Abstract cybersecurity enforcement shield representing NIS2 penalty and compliance framework in Spain

Spain NIS2 Penalties: The Three-Tier Fine Structure That Caps at €2M — and the Article 35 Management Liability That Doesn’t

Spain missed the NIS2 transposition deadline by over a year — and the fine structure in its January 2025 draft law looks very different from the headline numbers most compliance officers have been citing. The NIS2 Directive’s Article 34 sets a minimum fine floor of €10 million or 2% of global annual turnover for essential entity violations [1]. Spain’s Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad structures infractions into three tiers, with the standard very serious (muy grave) ceiling at €2 million [4].

That gap is not a loophole. The worst violations can still escalate to the full EU maximums. But for most in-scope Spanish organisations, understanding which tier an infraction lands in — and why — matters more than citing the headline figure.

The more pressing issue sits in Article 35 of Spain’s draft law, which makes management body members jointly and severally liable for their organisation’s NIS2 infringements. The organisational fine and personal director liability run on separate tracks — both can apply to the same incident. This guide covers Spain’s three-tier fine structure in full, the Centro Nacional de Ciberseguridad (CNCS) enforcement hierarchy, and what Article 35 personal liability means in practice. For the broader scope picture and the INCIBE-CERT vs CCN-CERT authority split, see NIS2 in Spain: the dual-authority model.

Does This Apply to Your Organisation? Scope Under Spain’s Draft Law

Spain’s draft law follows the NIS2 Directive’s two-tier classification. An entity is in scope if it operates in one of 18 regulated sectors and meets the relevant size threshold. Classification determines your fine ceiling and the supervisory intensity you will face. For a full determination walkthrough including auto-included digital service categories, see the NIS2 scope guide.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Classification Example sectors Size threshold Maximum fine
Essential entity Energy, transport, banking, health, water, digital infrastructure, public administration, space More than 250 employees or more than €50M annual turnover €10M or 2% of global annual turnover
Important entity Postal services, waste management, chemicals, food, manufacturing, digital providers (Annex II) More than 50 employees or more than €10M annual turnover €7M or 1.4% of global annual turnover

Spain’s draft law expands the sector list beyond the EU NIS2 baseline, adding the nuclear industry as an additional regulated sector [7]. The Spanish government estimates approximately 5,700 organisations will fall within the law’s scope [7]. This number may increase once sector-specific authorities complete their registration exercises following the law’s parliamentary passage.

Scope is determined by what your organisation does and its size — not by whether the CNCS has opened a file on you. Entities with cross-border EU operations should note that jurisdiction follows the member state of establishment: for cross-border determinations, see Article 26 jurisdiction explained.

Spain’s Three-Tier Fine Structure: Leve, Grave, and Muy Grave

Most compliance briefings for Spain cite only the EU Directive’s maximum figures. The draft law’s own infraction structure is more granular — and for most everyday compliance failures, the applicable ceiling is well below the Article 34 floor that generates headline coverage [4].

Tier Spanish term Fine range Typical triggers
Minor Leve €10,000–€100,000 Incomplete documentation, isolated procedural gap, minor incident notification delay
Serious Grave €100,001–€500,000 Repeated procedural failures, inadequate risk assessment, significant notification delay
Very serious Muy grave €500,001–€2,000,000 Wilful non-compliance, material harm to third parties, major disruption of essential services

The €2 million ceiling applies to most very serious infractions. For violations involving the most severe harm or a persistent pattern of non-compliance by essential or important entities, Spain’s draft preserves access to the full EU Article 34 maximums: €10 million or 2% of total worldwide annual turnover for essential entities, €7 million or 1.4% for important entities [1]. The three tiers function as the default structure; escalation to EU maximums represents the exceptional ceiling for the most serious cases.

This places Spain’s base tier structure lower than Germany’s NIS2 implementation, which set a €20 million ceiling for essential entities — above the EU Directive’s own minimum floor. At the standard muy grave level, Spain’s current draft is comparatively restrained. That restraint does not apply to Article 35 management liability, which runs independently of the entity-level fine tier and can attach to any infraction regardless of which tier it falls into.

What moves an infraction up the tiers

Both the NIS2 Directive and Spain’s draft law treat the following as aggravating factors when determining tier placement [1] [4]:

  • Intent and negligence: deliberate non-compliance is weighted more heavily than an isolated oversight or administrative gap
  • Duration: a sustained failure over months carries more weight than a brief lapse promptly corrected
  • Harm caused: material damage to third parties or disruption to essential services is the primary driver of very serious classification
  • Sector criticality: energy, health, and water entities face a stricter lens than lower-criticality sectors under the same infraction type
  • Market share: failures by entities whose disruption would create systemic effects receive heavier weighting
  • Prior infringements: a history of non-compliance automatically elevates tier placement for subsequent infractions

For the EU-wide penalty framework and how other member state implementations compare — including Germany (€20M ceiling) and Netherlands (€10M floor with periodic payments) — see the NIS2 penalties overview.

The CNCS Authority Chain: Who Enforces NIS2 in Spain

Spain’s new enforcement architecture places the Centro Nacional de Ciberseguridad (CNCS) at the apex, attached directly to the Presidencia del Gobierno — Spain’s Prime Minister’s office [7]. The CNCS is Spain’s sole national competent authority, its single point of contact with EU institutions including ENISA, and the lead body for national cybersecurity crisis coordination.

CCN-CERT serves public sector entities and government bodies. It operates under the Centro Criptológico Nacional (CCN), which sits within Spain’s national intelligence service (CNI). Essential public entities — ministries, regional governments, public health bodies, public universities — route incident reports and receive supervisory oversight through CCN-CERT.

INCIBE-CERT serves private sector entities, SMEs, and digital service providers. It operates under the Instituto Nacional de Ciberseguridad (INCIBE) within the Ministry of Economic Affairs. Most privately-held organisations in scope deal with INCIBE-CERT for incident reporting, technical guidance, and compliance queries [6].

CNPIC — the Centro Nacional para la Protección de las Infraestructuras Críticas — handles critical infrastructure operators in energy, water, and transport. CNPIC leads incident escalation and conducts sector-specific continuity testing for essential infrastructure operators [6].

The CNCS coordinates all three bodies and manages cross-sector or cross-border incidents. Sector-specific regulators (energy, telecoms, financial services) retain supervisory functions within their domains and may act alongside the CNCS in enforcement proceedings.

Supervisory intensity by entity classification

Essential entities face full supervisory audits on an annual cycle [6]. Important entities face risk-triggered and event-driven oversight — the authority investigates following a reported incident or credible tip, rather than on a fixed calendar. Both entity types are subject to the Article 32 enforcement toolkit [3]:

  • On-site and off-site inspections, including unannounced random checks
  • Targeted or regular security audits by independent bodies
  • Ad hoc audits following a significant incident or reported violation
  • Binding instructions to cease non-compliant conduct
  • Time-bound correction orders with defined remediation deadlines
  • Mandatory public disclosure of specified violations

Article 35 Management Liability: Director Penalties, Personal Sanctions, and the Management Ban

Article 35 of Spain’s draft law makes management body members jointly and severally liable for the NIS2 infringements their organisation commits [4]. Joint and several liability means the CNCS can pursue any individual board member for the full penalty amount — not a proportional share determined by role or seniority.

This provision builds on the NIS2 Directive’s Article 20, which requires management bodies to approve cybersecurity risk-management measures, oversee their implementation, and bear responsibility for violations of Article 21 [2]. Spain’s Article 35 goes further by making that responsibility financially enforceable against individuals. The organisational fine and the personal director liability are parallel tracks: the company pays its fine and a director faces personal enforcement in the same case, under separate legal bases.

