Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain’s election call returns attention to a NIS2 delay documented in the official records reviewed.
Spain published Royal Decree 806/2026 on 6 October. It dissolved the Congress of Deputies and Senate, called a general election for 29 November and set 23 December for the new chambers to convene. The decree does not change cybersecurity law. Its relevance is procedural: the Commission documented incomplete transposition in July, while the latest national stage material reviewed describes a planned law.
The Commission documented the delay in July
On 8 July, the European Commission referred Spain, Ireland, France and the Netherlands to the Court of Justice of the European Union for failing to notify full NIS2 transposition. Member States had until 17 October 2024. The Commission asked the Court to impose a lump sum and daily penalties until complete notification.
That referral was not a judgment and did not itself create Spain’s national NIS2 duties. It documented the position on 8 July; the material reviewed here does not establish the Court proceeding’s current status.
The latest national material reviewed described a planned law
The government approved a preliminary draft Law on Cybersecurity Coordination and Governance in January 2025. It was to collect mandatory reports and return to the Council of Ministers before going to Parliament. On 17 March 2026, the government still described the measure as a preliminary draft being processed by the responsible ministries. Its annual legislative plan, published on 5 May, continued to list the law as a 2026 initiative.
A targeted 6 October check of current BOE and Congress records found no enacted law or parliamentary bill under that title. This bounded check cannot prove no differently titled or unpublished work exists. The newly elected chambers are due to convene on 23 December.
Dissolution and caretaker status are different
The election decree does not by itself place the government into caretaker status. Article 21 of Spain’s Government Act says the government ceases after the general election and then continues in a caretaker capacity until its successor takes office.
During that caretaker period, the government must generally limit itself to ordinary public business and cannot present bills to Congress or the Senate. This can extend uncertainty, but it does not support a claim that every legislative or regulatory activity is frozen indefinitely.
Existing duties continue
Spain does not have a cybersecurity-law vacuum. Royal Decree-law 12/2018 and Royal Decree 43/2021 continue to impose security and incident-reporting duties on covered operators of essential services and digital service providers. Sector-specific rules and GDPR duties also continue where they apply.
The proposed NIS2 law would broaden and restructure the national framework. Its draft covered a wider group of essential and important entities, governance arrangements, risk management and incident reporting. Those proposed duties should guide preparation, but they should not be described as enacted Spanish obligations before a final law is published.
What organisations should do now
Organisations with Spanish operations should keep two records separate: current legal duties and NIS2 readiness. Confirm which entities and services fall under today’s Spanish, sector and data-protection rules. In parallel, map the services, suppliers, management ownership, risk controls and incident workflows likely to matter under NIS2.
Track the BOE, the next government’s legislative programme and official EU proceedings. For related coverage, see our Dutch NIS2 guide.
This article provides general information and is not legal advice.
Official sources
- Spanish election decree, Royal Decree 806/2026
- European Commission referral of Spain and three other Member States
- Interior Ministry announcement of the preliminary draft
- NIS2 Directive
- Spanish Government statement on the NIS2 draft, 17 March 2026
- Spain’s 2026 Annual Regulatory Plan
- Article 21 of the Government Act
- Current Spanish network and information systems security law
- Implementing Royal Decree 43/2021
- General Data Protection Regulation
Continue the series: European National Cyber & Digital Law Series index


