CRA Compliance in Spain
National competent authority, Article 14 CSIRT contacts, and enforcement guidance for Spain manufacturers.
Spain operates a dual-authority cybersecurity structure: the Centro Criptológico Nacional (CCN) under the CNI intelligence service handles government and critical infrastructure, while INCIBE (Instituto Nacional de Ciberseguridad) focuses on private sector and SME cybersecurity. For CRA purposes, INCIBE acts as the primary NCA for private-sector manufacturers, with CCN covering public sector supply chains. Spanish manufacturers in automotive, telecommunications, and industrial sectors have a significant CRA compliance footprint.
National Competent Authority (CRA)
INCIBE / CCN
Instituto Nacional de Ciberseguridad / Centro Criptológico Nacional
INCIBE serves as the primary CRA national competent authority for private sector manufacturers in Spain. CCN (under CNI) retains authority over public sector and critical infrastructure supply chains. Both coordinate under the overall cybersecurity strategy of the Ministerio de Asuntos Económicos y Transformación Digital.
https://www.incibe.es →National CSIRT (Article 14 Reports)
INCIBE-CERT
INCIBE-CERT and CCN-CERT
https://www.incibe.es/incibe-cert/comunicar-incidente
https://www.incibe.es/incibe-cert →CRA Enforcement in Spain
Spain's CRA enforcement involves coordination between INCIBE (for private sector manufacturers), CCN (for public sector supply chains), and the Secretaría de Estado de Digitalización e Inteligencia Artificial (SEDIA). Market surveillance for CE-marked products is coordinated with the Agencia Española de Consumo, Seguridad Alimentaria y Nutrición (AECOSAN) and sector-specific bodies. Spain has been building cybersecurity enforcement capacity through its National Cybersecurity Strategy, and CRA enforcement is expected to follow a graduated approach with strong emphasis on SME support given the structure of Spain's manufacturing sector.
Article 14 Incident Reporting for Spanish Manufacturers
Spanish private-sector manufacturers submit Article 14 notifications to INCIBE-CERT through its secure incident reporting portal. CCN-CERT handles notifications from manufacturers supplying public sector or critical infrastructure. INCIBE-CERT operates a 24/7 response capability for significant cybersecurity incidents. The Article 14 obligation requires an early warning within 24 hours of discovering active exploitation and a full notification within 72 hours. INCIBE-CERT participates in the EU CSIRTs network and coordinates with ENISA. Manufacturers unsure whether to report to INCIBE-CERT or CCN-CERT should default to INCIBE-CERT, which will route the report appropriately.
Market Surveillance & Penalties
Spain's market surveillance for CRA products is coordinated between INCIBE, CCN, and AECOSAN, with customs authorities involved for imported products. The full CRA penalty regime applies: up to €15 million or 2.5% of global annual turnover for violations of essential cybersecurity requirements. Spain's enforcement tradition in consumer product safety has been active through AECOSAN, and CRA cybersecurity enforcement is expected to build on this infrastructure. Spanish manufacturers should be aware that the Esquema Nacional de Seguridad (ENS) imposes additional cybersecurity requirements for public sector procurement, creating de facto higher standards for manufacturers supplying public authorities.
Support for Spanish Manufacturers
INCIBE provides free cybersecurity services for Spanish businesses including the CiberEmpresa platform with practical implementation guides, and sector-specific resources for industrial manufacturers. The Oficina de Seguridad del Internauta (OSI) provides consumer and SME guidance. INCIBE hosts an annual cybersecurity congress (ENISE) that addresses CRA implementation for manufacturers. The Red de Centros de Competencias en Ciberseguridad coordinates regional cybersecurity support. Spain's national certification laboratory ENAC provides accreditation for conformity assessment bodies supporting CRA product evaluations. CCN publishes the Spanish Security Guides (Guías CCN-STIC) with detailed technical controls aligned to CRA Annex I.
CVD Portal automates your Article 14 notification obligations.
Pre-built notification workflows for INCIBE-CERT, deadline tracking, CSAF advisory generation, and a public CVD submission portal. Free forever.
Start your free portalFrequently asked
How do I contact INCIBE or CCN as a manufacturer with a CRA compliance question?+
Private sector manufacturers should contact INCIBE through incibe.es, which provides a manufacturer enquiry service and the CiberEmpresa advisory platform. CCN is contacted through ccn.cni.es for public sector or classified infrastructure supply chain queries. INCIBE-CERT at incibe.es/incibe-cert handles incident notifications. INCIBE operates helpline services in Spanish during business hours and provides multilingual support through its EU-funded programmes.
Does Spain have national-level CRA implementing legislation?+
Spain is implementing CRA requirements through amendments to the Real Decreto-ley on cybersecurity and product safety regulations. Spain transposed NIS2 through the Real Decreto-ley 12/2018 framework, and CRA measures are expected to build on this foundation. The Ministerio de Asuntos Económicos y Transformación Digital is coordinating the national implementation. National implementing regulations are expected ahead of the CRA's December 2027 application date.
How does the CRA interact with Spain's Esquema Nacional de Seguridad?+
The Esquema Nacional de Seguridad (ENS) mandates cybersecurity standards for public sector ICT systems and their suppliers. Manufacturers supplying Spanish public authorities must comply with ENS requirements, which share significant overlap with CRA Annex I requirements. CCN is developing guidance on how ENS-certified products can leverage their certification toward CRA conformity. Manufacturers already certified under ENS should conduct a gap analysis to identify any CRA-specific additive requirements not covered by their ENS certification.
CRA guides for neighbouring countries
Need a CRA compliance checklist for your product?
Browse free niche-specific checklists covering classification, Annex I obligations, and CVD requirements.