Back to Blog
    Corporativo

    Business Cybersecurity: CRA, NIS2, GDPR and the AI Act

    •4 min

    A practical map separating the scope, dates and responsibilities of the CRA, NIS2, GDPR and AI Act instead of applying every duty to every business.

    Regulatory review: 26 August 2026. There is no single “full compliance in 2026” date, and the same rules do not apply to every business. The CRA, NIS2, GDPR and AI Act govern different organisations, products, systems and risks.

    Start by identifying the potentially applicable regime

    • Cyber Resilience Act (CRA): focuses on products with digital elements and the obligations of manufacturers, importers, distributors and other economic operators defined by the regulation.
    • NIS2 Directive: addresses essential or important entities in specified sectors, also taking account of size thresholds and national transposition rules.
    • GDPR: protects personal data, requires risk-appropriate security and has its own personal-data-breach notification regime.
    • AI Act: assigns duties according to the role of provider, deployer or other operator and according to the AI system's category and use.

    A company may fall under several regimes, one regime or none of these specific duties. The analysis must begin with the activity, product, sector, size, role and data processed.

    The actual Cyber Resilience Act timetable

    Regulation (EU) 2024/2847 applies generally from 11 December 2027. Earlier partial milestones include:

    • the chapter concerning notification of conformity assessment bodies has applied since 11 June 2026;
    • Article 14 reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 September 2026.

    Accordingly, 2026 is not the full application date for the product requirements. It is a preparation year and the starting point for specific reporting duties.

    NIS2: sectoral scope and Spanish transposition

    NIS2 does not automatically turn every SME or digital supplier into an obliged entity. Its annexes identify sectors and types of entity, while final classification depends on the directive's criteria and national legislation.

    On 17 March 2026, the Spanish Government described the Cybersecurity Coordination and Governance Act as still being processed. Before assigning an obligation or competent authority, check the text ultimately published in Spain's Official State Gazette and any applicable sector-specific rules.

    The management body's role

    For entities within NIS2, Article 20 requires management bodies to approve cybersecurity risk-management measures, oversee implementation and receive training. Liability for infringements is governed through national law.

    This does not support a claim of automatic financial or personal liability for every director of every company. The actual exposure depends on scope, transposition, applicable corporate duties, conduct and harm.

    Do not merge notification channels

    The CRA and NIS2 have their own sequences and recipients. The GDPR adds another regime where an incident is a personal data breach. The same event may trigger more than one assessment, but it should not be reported indiscriminately “to ENISA”, nor should every deadline be assumed to be 24 hours.

    The response plan should identify in advance who classifies the event, which authority is competent, what evidence must be retained and how legal, technical and contractual communications are coordinated.

    Cybersecurity governance checklist

    1. Classify entities, products, services, AI systems and personal-data processing.
    2. Assign owners for risk, response, continuity, privacy and regulatory communications.
    3. Document risk-proportionate measures and oversight by the relevant management body.
    4. Include the supply chain in risk assessment without assuming unlimited liability for every supplier.
    5. Prepare separate notification matrices for the CRA, NIS2, GDPR and sector-specific duties.
    6. Review contracts, evidence, training and response exercises.

    Official sources

    See Regulation (EU) 2024/2847 — Cyber Resilience Act, Directive (EU) 2022/2555 — NIS2, and the Spanish Council of Ministers reference on the national legislative process.

    Practical next step

    Apply this information to your situation

    Review the relevant service or tell us about the facts before making a tax, legal or business decision.

    Tags

    CiberseguridadComplianceNIS2AdministradoresLegal TechSeguridad Digital

    5 sources

    Documentary sources

    References recorded for this publication. Check the current version and date before making a decision.

    Related articles

    Need personalized advice?

    Our team is ready to help with your tax, accounting and legal needs in Spain.

    WhatsApp UsCall Now