Abstract illustration of cybersecurity network nodes over a high-voltage electricity transmission grid

Spain NIS2 Energy Compliance: Why Red Eléctrica Answers to CNPIC, CNMC, and INCIBE-CERT — Not CCN-CERT

Search “NIS2 Spain energy” and most guides tell you the same three things: Spain missed the transposition deadline, energy is a covered sector, and penalties top out at €10 million. None of them explain why a company the size of Red Eléctrica currently answers to three separate Spanish regulators for cybersecurity — or why Spain is fighting two separate cases at the Court of Justice of the EU, not one.

That gap matters if you’re the one deciding what to build before either law passes. This guide maps Spain’s actual regulatory structure for energy — CNPIC’s critical-infrastructure track, CNMC’s electricity-specific Network Code on Cybersecurity, and the still-pending INCIBE-CERT/NIS2 track — using Red Eléctrica’s own compliance position as the working example, so you can see which parts are legally live today and which are still sitting in draft.

Who This Applies To: Spain’s Energy Entities Under NIS2 Annex I

If your organisation operates in electricity, gas, oil, hydrogen, or district heating in Spain, NIS2 Annex I almost certainly covers you [11]. The open question isn’t whether the Directive applies — it’s whether you’re essential or important, and which regulator you actually answer to.

Entity type Annex I subsector Classification Size test
Electricity TSO (e.g., Red Eléctrica/Redeia) Electricity Essential Effectively size-irrelevant — sole Spanish TSO, near-certain CNPIC critical-operator candidate
Electricity DSOs Electricity Essential Medium+ (≥50 staff or >€10M turnover/balance)
Suppliers, NEMOs, aggregation/demand-response/storage participants Electricity Essential or Important by role Medium+
Gas supply, DSO/TSO, storage, LNG Gas Essential Medium+
Oil transmission, production, refining, storage Oil Essential Medium+
Hydrogen production, storage, transmission Hydrogen (new vs. NIS1) Essential Medium+
District heating & cooling operators District heating/cooling Essential Medium+

Size thresholds don’t apply to entities separately identified as critical entities under the CER Directive — the mechanism behind Red Eléctrica’s own status, covered below.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Spain Still Hasn’t Transposed NIS2 — and It’s Running Two Separate Bills, Not One

Spain missed the 17 October 2024 transposition deadline, and unusually, is now fighting two separate infringement cases at the Court of Justice of the EU, not one — because Spain split its two EU cybersecurity obligations into two bills moving through the Cortes Generales at different speeds.

Track 1 — cyber risk management (NIS2, Directive 2022/2555): the Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad [6], approved by the Council of Ministers on 14 January 2025, still hadn’t reached the Boletín Oficial del Estado as of mid-2026. The Commission escalated to a reasoned opinion on 7 May 2025, then referred Spain to the CJEU on 8 July 2026 alongside Ireland, France, and the Netherlands, seeking a lump sum plus daily penalties [7].

Track 2 — critical-entity resilience (CER, Directive 2022/2557): the Anteproyecto de Ley de Protección y Resiliencia de Entidades Críticas [5], which evolves rather than repeals the existing Ley 8/2011 critical-infrastructure framework. The Commission issued a separate reasoned opinion on this track in July 2025 and referred Spain to the CJEU again around 29 April 2026 — a distinct case from Track 1.

Practically: until one or both laws pass, Spain has no domestic penalty regime, no mandatory domestic notification portal, and no legally confirmed role for the Centro Nacional de Ciberseguridad the draft law proposes to create. What’s already enforceable sits on pre-existing legal ground — Ley 8/2011 critical-operator obligations, and the EU-level Network Code on Cybersecurity for electricity, which entered into force independently of Spain’s transposition timeline. The two-track split also means a single “are we compliant” answer doesn’t exist yet: an energy operator could be well ahead on physical/critical-infrastructure resilience under CNPIC and still have no domestic legal basis for its incident-notification programme, or the reverse.

The Three Regulators an Energy Operator Actually Deals With

No single regulator owns “Spain energy cybersecurity.” A TSO like Red Eléctrica sits at the intersection of all three — a structure that predates NIS2 and will outlast the current transposition delay.

Regulator Legal basis What it covers
CNPIC (Ministerio del Interior) Ley 8/2011, evolving toward CER via the pending Anteproyecto Physical/operational critical-infrastructure protection; designates “critical operators”
CNMC (energy regulator) Commission Delegated Regulation (EU) 2024/1366 [9], Art.4 Cross-border electricity-flow cybersecurity; transitional NCCS competent authority; ran the high-impact/critical-impact entity classification [8] (Resolutions 13 Mar & 30 Apr 2025)
INCIBE-CERT (once the draft law is in force) Draft Ley de Coordinación y Gobernanza de la Ciberseguridad transposing NIS2 Art.21/23 General cyber risk-management measures + incident notification for private-sector essential/important entities

The overlap is the point, not a flaw: CNPIC’s mandate is physical and operational resilience (can the grid survive an attack or disaster), CNMC’s NCCS mandate is electricity-specific cyber risk to cross-border flows, and INCIBE-CERT’s future mandate is general cyber risk management and incident reporting. A single control — network segmentation between corporate IT and SCADA, for instance — can satisfy pieces of all three simultaneously, but no single filing or audit currently covers all three at once.

Red Eléctrica as the Case Study: How a CNPIC Designation Becomes an Automatic NIS2 Essential-Entity Status

Article 3(1) of NIS2 [1] lists entity categories that qualify as essential regardless of size — normally reserved for DNS registries, top-level-domain operators, and public administration. One more category sits in that list: entities identified as critical entities under the CER Directive.

Spain hasn’t transposed CER yet, so no Spanish company holds that formal designation today. But the mechanism is worth understanding now, because it’s about to apply directly to Spain’s electricity backbone. As Spain’s sole electricity TSO managing the national high-voltage grid, Red Eléctrica/Redeia is the textbook case for a CNPIC “critical operator” designation under Ley 8/2011 — Article 13 of that law [4] requires managing at least one infrastructure classed as Critical Infrastructure before CNPIC will designate an operator, and it’s difficult to construct a national high-voltage grid that doesn’t clear that bar. Spain doesn’t publish its critical-operator registry — those designations sit behind national-security protections, the same way France’s OIV list is legally classified — so treat REE’s status here as the standard illustration of how the statutory test applies, not a confirmed public designation. The pending resilience bill is built to carry existing Ley 8/2011 designations forward into the CER framework rather than starting critical-entity identification from zero.

The practical consequence, once both Spanish laws are in force: a TSO’s CNPIC status stops being a purely physical-security compliance track and becomes the legal trigger for automatic essential-entity status under NIS2 Article 3(1)(f) — independent of employee count or turnover. For everyone below TSO scale, size still matters; DSOs, suppliers, and market participants qualify through the ordinary medium-enterprise threshold in Annex I instead.

INCIBE-CERT, Not CCN-CERT: Where Private Energy Operators Actually Report

A recurring mix-up in compliance write-ups: because CCN-CERT sits inside the Centro Criptológico Nacional, which itself reports to the Centro Nacional de Inteligencia (CNI, Spain’s intelligence service), some material shorthands it as “CNI-CERT.” That’s not a separate body — it’s CCN-CERT [10], and it exists specifically for public administrations and classified government systems. Our Spain competent authority breakdown covers the full public/private split in detail.

Red Eléctrica, like every other private-law energy company, is not public administration — so its incident-reporting channel is INCIBE-CERT (operated under the Ministerio para la Transformación Digital), not CCN-CERT. The distinction is operational, not academic: CCN-CERT runs the LUCIA incident-management platform and ENS certification scheme for government ICT; INCIBE-CERT runs the private-sector notification portal. A corporate group with both a private energy subsidiary and a public-sector grid-adjacent entity could genuinely need both channels — a standard energy operator only needs one.

Article 21 Controls, Mapped for OT and Grid Environments

Spain’s own domestic measure set isn’t published yet, so the safest baseline is NIS2’s own text, read for an OT/grid context and cross-checked against the general energy-sector requirements that apply EU-wide.

