Law / Spain

Real Decreto-ley 12/2018, Incident Notification Obligation

Real Decreto-ley 12/2018 de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de enero

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 9 September 2018.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds an operator of essential services and a digital service provider within the scope described on this jurisdiction's companion security-obligations row; a digital service provider's notification duty applies only when it has access to the information needed to assess the incident's impact.
  • Notify the competent authority, through your reference CSIRT, without undue delay, of an incident that may have a significant disruptive effect on the provision of your service, whether on your own networks or a third-party provider's.
  • For a CRITICO-severity incident under the national notification instruction, notify immediately, follow up with an interim notification within 24 to 48 hours, and file a final notification within 20 days; for a MUY ALTO-severity incident, notify immediately, follow up within 72 hours, and file a final notification within 40 days; an ALTO-severity incident requires only an immediate initial notification.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Titulo VII (arts. 35 to 42) creates an administrative infringement and fine regime; a repeated failure to notify an incident with a significant disruptive effect is itself a muy grave infraction under article 36.2.b, but no offence reviewed here is criminal.

Penalty structure

Article 37 tiers the fine to the infraction's classification under article 36, which lists a repeated failure to notify a significantly disruptive incident, and a failure to notify a less severe incident where notification is required, among the muy grave and grave infractions respectively: a muy grave infraction draws a fine of EUR 500,001 to 1,000,000; a grave infraction draws EUR 100,001 to 500,000; a leve infraction draws a warning or a fine of up to EUR 100,000. The figure recorded here as fixed_cap is the top of the muy grave tier; the schema has no separate field for the lower tiers, which this note carries.

Rule
Fixed only
As of
12 September 2026
Currency
EUR
Fixed cap
1,000,000

Who enforces it

Enforcement body

The competent authority varies by sector: the Secretaria de Estado de Seguridad (Ministerio del Interior, through the Centro Nacional de Proteccion de Infraestructuras y Ciberseguridad) for most designated critical operators of essential services, the Secretaria de Estado de Digitalizacion e Inteligencia Artificial (Ministerio de Asuntos Economicos y Transformacion Digital) for digital service providers, and the Centro Criptologico Nacional (Ministerio de Defensa) for public-sector operators and digital service providers within the scope of Ley 40/2015; the CCN-CERT and INCIBE-CERT operate as reference CSIRTs that receive notifications.

Settledness

As of
12 September 2026
Guidance link
https://www.dsn.gob.es/en/node/24160
Guidance body
Departamento de Seguridad Nacional (DSN), Presidencia del Gobierno
Open questions
Will Real Decreto 43/2021's severity-tiered notification clock be replaced by NIS2's own fixed 24-hour and 72-hour clock once the Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad is enacted, or will a Spain-specific clock be carried forward under the new Act's implementing regulations?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 19 requires an operator of essential services to notify the competent authority, through its reference CSIRT, of an incident that may have a significant disruptive effect on its service, and requires a digital service provider to notify an incident with a significant disruptive effect on its service, limited to cases where the provider has access to the information needed to assess the incident's impact.

Article 22 sets an initial notification made without undue delay (sin dilacion indebida), followed by interim and final notifications.

Real Decreto 43/2021's own national incident-notification and management instruction (its Anexo) fixes the clock by severity: for a CRITICO-severity incident, the initial notification is immediate, the interim notification is due within 24 to 48 hours and the final notification within 20 days; for a MUY ALTO-severity incident, the interim notification is due within 72 hours and the final notification within 40 days; an ALTO-severity incident requires only an immediate initial notification, and a MEDIO- or BAJO-severity incident carries no notification duty under the instruction.

This is a looser, severity-gated clock than the fixed 24-hour early warning and 72-hour notification Directive (EU) 2022/2555 itself sets, and it remains, according to official trackers, in full force pending the NIS2 transposition described on this jurisdiction's Anteproyecto rows.

When LexLint raises it

  • operates_social_platform

Read the law

BOE, consolidated text (ELI address), Real Decreto-ley 12/2018

Back to the example  ·  Lint your app