address), Real Decreto-ley 12/2018