Legal Cybersecurity: Obligations and Corporate Liability for 2026
Discover the new legal obligations in cybersecurity for 2026: NIS2, AI Act, and the direct liability of administrators. Protect your company and its board members.
The End of Technical Voluntariness in Cybersecurity
For years, cybersecurity was treated as a secondary technical matter, relegated to the "IT department." However, we are entering a new era. By 2026, the European and Spanish regulatory framework will have completed a radical transformation: cybersecurity is no longer a choice; it is an unavoidable legal obligation for administrators and board members.
The regulatory convergence of the AI Act, the NIS2 Directive, and the Resilience Act (CRA) places cyber-resilience at the heart of corporate governance. This article analyzes the legal obligations your company must face to avoid sanctions that, in many cases, can reach millions of euros.
The Regulatory Pillars: From GDPR to NIS2 and the AI Act
Current legislation focuses not only on protecting data but on ensuring the continuity of essential services and the integrity of the supply chain. The most critical regulations include:
- NIS2 Directive: Expands the scope of companies considered "essential" or "important," including sectors such as energy, transport, health, and even digital providers and food.
- GDPR (General Data Protection Regulation): Continues to be the benchmark for the protection of personal data, requiring "technical and organizational measures" proportional to the risk.
- AI Act (Artificial Intelligence Act): For companies implementing AI, this law imposes strict security and transparency requirements to prevent systemic biases and technological vulnerabilities.
- CRA (Cyber Resilience Act): Establishes that products with digital components must comply with security standards throughout their entire lifecycle.
Direct Liability of Administrators
One of the most significant changes for 2025 and 2026 is the personalization of liability. Governance is no longer limited to approving budgets; it requires active supervision. Under the framework of the NIS2 Directive and the Spanish Capital Companies Act:
- Administrators can be held personally liable for the lack of adequate cybersecurity measures if it is proven that they acted with negligence in their duty of oversight.
- Management bodies MUST receive specific training to identify risks and assess the cybersecurity maturity of their organization.
- The lack of an immediate reporting protocol (within 24-72 hours) for incidents can lead to disqualification from holding management positions.
Practical Case: The Supply Chain Risk
Imagine a Spanish medium-sized enterprise (SME) that provides logistics services to a multinational. A "ransomware" attack on the SME's servers paralyzes the multinational's supply chain for three days. Under the new regulations, the multinational is obliged to audit its suppliers' security. If the SME cannot prove it has implemented the "state of the art" in security, it faces not only the loss of the contract but also million-dollar claims for damages and potential administrative sanctions.
Compulsory Measures: What Should Every Company Do Today?
To ensure "legal compliance" in terms of cybersecurity, companies must implement at least the following measures:
- Risk Analysis: A technical-legal document that identifies threats and established mitigation measures.
- Incident Response Plan: A documented protocol that defines who does what and when in the event of an attack.
- Audit of Third Parties: Reviewing the legal contracts and security certifications of all digital providers (SaaS, Cloud, Hosting).
- Continuous Training: Phishing simulations and awareness programs for all employees, from the CEO to the administrative staff.
The 2026 Horizon: Preparing for the Major Change
The year 2026 is marked as the "deadline" for full adaptation to the new European digital requirements. This implies that companies must transition from a reactive model (fixing things after they break) to a proactive compliance model. This includes managing the ethics of artificial intelligence and ensuring that any digital product sold in the EU has a "CE" mark for cybersecurity.
Conclusion: Cybersecurity as a Competitive Advantage
At Navarro, we interpret these regulations not as a burden, but as an opportunity. Companies that demonstrate robust legal and technical cybersecurity generate greater trust in the market, facilitate their internationalization, and protect their most valuable asset: their reputation. Protecting your business starts with a legal audit of your technological risks.
Contact our expert team to evaluate your company's compliance level and prepare for the 2026 regulatory challenges.