Resilience of communications networks: new framework and obligations

  • The new Royal Decree defines communications networks and services as essential infrastructures and sets strict security and continuity obligations.
  • Operators and managers of critical infrastructure must develop security plans and guarantee minimum electrical autonomy of between 4 and 24 hours.
  • Incident reporting is being strengthened, the protection of 112 centers is being reinforced, and a Security and Resilience Coordination Committee is being created.

resilience of communications networks

La resilience of communications networks It has become firmly entrenched in the political and business agendas, and also in everyday conversations. Power outages, torrential rains, volcanic eruptions, and pandemics have demonstrated that when telecommunications fail, virtually everything grinds to a halt: public services, economic activity, emergency response, and even the most basic communication between people.

In this context, the Ministry for Digital Transformation and Public Administration has promoted a Draft Royal Decree on the security and resilience of electronic communications networks and servicesas well as certain digital infrastructuresThis text, now in the consultation and public hearing phase, designs a very detailed legal framework to strengthen security, guarantee service continuity and minimize the impact of incidents on users, relying on demanding obligations for operators and infrastructure managers.

Why network resilience has become a priority

In recent years, a number of critical episodes such as the COVID-19 pandemic, the eruption of the La Palma volcano, the DANA storm that affected the Valencian Community in 2024, or the April power outage They have put telecommunications infrastructures under immense pressure. In all of them, the same thing became evident: without reliable communications, as happens in cloud service outages, emergency management becomes greatly complicated.

These events have made it clear that networks, electronic communications services, and associated digital infrastructures They are not a luxury, but a essential asset for the functioning of the country in crisis situationsThat is why the Government has decided to formally classify them as essential facilities and services when an emergency is declared.

This rating implies that, in the event of a serious incident, All public administrations and the State Security Forces and Corps must collaborate in the protection, maintenance, and rapid recovery of these networks. It is no longer just a “private” matter for the operators, but a shared responsibility involving national security, civil protection, and the continuity of essential services.

The draft regulation also arises to fill a regulatory gap: until now there were various scattered obligations regarding cybersecurity, critical infrastructure protection, and emergency management, but there was no single standard. unified, updated and specific framework on security and resilience of communications networks and certain strategic digital infrastructures.

Scope of the Royal Decree and who is affected

The draft Royal Decree is aimed at a very specific group of actors, starting with the electronic communications operators that provide services to the public in SpainThis includes the main telecoms (Telefónica, MasOrange, Vodafone, Digi, etc.), but also other smaller companies that meet the established criteria.

In addition to network operators, the regulation also applies to responsible for key digital infrastructuresThese include the submarine cables that connect Spain with other countries, the satellite systems, data centers and internet exchange points (IXPs) that exceed certain relevance thresholds.

Specifically, those who will be subject to these obligations are manage infrastructures with more than 500.000 users or with annual revenues exceeding 50 million eurosAlso included are operators designated as critical by critical infrastructure regulations or those providing emergency services, among other specific cases that meet certain requirements.

The following are explicitly excluded from the scope of the text: networks linked to National Security and Defensewhich are governed by their own specific regulations. This exclusion avoids overlaps with other, more sensitive regulatory frameworks.

It is worth emphasizing that the Royal Decree does not only focus on large backbone networks or the most visible infrastructure; its objective is for every relevant link in the electronic communications chain to adopt security measures and continuity plans aligned with the criticality of your facilities.

Mandatory safety plans and facility classification

One of the central pillars of the new regulations is the obligation for the affected parties to prepare a General Security Plan and, in addition, various specific plans adapted to the characteristics of each network, service and type of incident that they may face.

The General Security Plan must include, at a minimum, a systematic risk analysis that considers natural threats (extreme weather phenomena, floods, fires, earthquakes), technical problems (massive failures, configuration errors, equipment degradation) and intentional threats (cyberattacks, sabotage, intrusions into physical infrastructures).

Based on that analysis, the operator must define the priority measures for prevention, protection, detection and responseThis includes everything from the design of redundant architectures and the diversification of transmission routes, including protocols for action in case of blackouts, internal and external communication plans, and coordination procedures with public authorities.

In addition to the general plan, the following are required Specific plans by network type and service (for example, mobile networks, fixed networks, wholesale services, international segments, etc.), and also by type of incident (power outage, massive software failure, localized natural disaster, widespread cyberattack, etc.). These documents must be adapted to the specific situation and detail responsibilities, reaction times, available backup resources, and traffic prioritization strategies.

A key element of the scheme is the classification of all facilities The operators are categorized at different levels, depending on their criticality and the impact their prolonged downtime would have. Equipment whose unavailability could seriously affect the provision of essential services will be placed at the highest level, while other locations with less impact will be placed at intermediate or basic levels.

Requirements for electrical autonomy and continuity of service

The most demanding – and also the most controversial – part of the draft Royal Decree is the one that establishes the minimum electrical autonomy that the facilities must guarantee In case of a prolonged supply interruption. Here the text is very clear and establishes three levels according to the assigned criticality level.

On the one hand, infrastructures classified as first level They must be capable of continuing to operate for at least 24 hours without power from the conventional electrical grid. This affects central nodes, backbone infrastructure, and locations where a power outage would have a massive impact on connectivity.

On a second level are the intermediate level facilitiesThese sites must guarantee operational continuity for at least 12 hours. They are important locations, but their impact is more limited geographically or in terms of the services affected.

Finally, the remaining facilities – those at the basic level – will need to have resources to maintain a minimum level of service. four hours of electric autonomyAlthough the threshold is lower, it is still a significant leap compared to the current situation in many locations, especially in dense urban environments.

In the specific area of ​​mobile networks, the decree introduces a very specific obligation: that four-hour autonomy must be sufficient to maintain the communications coverage for at least 85% of the populationThis does not mean that each individual antenna has to reach that threshold on its own, but rather that the entire network must be sized so that, during that period, the vast majority of citizens continue to have access to the service, including calls to the 112 emergency number.

To achieve this goal, each operator will have leeway to design their own technology prioritization strategyFor example, it can strengthen the autonomy of key sites, prioritize voice over data, concentrate resources in densely populated areas or particularly sensitive infrastructure (hospitals, emergency coordination centers, critical facilities, etc.). The important thing is that the overall result meets the coverage and continuity requirements.

Estimated costs, industry discussions, and deployment challenges

The report accompanying the draft Royal Decree estimates that total cost of implementing resilience and security measures -primarily those related to reinforcing electrical autonomy- will be between 51 and 73 million euros for the entire mobile communications networks.

According to official estimates, around one 30% of the approximately 10.400 network sites needed to ensure coverage for 85% of the population They already have batteries or generators capable of sustaining service for four hours. This would leave approximately 7.280 sites that would need to be reinforced with new backup solutions.

Taking as a reference a average investment of 7.000 euros per site Including a volume discount of approximately 30%, the government concludes that the total cost would fall within the range of €50,96 million to €72,8 million. The administration maintains that this figure is proportionate and reasonable, especially when compared to the social and economic impact of a widespread disruption to communications.

However, sources within the telecommunications sector itself maintain that the The actual bill could be much higher.easily reaching several hundred million euros. Companies argue that the official estimate underestimates the technical and urban planning complexity of many deployments, especially in large cities where most antennas are installed on building rooftops.

In these urban contexts, the installation of large capacity batteries or generator sets raises space problems, structural overload, and procedures with homeowners' associationsMany roofs are not prepared to withstand the increased load that this equipment entails, forcing reinforcement work or the search for equally or more expensive alternative solutions.

In addition, the companies that own the towers (Cellnex, Vantage Towers, Totem, American Tower, among others) They will not undertake the investment on their own if the contracts with the operators do not guarantee profitability. to offset the expense. In the end, much of that financial effort will end up impacting the balance sheets of telecom companies, already strained by intense competition, price pressures, and the need to continue investing in capacity, 5G, and new features.

From the State's perspective, the Government emphasizes that the The direct budgetary impact will be virtually nil.Since the tasks of supervision, coordination, and response will rely on existing structures and organizations, the possibility of marginal costs related to incident management tools, the development of technical guides, or audit campaigns is acknowledged, but without committing to significant new expenditures unless, in the future, a co-financing program or specific aid becomes available.

112 centers, public alert systems and emergency services

Beyond general connectivity, the text dedicates a special section to the communications related to emergency serviceswith special emphasis on the centers that manage the 112 number and on public alert systems for the population.

These emergency coordination centers, as well as the operators that provide them with connectivity, will be required to develop their own Security Plans, aligned with the operator's General Security Plan but with a very specific focus on the continuity of communications in critical situations.

The goal is that, even in extreme scenarios such as major blackouts, natural disasters, or simultaneous incidents in different parts of the country, the number 112 and the mass notification systems to the public remain operational. Recent experience has shown that without these communications, the capacity of civil protection, police, fire, or emergency medical services is seriously compromised.