Measure Article 21(2) Energy-specific note
Risk analysis & policy (a) CNMC’s NCCS high-impact/critical-impact classification effectively pre-scopes your risk tier for cross-border flows
Incident handling (b), Art.23 Dual clock: NIS2’s 24h/72h/1-month cascade to INCIBE-CERT, plus separate NCCS incident-sharing duties for cross-border-relevant events
Business continuity (c) Grid restoration and black-start scenarios sit outside a generic BC template
Supply chain (d) OT/ICS vendor cascade (SCADA/PLC integrators) — same direct-supplier scope as any sector, but energy OT vendor lists are usually incomplete
Acquisition/dev/maintenance, cryptography, access control, MFA (e), (h), (i), (j) IT/OT boundary segmentation is the practical gap most Spanish energy operators haven’t documented yet

The Notification Clock and What Non-Compliance Actually Costs

Once Spain’s transposition law is in force, Article 34 [3] sets the EU floor Spain must meet, not necessarily its final number: essential entities face fines up to €10,000,000 or 2% of worldwide annual turnover, whichever is higher; important entities face up to €7,000,000 or 1.4%, whichever is higher. Our Spain penalties breakdown covers the draft law’s own three-tier domestic structure in detail (a leve/grave/muy grave scale running roughly €10,000 to €2,000,000, with escalation to the EU ceiling for the most severe cases) — treat that scale as draft-stage, not final, until the law reaches the BOE.

The clock that applies once INCIBE-CERT is live, per Article 23 [2]: 24 hours for an early warning, 72 hours for a full notification, and a final report no later than one month after that — with a further month if the incident is still open.

A Compliance Checklist for the Gap Before the Law Passes

Step Effort
Confirm your Annex I category and whether CNMC’s NCCS high-impact/critical-impact classification already applies to you Low
Check whether you, or a group entity, already hold a CNPIC critical-operator designation under Ley 8/2011 Low
Gap-map existing ISO 27001/IEC 62443 controls against NIS2 Article 21(2) — as a general guideline, a mature ISO 27001:2022 programme tends to cover a large share of Article 21’s ten measures, with OT-specific gaps (segmentation, legacy-asset handling) the most common shortfall Medium
Build the INCIBE-CERT reporting workflow now, before the notification duty is legally live — the 24-hour clock won’t wait for your team to learn a new portal Medium
Track both bills separately — passing a Track 1 (cyber) readiness review doesn’t cover Track 2 (CER/CNPIC) obligations, and vice versa Low, ongoing

Frequently Asked Questions

Does NIS2 already apply to Spanish energy companies?
Not as a directly enforceable domestic law — Spain hasn’t transposed the Directive. But EU-level obligations that don’t depend on Spanish transposition, like the Network Code on Cybersecurity for electricity, are already in force, and Spain’s existing Ley 8/2011 critical-infrastructure duties continue to apply in parallel.

What’s the actual difference between INCIBE-CERT and CCN-CERT for an energy company?
INCIBE-CERT is the private-sector channel; CCN-CERT is for public administrations and classified government systems. A standard private energy operator, including a listed TSO like Redeia, reports to INCIBE-CERT once that channel is legally live — not CCN-CERT.

Is Red Eléctrica the only Spanish energy company this dual-status mechanism could apply to?
No — it’s the clearest example because it’s Spain’s sole electricity TSO and the textbook fit for a CNPIC critical-operator designation, but any operator that CNPIC (and eventually its CER successor) actually designates as critical could see the same automatic essential-entity trigger once both Spanish laws are in force.

What happens if an incident occurs before Spain finishes transposing NIS2?
There’s no confirmed domestic notification portal or penalty regime until the law passes, but that’s not a safe assumption to build a security programme on — the underlying Article 21 risk-management expectations, CNMC’s NCCS duties, and Ley 8/2011’s operator obligations all continue to apply regardless of the transposition delay.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  • NIS2 Directive, Article 3 — Scope (nis-2-directive.com)
  • NIS2 Directive, Article 23 — Reporting obligations (nis-2-directive.com)
  • NIS2 Directive, Article 34 — Penalties (nis-2-directive.com)
  • Ley 8/2011, de 28 de abril, protección de infraestructuras críticas (BOE-A-2011-7630)
  • Anteproyecto de Ley de Protección y Resiliencia de Entidades Críticas — Spain CER transposition tracker
  • Draft Ley de Coordinación y Gobernanza de la Ciberseguridad — Departamento de Seguridad Nacional
  • “EU Court Action Targets Ireland, Spain, France Over Critical Infrastructure Cyber Law” — Brussels Signal
  • CNMC expediente DCOOR/DE/002/25 — Código de red NCCS-E
  • Commission Delegated Regulation (EU) 2024/1366 — Network Code on Cybersecurity (ACER)
  • “Spain NIS2 Implementation 2026 — INCIBE-CERT, CCN-CERT & SaaS Compliance Guide” — sota.io
  • NIS2 Directive, Annex I — Sectors of high criticality (EUR-Lex)
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: