pressebox_600x600_v2.png ()

PresseBox - unn | UNITED NEWS NETWORK GmbH

https://www.pressebox.de

23.09.2026

NIS2 in Spain: what CISOs need to know about personnel screening

Zürich, 23.09.2026 (PresseBox) - Spain continues to work on transposing the NIS2 Directive through the future Cybersecurity Coordination and Governance Act. As of September 2026, the transposition should still be described as an ongoing legislative process rather than as fully applicable Spanish law. NIS2 broadens the European cybersecurity risk-management framework for essential and important entities across numerous sectors.

NIS2 requires proportionate risk-management measures, supply-chain security, incident management, access controls and training, among other areas. However, the Directive does not impose a general obligation to conduct background checks on employees. Validato views screening of certain individuals as a possible complementary, risk-based measure where the role and legal framework justify it. “NIS2 strengthens risk management, but it does not automatically turn every personnel check into a legal requirement. The key is to identify sensitive functions and apply proportionate, legally permissible controls,” says André Naef, CEO of Validato.

Validato recommends that potentially affected organisations have CISO, HR and Legal jointly assess which profiles have elevated risk exposure and which controls are appropriate. Any personnel screening must be assessed under the GDPR, Spain’s LOPDGDD and applicable sector-specific rules; criminal-record data requires a specific legal basis.
mehr...