What triggers Article 35

Approval failure. The management body has not formally approved the organisation’s cybersecurity risk-management measures. Approval means a documented board-level decision — not a delegation to the CISO or IT function. A board that handed cybersecurity entirely to a technical team retains no approval record when the CNCS reviews the governance trail.

Oversight failure. The management body has not actively overseen the implementation of those measures over time. Article 20 requires ongoing oversight, not a one-time sign-off [2]. Competent authorities expect documented evidence: board meeting minutes addressing cybersecurity, periodic risk register reviews reaching board level, and audit reports with documented management responses.

Training failure. Article 20 requires management body members to receive regular cybersecurity training sufficient to understand the organisation’s risk exposure and assess the adequacy of risk management practices [2]. Failure to document this training — and to ensure comparable training for employees — creates a compliance gap that directly supports an Article 35 finding against individual directors.

The management ban

Beyond financial liability, Article 32 of the NIS2 Directive empowers competent authorities to temporarily prohibit a responsible officer from exercising management functions [3]. This sanction applies to individuals when initial enforcement has not produced compliance. A temporary management ban disrupts board composition, affects executive function directly, and may trigger contractual and directors’ liability insurance consequences that compound the NIS2 penalty itself.

The liability framework leaves no room for delegation as a defence. A board member cannot argue that cybersecurity was “IT’s responsibility.” Article 20 of the Directive and Article 35 of Spain’s draft law together make the management body the accountable unit — and the individuals within it personally exposed. For a full breakdown of board-level obligations under NIS2, see the NIS2 board directors guide.

Non-Financial Sanctions: Audit Orders, Service Suspension, and Public Disclosure

Fines are the most visible NIS2 enforcement track. The Article 32 toolkit includes several non-financial sanctions that can be more operationally disruptive, particularly for entities whose operations depend on regulatory certification or public procurement eligibility.

  • Service suspension: the CNCS may suspend certifications or authorisations tied to the entity’s ability to operate. For trust service providers, regulated digital infrastructure operators, and entities holding sector licences, a suspension order is effectively a shutdown notice [3].
  • Mandatory security audit: the authority can order an independent security audit conducted entirely at the entity’s expense, with findings reported directly to the CNCS. The cost and resource burden fall on the non-compliant organisation [3].
  • Public disclosure: the CNCS may require the entity to publicly disclose the nature of its non-compliance. This affects procurement bids, enterprise customer contracts, sector-specific reputational standing, and any publicly-held tender requirement that references NIS2 compliance status [5].
  • Monitoring officer: the CNCS may appoint an officer to oversee compliance directly, maintaining ongoing operational access to the entity until the authority is satisfied that violations have been remediated [3].

These sanctions operate independently of financial fines. An entity can receive a €500,000 grave-tier fine and a monitoring officer appointment in the same enforcement action. For essential entities whose operations depend on continuous regulatory certification, the non-financial track is often the more urgent operational concern.

Enforcement Timeline: When Do These Fines Actually Apply?

Spain’s draft law is in parliamentary process as of mid-2026. The Anteproyecto was approved by Spain’s Council of Ministers on 14 January 2025 [7] and requires parliamentary passage and publication in the Boletin Oficial del Estado (BOE) before national enforcement begins. No firm parliamentary timetable has been confirmed.

That does not mean compliance obligations are paused. The NIS2 Directive’s transposition deadline passed on 17 October 2024. On 28 November 2024, the European Commission opened infringement proceedings against Spain — alongside 22 other member states — for failing to complete transposition [8]. The Commission issued a reasoned opinion in May 2025, the procedural step before possible referral to the Court of Justice of the EU. These proceedings apply direct political and legal pressure to accelerate parliamentary passage and will continue until Spain’s law is fully enacted.

In-scope entities are advised to treat compliance as a current obligation, not a future one. The underlying Directive obligations — risk management measures under Article 21, incident notification under Article 23 — are grounded in EU law, not national transposition. For the Article 23 incident notification requirements and what the 24-hour early warning standard requires in practice, that guide covers the current applicable standard while Spain’s law is finalised.

Three actions to take before enforcement begins:

  1. Classify your organisation: determine essential or important status against the thresholds above. Classification drives your fine ceiling, supervisory intensity, and the CSIRT (CCN-CERT or INCIBE-CERT) you will report to.
  2. Assign governance: appoint a named security owner and document a formal management board approval of your cybersecurity risk management framework. This is the foundational Article 35 defence.
  3. Build your audit evidence: the documents the CNCS will request in an inspection start with incident logs, risk registers, training records, and board-level review documentation. Start accumulating this evidence now.

Frequently Asked Questions

When will Spain’s NIS2 law actually be enforced?

No confirmed enforcement date as of mid-2026. Parliamentary passage is expected during 2026, with active supervisory activity possible shortly after BOE publication. This is a practitioner estimate rather than an official announcement [4].

Can the fine exceed €2 million under Spain’s draft law?

Yes. The most serious violations — those involving essential entities, significant harm, or repeated non-compliance — can escalate to the full EU Article 34 maximums: €10 million or 2% of global annual turnover for essential entities, €7 million or 1.4% for important entities [1].

Does Article 35 management liability apply to all board members equally?

Article 35 covers the management body as a whole. Joint and several liability means any individual member can be pursued for the full penalty amount. In practice, authorities typically pursue members with direct oversight responsibility, but the draft text contains no safe-harbour provision limiting liability to specific roles [4].

What is the difference between the CNCS and INCIBE?

The CNCS is the apex policy and enforcement authority — it sets national cybersecurity strategy, coordinates sector authorities, and handles EU-level liaison. INCIBE-CERT is the operational CSIRT for the private sector — it handles incident response and technical guidance for most privately-held in-scope organisations. The CNCS may direct or coordinate INCIBE-CERT in specific enforcement actions [6] [7].

Can an organisation be fined under both NIS2 and GDPR for the same incident?

Yes. A cybersecurity incident involving personal data may trigger NIS2 enforcement by the CNCS or INCIBE-CERT and GDPR enforcement by Spain’s data protection authority (AEPD) simultaneously. The two regimes operate independently — no reduction or offset applies between them.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive Article 34: General Conditions for Imposing Administrative Fines — nis-2-directive.com. Essential entity floor (€10M or 2% of global annual turnover); important entity floor (€7M or 1.4%); member state discretion to exceed these minimums.
  2. NIS2 Directive Article 20: Governance — nis-2-directive.com. Management body approval, oversight, and training obligations; basis for Article 35 management liability under Spain’s draft law.
  3. NIS2 Directive Article 32: Supervisory and Enforcement Measures for Essential Entities — nis-2-directive.com. Full enforcement toolkit including on-site inspections, security audits, binding instructions, service suspension, and management position prohibition.
  4. Spain NIS2 Transposition: Status, Requirements, and Roadmap — Copla. Three-tier infraction structure (leve/grave/muy grave); management joint and several liability; CNCS enforcement framework.
  5. NIS2 Spain: Is Your Company Ready for 10M EUR Fines? — Delbion. Non-financial sanction types; management personal liability scope; public disclosure consequences.
  6. Spain’s NIS2 Delay: Turn Regulatory Uncertainty Into Compliance Advantage — ISMS Online. CNCS, CCN-CERT, INCIBE-CERT, and CNPIC authority roles; essential vs important supervisory intensity.
  7. Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad — Spanish Government (Departamento de Seguridad Nacional). Official announcement of CNCS establishment and function; approved 14 January 2025.
  8. Commission calls on 23 Member States to fully transpose the NIS2 Directive — European Commission. Infringement proceedings opened 28 November 2024 against Spain (and 22 other member states) for missing the 17 October 2024 transposition deadline.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: