Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — Spain

Command of the Spanish regulatory framework — CCN-CERT, INCIBE, AEPD, Esquema Nacional de Seguridad — for public and private organizations.

Last updatedAugust 22, 2026

The local regulatory framework

Spain's cybersecurity framework is structured by the Centro Criptológico Nacional (CCN-CERT), the reference body for the security of government and strategic entities' information systems, by the Instituto Nacional de Ciberseguridad (INCIBE) for awareness and support to businesses and citizens, and by the Agencia Española de Protección de Datos (AEPD) for personal data protection. The Esquema Nacional de Seguridad (ENS) sets out the security requirements applicable to public sector information systems and related providers, across three categorization levels (básico, medio, alto). The NIS2 directive, currently being transposed, broadens the scope of essential and important entities subject to risk management obligations.

Concrete obligations

Compliance with the Esquema Nacional de Seguridad (ENS) according to the applicable categorization level (básico, medio, alto) for public sector and related systems

GDPR compliance under the oversight of the Agencia Española de Protección de Datos (AEPD)

Anticipation of obligations arising from the NIS2 transposition for essential and important entities

Alignment of security practices with CCN-CERT's technical recommendations and frameworks

Priority sectors

Public sectorFinanceIndustry

Delivery modalities

Engagement model

Direct engagement

Framework

Esquema Nacional de Seguridad (ENS)

Languages

Spanish, English, French

Local FAQ

What are the reference cybersecurity authorities in Spain?

The CCN-CERT for the security of strategic information systems, INCIBE for support to businesses, and the AEPD for personal data protection.

What is the Esquema Nacional de Seguridad (ENS)?

A framework setting out the security requirements applicable to public sector information systems and related providers, structured across three categorization levels: básico, medio and alto.

How is the applicable ENS level determined?

It depends on the risk analysis and the potential impact of a breach affecting the information handled by the system in question.

Does NIS2 apply in Spain?

Yes, its transposition broadens the scope of essential and important entities subject to risk management and incident notification obligations. This topic has its own dedicated page on this site.

Which authority oversees data protection in Spain?

The Agencia Española de Protección de Datos (AEPD), which enforces GDPR.

What services are most requested in Spain?

Security audits and GRC compliance aligned with the ENS for the public sector, complemented by penetration testing and continuous monitoring for the private sector.

How does an engagement in Spain typically start?

With an initial scoping phase to determine the applicable ENS level or the entity's status under NIS2, followed by defining the technical scope of the engagement.

Get in touch