For: In-house counsel, CTOs, and compliance and risk leads at Spanish fintechs, together with the ICT vendors that support financial institutions.
Goal: A clear, Spain-specific path to DORA compliance in 2026, covering obligations, incident reporting, contractual edits, supervisory expectations and a practical action plan with sample clauses.
DORA compliance Spain has moved from a theoretical regulatory project to an operational reality: the Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, became applicable across the European Union on 17 January 2025, and in 2026 Spanish supervisors are actively testing how financial entities and their technology suppliers have implemented it. For fintechs, payment institutions and the ICT providers that serve them, the question is no longer whether DORA applies, but whether contracts, incident playbooks and resilience testing programmes can withstand supervisory scrutiny from Banco de España and the Comisión Nacional del Mercado de Valores (CNMV).
This guide explains, in practitioner terms, what DORA requires, who is in scope in Spain, how incident reporting works, and which contract clauses need to change.
Five quick takeaways before we dig in:
The Digital Operational Resilience Act is formally Regulation (EU) 2022/2554 of the European Parliament and of the Council. It was adopted as part of the EU’s digital finance package and entered into force in January 2023, with its substantive requirements becoming applicable from 17 January 2025. Because it is a Regulation rather than a Directive, DORA has direct effect in every Member State, including Spain, financial entities and their suppliers must comply with the EU text itself rather than a separately enacted Spanish law.
DORA’s central objective is to create a single, harmonised framework for digital operational resilience across the EU financial sector. Before DORA, ICT risk was addressed through a patchwork of sectoral rules and supervisory guidelines; DORA consolidates these into one binding regime built on five pillars:
In Spain, these obligations map onto the existing supervisory architecture. Banco de España supervises credit institutions and payment service providers, while the CNMV oversees investment firms and market participants. Both act as the national autoridad competente (competent authority) for the entities within their remit, meaning that the EU text of DORA is interpreted and enforced through Spanish supervisory channels. This is the heart of dora compliance spain: an EU rulebook, applied and policed locally.
DORA casts a wide net. It applies to a long list of financial entities and, importantly, reaches the ICT third-party service providers that support them. The following entity types are squarely within scope when established or operating in Spain:
DORA applies a degree of proportionality. The framework allows smaller entities, for example, certain small and non-interconnected investment firms, small institutions for occupational retirement provision and micro-enterprises, to apply a simplified ICT risk management framework. The obligations therefore scale with an entity’s size, risk profile and systemic importance, but very few financial entities fall entirely outside the regime. Note that certain categories benefit from specific exemptions under DORA itself; scoping should be confirmed against the Regulation’s text and supervisory guidance.
| Entity type | Core DORA obligations |
|---|---|
| Credit institution | Full ICT risk framework, incident reporting, resilience testing (including threat-led penetration testing where designated), third-party risk register |
| Payment / e-money institution | Full framework; incident reporting; outsourcing contract controls; proportionate testing |
| Investment firm | Full or simplified framework depending on size; CNMV as competent authority |
| Crypto-asset service provider | Full framework; incident reporting; third-party controls |
| Small / micro financial entity | Simplified ICT risk management framework; proportionate obligations |
| ICT third-party provider | Contractual obligations via clients; direct EU oversight if designated “critical” |
A crucial point for vendors: ICT providers are not generally subject to the full DORA framework in their own right, but they are bound by it indirectly through the mandatory contractual terms their financial-entity clients must impose. Providers designated as critical ICT third-party service providers are an exception, they are placed under a direct EU oversight regime led by the European Supervisory Authorities.
Achieving dora compliance spain means implementing a connected set of technical and organisational controls. The sections below walk through the core obligations.
DORA requires each in-scope entity to maintain a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system. The framework must enable the entity to address ICT risk quickly, efficiently and comprehensively, and to ensure a high level of digital operational resilience. In practice this covers the familiar lifecycle: identify ICT-supported business functions and assets; protect them with appropriate security policies and controls; detect anomalous activity; respond and recover through business continuity and disaster recovery plans; and learn and evolve from incidents and tests.
Governance sits at the centre. The management body, the board or equivalent, bears ultimate responsibility for ICT risk and must define, approve, oversee and remain accountable for the framework. Board members are expected to maintain sufficient knowledge to understand and assess ICT risk and its impact. For Spanish entities, this means ICT resilience cannot be delegated wholesale to the IT function; it must be documented, owned at board level, and reviewed at least annually and after major incidents. Entities must also maintain business continuity policies, backup procedures, and recovery plans with clearly defined recovery objectives.
DORA obliges entities to establish and implement an ICT-related incident management process to detect, manage and notify incidents, and to classify them according to criteria set out in the Regulation and its technical standards. Major incidents trigger mandatory reporting to the competent authority on a staged basis. Because this is the area attracting the most supervisory attention in Spain, it is covered in detail in its own section below.
Entities must establish a sound and comprehensive digital operational resilience testing programme as an integral part of their ICT risk management framework. At a baseline, all in-scope entities must perform a range of appropriate tests, such as vulnerability assessments, scans, network security assessments, gap analyses, physical security reviews, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing and penetration testing. ICT tools and systems supporting critical or important functions must be tested at least annually.
A more demanding layer applies to significant entities: threat-led penetration testing (TLPT). Entities identified by competent authorities as needing to carry out TLPT must do so at least every three years, using testers who meet strict independence and competence requirements. The testing must cover several or all critical or important functions and be performed on live production systems. For Spanish firms, competent authorities will identify which entities fall into the TLPT population, so part of the compliance exercise is confirming your testing tier with Banco de España or the CNMV as relevant.
DORA treats dependency on ICT providers as a core source of systemic risk. Entities must manage ICT third-party risk as an integral component of their framework, maintain a register of information covering all contractual arrangements for the use of ICT services, and assess concentration risk before entering into arrangements. Before contracting, they must conduct due diligence, and before entering arrangements supporting critical or important functions, they must assess sub-outsourcing chains and exit strategies. These requirements flow directly into contract drafting, which the next section addresses in full.
The most immediate, concrete step towards dora compliance spain is revisiting ICT outsourcing contracts. DORA prescribes minimum contractual content for arrangements with ICT third-party providers, with enhanced requirements where the service supports a critical or important function. Financial entities are the ones legally obliged to secure these terms, but vendors should expect, and prepare for, repapering requests throughout 2026.
Use the following checklist when reviewing or redlining an ICT outsourcing agreement. The clause descriptions below are sample language for illustrative purposes only and do not constitute bespoke legal advice.
Practical tip: rather than amend each contract individually, many Spanish financial entities are deploying a DORA addendum or standardised annex that layers the mandatory terms over existing master agreements. This accelerates repapering and gives supervisors a consistent, auditable artefact. Vendors who proactively draft a DORA-ready annex pack, covering audit, termination and testing rights, can differentiate themselves and shorten sales cycles with regulated clients.
Incident reporting is where theory meets the clock. DORA requires financial entities to classify ICT-related incidents and to report major ICT-related incidents to the relevant competent authority. A “major” incident is one that meets the materiality thresholds defined in DORA and its regulatory technical standards, assessed against criteria such as the number of clients and financial counterparts affected, data losses, geographical spread, duration and service downtime, economic impact and reputational effect.
DORA establishes a staged, time-bound reporting model. Rather than a single deadline, entities submit a sequence of notifications to the competent authority:
The precise time-based deadlines for each stage are fixed by the regulatory and implementing technical standards that supplement DORA, and the specific submission channels and templates are operated through the competent authority. Because DORA leaves certain procedural details to be specified by these standards and by competent authorities, Spanish entities should confirm current deadlines and reporting templates directly through Banco de España or the CNMV according to their supervisor, and monitor the European Supervisory Authorities’ materials on operational resilience for updated technical guidance.
To be ready, every in-scope entity should maintain a tested incident playbook that pre-maps the data fields DORA requires, incident identification and classification, affected functions and services, number of users and counterparts impacted, start time and duration, economic and reputational impact, actions taken, and root-cause findings. A rehearsed internal workflow, with named decision-makers empowered to classify an incident as “major” and trigger the reporting clock, is the single most valuable preparation a Spanish fintech can make. Where an incident also involves personal data, a parallel notification pathway to the Agencia Española de Protección de Datos (AEPD) may be required, as discussed below.
DORA does not operate in isolation. Companies serving financial entities in Spain frequently sit at the intersection of several EU regimes, and understanding the overlap is essential for correct scoping. As a general principle, DORA acts as lex specialis for the financial sector in relation to ICT risk: where DORA applies, its specific ICT and incident rules generally take precedence over the more general cyber rules for the relevant entities. GDPR obligations on personal data, however, apply in parallel and are not displaced.
| Regime | Primary scope | Key obligations for ICT providers | Incident reporting | Lead regulator (Spain) |
|---|---|---|---|---|
| DORA (Reg. (EU) 2022/2554) | Financial entities and their ICT providers | Contractual controls; cooperation on testing and incidents; direct oversight if “critical” | Staged reporting of major ICT incidents to competent authority | Banco de España / CNMV |
| NIS2 Directive | Essential and important entities across critical sectors | Cybersecurity risk management and supply-chain security measures | Early warning and incident notification to national CSIRT/authority | National competent authorities / CSIRT |
| GDPR (Reg. (EU) 2016/679) | Any processing of personal data | Processor obligations; security of processing; breach assistance | Personal data breach notification (generally within 72 hours) | AEPD |
| Cyber Resilience Act (CRA) | Manufacturers of products with digital elements | Security-by-design, vulnerability handling for hardware/software products | Reporting of actively exploited vulnerabilities and incidents | Market surveillance authorities |
For a SaaS or ICT provider in Spain, the practical scoping exercise is to map each regime against your activity. If you supply services to regulated financial entities, DORA’s contractual obligations will reach you through your clients. If your organisation independently qualifies as an essential or important entity under NIS2, you carry direct cybersecurity duties. If you process personal data, GDPR applies regardless. And if you manufacture products with digital elements, the CRA’s security-by-design and vulnerability-handling obligations come into play (noting that the CRA’s main obligations are phased in over a transitional period). Many providers will sit under two or more regimes simultaneously, which is why a consolidated compliance register, mapping obligations, deadlines and lead regulators, is a worthwhile investment.
In 2026, DORA compliance in Spain is being embedded into live supervisory practice. Banco de España, as the competent authority for credit institutions and payment service providers, and the CNMV, for investment firms and market participants, are the entities that will request evidence of compliance during inspections and ongoing supervision. The AEPD remains the data protection authority where incidents touch personal data.
During supervisory engagement, entities should expect requests covering:
DORA provides that competent authorities have supervisory and enforcement powers, including the ability to require entities to adopt measures to remedy breaches and to impose administrative penalties and remedial measures proportionate to the infringement. For critical ICT third-party providers under the direct EU oversight regime, the Lead Overseer can impose periodic penalty payments to compel compliance. Because specific penalty levels and enforcement decisions in Spain will depend on the measures each supervisor adopts under its national powers, entities should treat published supervisory statements from Banco de España and the CNMV as the authoritative source for current expectations.
Consider an illustrative scenario: a mid-sized Spanish payment institution relies on a cloud provider for its core ledger. During a routine inspection, Banco de España asks for the DORA contractual annex and the exit plan. If the contract lacks audit rights or a tested exit strategy, the institution faces a remediation demand, a repapering exercise under time pressure, and heightened scrutiny of its wider third-party estate. The lesson is that supervisory readiness is as much about documentation and evidence as about the underlying controls.
For fintechs and ICT providers that need to close gaps quickly, the following phased plan structures the work into a manageable sequence. Treat it as a starting framework to adapt to your size and risk profile.
Resourcing matters: this is not an IT-only project. The most successful programmes pair legal and procurement expertise (for the contractual repapering) with security and operations expertise (for testing and incident response), under clear board accountability. ICT providers should mirror this by preparing a client-facing DORA annex pack and standing cooperation procedures, so they can respond to repapering requests at scale rather than negotiating each one from scratch.
DORA compliance Spain is now a core operational discipline for every fintech, financial entity and ICT provider operating in the Spanish market. With DORA applicable since 17 January 2025 and Spanish supervisors actively testing implementation through 2026, the priorities are clear: document a board-owned ICT risk framework, repaper outsourcing contracts to include the mandatory DORA terms, build and rehearse a staged incident-reporting playbook, and run resilience testing with the evidence to prove it. The organisations that treat operational resilience in Spain as an integrated legal and technical programme, rather than a box-ticking exercise, will be the ones that pass supervisory scrutiny and win trust with regulated clients.
If you are unsure where your gaps lie, start with a focused scope-and-contract review, then work methodically through the roadmap above.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.
posted 3 minutes ago
posted 22 minutes ago
posted 29 minutes ago
posted 43 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message