Cyber Resilience Act Enforcement in Spain
Learn how the EU Cyber Resilience Act applies to companies in Spain, including local market surveillance and enforcement by INCIBE.
Core Definition
The Cyber Resilience Act is an EU Regulation, meaning it applies directly in Spain without the need for national transposition. However, enforcement and market surveillance activities will be conducted by national authorities like INCIBE. Any product with digital elements sold or made available in Spain must comply with CRA standards by December 2027.
Key Compliance Steps for Spain
- Identify Local Representatives: If you are based outside the EU but selling into Spain, appoint an Authorized Representative in the Union.
- Monitor INCIBE Guidelines: Follow any localized guidance or translation of standards provided by INCIBE.
- Prepare ENISA Reporting: Ensure your vulnerability reporting pipelines are connected to the central ENISA platform and your national CSIRT.
- Localize Documentation: Ensure that the required EU Declaration of Conformity and user instructions are available in the languages required by Spain.
How This Plays Out in Practice
INCIBE, Spain's national cybersecurity institute, combines its existing incident-response and awareness role with the new CRA market-surveillance mandate.
What to Watch For
Spain's fast-growing fintech and tourism-tech sectors are likely enforcement priorities given their consumer-data exposure.
Assess Your CRA Readiness
Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Spain.