The regulation aims to ensure that both 112 centers and the networks that support them have redundancies, alternative routes and sufficient energy autonomyThis aims to avoid single points of failure and minimize downtime. It also seeks to strengthen coordination mechanisms between these centers, operators, and national and regional authorities with emergency responsibilities.

In parallel, provisions are included to ensure that the public alert systems -for example, mass mobile messages in case of imminent catastrophe- maintain their operability under the same demanding conditions required for the rest of the critical services.

Incident notification system and severity classification

Another important section of the Royal Decree is the one relating to security and continuity incident notification procedureThe idea is for the authorities to have reliable and up-to-date information in the shortest possible time in order to coordinate effective responses.

First, operators are required to issue a initial notification within a maximum of one hour From the moment a relevant incident occurs. This early communication does not need to contain all the technical details, but it should provide sufficient information about the preliminary scope, affected services, and possible causes.

From there, they must be sent periodic intermediate notifications They will provide updates on the status of the incident, progress in recovery efforts, and any significant changes in the impact on users. The frequency of these communications will be adjusted according to the magnitude and evolution of the event.

Once the incident is resolved, a final notification that formally closes the information cycle, and at a later date a will have to be prepared Detailed report that thoroughly analyzes the root causes, design or operational failures that may have contributed, the real impact in terms of users and services, and the corrective measures that will be introduced to prevent a recurrence.

The decree also introduces a system of classification of incidents as “significant” or “minor” Based on objective criteria: number of users affected, duration of the disruption, geographical area impacted, and type of service compromised. This classification will help prioritize resources, activate specific protocols, and facilitate coordination with other national and European bodies.

Supervision, institutional coordination and a new Security Committee

La Secretary of State for Telecommunications and Digital Infrastructures It is established as the authority responsible for overseeing compliance with all obligations set forth in the Royal Decree. Its functions include receiving and analyzing incident reports, reviewing security plans, and conducting controls or audits.

This body will also be responsible for coordinate actions with other administrations, both at the state and regional levels, and to coordinate collaboration with European and international entities working on network security, cyber resilience or critical infrastructure protection.

The text foresees the creation of a Coordination table for the security and resilience of electronic communications networks and servicesThis forum aims to function as a permanent space for the exchange of information, technical debate, and monitoring of the implementation of the planned measures.

Representatives from operators, infrastructure managers, regulatory authorities, security forces, and other key stakeholders will be able to participate in this roundtable, with the aim of promote simulation exercises, share best practices and analyze relevant incidents that will allow us to draw lessons for the future.

The existence of this collegiate body has also been a a recurring demand from the telecommunications sector itself, which demanded a stable and structured channel of communication with the administration to address everything related to security and continuity of service.

Consultation process and public hearing for the draft regulation

Before reaching its final approval, the draft Royal Decree is submitted to a dual process of public participation, in accordance with the provisions of the general legislation on administrative procedure and the drafting of regulations.

First, a prior public consultation, whose objective was to gather initial opinions from operators, citizens and any interested party on the need and opportunity to develop specific regulations on the security and resilience of electronic communications networks and certain digital infrastructures.

In this consultation, individuals and entities could send their contributions to the following email address: [email protected]provided they were properly identified and focused their comments on the justification, scope, and general content of the future standard. It was also noted that contributions would be subject to publication, except for those parts expressly marked as confidential.

Having overcome that initial phase, the draft text has been published for public audience during a period extending until January 8, 2026. In this phase, operators, associations, companies and citizens are again invited to formulate more concrete observations on the proposed articles, their specific obligations and their practical feasibility.

Allegations at this stage must be sent to the following email address [email protected]The sender's identity is clearly indicated, and the assessment is limited to the necessity, relevance, or content of the text submitted for consultation. The aim is to ensure that the final result is a technically sound standard, tailored to the realities of the sector and aligned with European standards for cybersecurity and critical infrastructure resilience.

This entire regulatory and procedural framework aims to ensure that, in the face of future crises—whether they arise from or power outages, extreme weather events, technical failures, or large-scale cyberattacks-, the country will have much more robust communications networks and services, with operators obliged to plan and invest in resilience, and with administrations that are better connected, coordinated and prepared to protect infrastructures that have become, without exaggeration, the nervous system of the digital society.

Cloudflare global outage
Related article:
Cloudflare global outage: impact, causes under investigation, and how it affects you

Add as preferred source in Google