Abstract network security visualization over a dark transport infrastructure backdrop, representing NIS2 cybersecurity compliance for Spain's transport sector

Spain’s NIS2 Transport Split: Why AENA Reports to INCIBE-CERT While ADIF and Spain’s 28 Port Authorities Answer to CCN-CERT

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Does NIS2 Apply to Your Transport Operation in Spain?

If you run an airport, manage rail infrastructure, operate a port, or handle freight or passenger transport in Spain, NIS2 almost certainly reaches you. Transport is one of the seven high-criticality sectors in Annex I of Directive (EU) 2022/2555, and Spain’s draft transposition law follows the directive’s sector list without narrowing it for transport [1][2]. The real questions are (a) whether your entity is Essential or Important, and (b) which of Spain’s four incident-reporting authorities receives your notification — and the second question does not follow the answer to the first.

Sub-sector Annex I entity type Spanish example Typical classification
Air Airport managing bodies; air carriers; ATM/ANS providers AENA; airlines; ENAIRE Essential (regardless of size, per state-critical designation)
Rail Infrastructure managers; railway undertakings ADIF, Adif-Alta Velocidad; Renfe Essential
Water Port managing bodies; VTS operators; water transport companies Puertos del Estado; the 28 port authorities Essential
Road Traffic-management-control systems; Intelligent Transport Systems operators ITS/traffic-control operators Essential or Important, by size threshold

Size still matters for the Important/Essential split on the entities that aren’t automatically critical: more than 250 staff or over €50M annual turnover pushes an operator into the Essential tier; 50–249 staff or €10–50M turnover lands in Important [3]. But several of Annex I’s transport categories — airport managing bodies, rail infrastructure managers, port managing bodies among them — are treated as Essential outright because of what they do, not how big they are, the same logic that puts sole national providers of a critical service straight into the Essential tier regardless of headcount [3]. For the full essential-vs-important walkthrough, see our Spain competent authority guide.

AENA and Air Transport: One Operator, Three Possible Regulators

AENA manages 46 airports and two heliports across Spain, and its network carried a record 321.6 million passengers in 2025 [8] — by any measure, the backbone of Annex I’s “airport managing bodies” category [2]. What trips up most compliance briefings is AENA’s legal form. AENA S.A. is not a public administrative body; it is a sociedad anónima, a private-law commercial company, even though ENAIRE (itself a state entity) holds 51% of its capital [11]. Spain’s CSIRT-routing rule keys off legal form, not ownership percentage: a privately incorporated company — majority-state-owned or not — notifies INCIBE-CERT, the same CSIRT that handles airlines and ground-handling firms [4].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

ENAIRE, the air navigation service provider that runs Spain’s air traffic management — a separate Annex I category from airport operation [2] — is registered on Spain’s own public-entity inventory as an entidad pública empresarial, a genuinely public-law form [12]. That is the same legal category as ADIF, covered next, and under Spain’s public-sector routing rule it points toward CCN-CERT rather than INCIBE-CERT [4]. So within civil aviation alone, the airport operator and the company that controls the airspace above those airports — both effectively state-controlled — would, on this reading, answer to two different national CSIRTs, purely because of how each was incorporated. Treat the ENAIRE routing as a strong inference from the general rule rather than a directly published instruction, and confirm the current contact before you need it in an incident.

Military aviation sits outside both tracks. Shared civil-military airfields and any network specifically entrusted to the Armed Forces route to ESPDEF-CERT, run by the Joint Cyberspace Command [4]. If your operation touches a joint-use airfield, the civilian ATM and passenger-handling side stays with INCIBE-CERT while the defence-designated side goes to ESPDEF-CERT — document that boundary in your incident response plan now, because Spain’s published guidance does not yet spell out the edge cases for contractors working across it [4].

ADIF and Rail: Why a State-Owned Railway Doesn’t Report Like AENA

ADIF — the Administrador de Infraestructuras Ferroviarias — is configured under Law 40/2015 Article 103.1 as an entidad pública empresarial attached to the Ministry of Transport, with its own legal personality and assets [10]. That single classification detail is the whole story: unlike AENA’s private commercial form, ADIF is organised under public administrative law, which routes its incident notifications to CCN-CERT, the CSIRT the National Cryptologic Centre operates for the public sector [4]. Adif-Alta Velocidad, split off as a separate entity under Real Decreto-Ley 15/2013 to run the high-speed network, carries the same public-entity status and the same routing [10].

Renfe, the train operating company that runs services over ADIF’s infrastructure, is the entity most likely to be confused with ADIF in a compliance review — but it is a distinct “railway undertaking” under Annex I, not an “infrastructure manager” [2]. Renfe’s own legal form determines its routing independently of ADIF’s; don’t assume the two share a CSIRT contact just because they share a network. Verify each entity’s classification separately before you build a joint incident-response runbook. For the full public-vs-private routing logic, see our breakdown of Spain’s three-CSIRT (plus OCC) architecture.

Spain’s 28 Port Authorities: Public Entities, One Routing Answer

Spain’s state port system runs on a two-tier public structure: Puertos del Estado coordinates system-wide policy and efficiency, while 28 Autoridades Portuarias each manage one or more of the country’s 46 ports of general state interest under a decentralised autonomy model [9]. Both tiers are entes de derecho público — public-law entities with their own legal personality, distinct from AENA’s commercial form [9]. That makes the routing answer for the entire port system simple, in contrast to the airport picture: every port authority, along with Puertos del Estado itself, reports to CCN-CERT [4].

Annex I’s water-transport category covers more than the port managing bodies themselves. Vessel traffic services (VTS) operators — the systems that monitor and manage vessel movements in Spanish waters — and passenger or freight water-transport companies operating in inland, sea, or coastal traffic are separately in scope [2]. A shipping line calling at a Spanish port is a private-law company in almost every case, so it follows AENA’s track to INCIBE-CERT even though the port it calls at reports to CCN-CERT — another instance of the same entity-type dividing line running straight through a single supply chain.

The PIC Overlay: Transport Compliance in Spain Predates NIS2

AENA, ADIF, and the port authorities were already “critical operators” under Spanish law more than a decade before NIS2 existed. Ley 8/2011 established Spain’s Sistema PIC (Protección de Infraestructuras Críticas) across 12 strategic sectors, transport among them, with a sector-specific strategic plan for airports, ports, roads, and railways approved in 2015 [6]. The Centro Nacional para la Protección de las Infraestructuras Críticas (CNPIC), under the Secretary of State for Security at the Ministry of Interior, designates critical operators and requires them to maintain operator security plans and specific infrastructure protection plans, updated annually [6].

NIS2 does not replace this framework — it runs alongside it. Spain’s own national cyber authority lists a fourth coordination body most compliance guides miss entirely: the Oficina de Coordinación de Seguridad (OCC), housed at the Ministry of Interior specifically to coordinate critical infrastructure operators [4]. In practice, a designated critical operator in transport carries three parallel obligations that a same-sized but non-critical operator in another sector does not: NIS2’s Article 21 risk-management measures and Article 23 incident notification to INCIBE-CERT or CCN-CERT, PIC’s operator security plan filed with CNPIC, and OCC coordination on the physical-security side. Budgeting for NIS2 alone, without accounting for the PIC filing cycle already in place, is the most common gap-analysis miss we see in transport compliance reviews.

Penalties and the Transposition Clock

Spain missed the NIS2 transposition deadline of 17 October 2024. The European Commission issued a reasoned opinion on 7 May 2025 and, on 9 July 2026, referred Spain — together with Ireland, France, and the Netherlands — to the Court of Justice of the EU under case INFR(2024)0270, seeking a lump-sum penalty plus daily fines until transposition is complete [7]. Until Spain’s draft law clears Congress and is published in the Boletín Oficial del Estado, the directive’s obligations under (EU) 2022/2555 still apply directly from the missed deadline — the legislative delay does not suspend your compliance exposure.

When the draft law does pass, its fine structure is more granular than the headline Article 34 figures most briefings quote. Spain’s Anteproyecto sorts infractions into three tiers: leve (€10,000–100,000), grave (€100,001–500,000), and muy grave (€500,001–2,000,000) — with the €2M ceiling covering most real-world violations, while the worst cases (wilful non-compliance, material harm) can still escalate to Article 34’s full EU maximums [5].

Tier Fine range Article 34 ceiling (worst cases)
Essential entity Up to €2M under Spain’s muy grave tier €10M or 2% of global turnover, whichever higher [1]
Important entity Up to €2M under Spain’s muy grave tier €7M or 1.4% of global turnover, whichever higher [1]

Spain’s draft law adds a separate exposure on top of the organisational fine: Article 35 makes management-body members jointly and severally liable for their entity’s NIS2 infringements, running on its own track alongside — not instead of — the corporate fine [5]. For board-level implications, see our Spain penalties and enforcement guide.

Compliance Checklist for Spanish Transport Operators

Step Owner Effort
Confirm your entity’s legal form (S.A. vs. entidad pública empresarial vs. ente de derecho público) and lock in the correct CSIRT contact Legal / Compliance Low
Check whether your entity already holds a PIC critical-operator designation and cross-reference its operator security plan against your Article 21 risk-management measures CISO + Compliance Medium
Map Article 21(2) measures (risk analysis, incident handling, business continuity, supply chain, access control) to existing OT/IT controls across airport, rail, or port systems CISO / IT Security High
Build a documented incident-notification runbook: 24h early warning, 72h notification, 1-month final report, addressed to the correct CSIRT [3] Compliance Officer Medium
Brief the management body on Article 20 approval/oversight duties and Spain’s Article 35 joint-liability exposure Board / C-Suite Low

Frequently Asked Questions

Does a private company operating inside a state-owned port or airport report to the same CSIRT as the port or airport authority?

Not necessarily. Routing follows each entity’s own legal form, not the site it operates from. A privately incorporated shipping line or ground-handling company reports to INCIBE-CERT even when it operates inside a port managed by one of the 28 public-law port authorities, which reports separately to CCN-CERT. Confirm each entity’s classification independently rather than inheriting the site operator’s routing.

Is Spain’s NIS2 transport framework already enforceable?

The directive’s substantive obligations under (EU) 2022/2555 apply from the missed 17 October 2024 deadline regardless of domestic legislative progress, though Spain’s specific fine tiers, the CNCS umbrella structure, and the Article 35 liability provision only take effect once the draft law is published in the BOE [5][7].

Does the PIC critical-operator designation replace NIS2 obligations for transport entities?

No. PIC and NIS2 are separate, parallel regimes with different legal bases, different filing authorities (CNPIC/OCC versus INCIBE-CERT/CCN-CERT), and different enforcement tracks. A transport operator holding both designations must satisfy both sets of obligations [4][6].

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: