[codicts-css-switcher id=”346″]

Global Law Experts Logo
dora compliance spain

Our Expert in Spain

  • GOLD

DORA Compliance Spain: 2026 Requirements for Fintechs & ICT Providers

By Global Law Experts
– posted 2 hours ago

For: In-house counsel, CTOs, and compliance and risk leads at Spanish fintechs, together with the ICT vendors that support financial institutions.

Goal: A clear, Spain-specific path to DORA compliance in 2026, covering obligations, incident reporting, contractual edits, supervisory expectations and a practical action plan with sample clauses.

Why DORA compliance Spain matters in 2026

DORA compliance Spain has moved from a theoretical regulatory project to an operational reality: the Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, became applicable across the European Union on 17 January 2025, and in 2026 Spanish supervisors are actively testing how financial entities and their technology suppliers have implemented it. For fintechs, payment institutions and the ICT providers that serve them, the question is no longer whether DORA applies, but whether contracts, incident playbooks and resilience testing programmes can withstand supervisory scrutiny from Banco de España and the Comisión Nacional del Mercado de Valores (CNMV).

This guide explains, in practitioner terms, what DORA requires, who is in scope in Spain, how incident reporting works, and which contract clauses need to change.

Five quick takeaways before we dig in:

  • Directly applicable law. DORA is an EU Regulation, so it applies directly in Spain without a national transposition statute, there is no local act to wait for.
  • Everyone in the chain is affected. Financial entities carry the primary obligations, but ICT third-party providers feel DORA through mandatory contractual controls, and critical providers face direct oversight.
  • Incident reporting is tightly time-boxed. Major ICT-related incidents must be reported to the competent authority on a staged basis with defined deadlines.
  • Contracts must be rewritten. Outsourcing agreements need audit rights, exit plans, sub-outsourcing transparency and resilience testing provisions to be DORA-ready.
  • Spanish supervision is live. Banco de España and the CNMV are embedding DORA into their inspection practice, so gaps carry real enforcement risk.

What is DORA? The EU regulation and its legal status

The Digital Operational Resilience Act is formally Regulation (EU) 2022/2554 of the European Parliament and of the Council. It was adopted as part of the EU’s digital finance package and entered into force in January 2023, with its substantive requirements becoming applicable from 17 January 2025. Because it is a Regulation rather than a Directive, DORA has direct effect in every Member State, including Spain, financial entities and their suppliers must comply with the EU text itself rather than a separately enacted Spanish law.

DORA’s central objective is to create a single, harmonised framework for digital operational resilience across the EU financial sector. Before DORA, ICT risk was addressed through a patchwork of sectoral rules and supervisory guidelines; DORA consolidates these into one binding regime built on five pillars:

  • ICT risk management. A governance-led framework to identify, protect against, detect, respond to and recover from ICT-related disruptions.
  • ICT-related incident management and reporting. Standardised classification and reporting of major incidents to competent authorities.
  • Digital operational resilience testing. Regular testing of ICT systems, including advanced threat-led penetration testing for certain entities.
  • ICT third-party risk management. Rules governing outsourcing to, and dependency on, ICT service providers, including mandatory contractual content.
  • Information sharing. Voluntary arrangements for exchanging cyber threat intelligence among financial entities.

In Spain, these obligations map onto the existing supervisory architecture. Banco de España supervises credit institutions and payment service providers, while the CNMV oversees investment firms and market participants. Both act as the national autoridad competente (competent authority) for the entities within their remit, meaning that the EU text of DORA is interpreted and enforced through Spanish supervisory channels. This is the heart of dora compliance spain: an EU rulebook, applied and policed locally.

Who is in scope in Spain, financial entities and ICT providers

DORA casts a wide net. It applies to a long list of financial entities and, importantly, reaches the ICT third-party service providers that support them. The following entity types are squarely within scope when established or operating in Spain:

  • Credit institutions (banks)
  • Payment institutions and account information service providers
  • Electronic money institutions
  • Investment firms
  • Crypto-asset service providers authorised under MiCA and issuers of asset-referenced tokens
  • Central securities depositories and central counterparties
  • Trading venues and trade repositories
  • Managers of alternative investment funds and UCITS management companies
  • Insurance and reinsurance undertakings, and insurance intermediaries
  • Crowdfunding service providers
  • ICT third-party service providers, where they provide services to the above

DORA applies a degree of proportionality. The framework allows smaller entities, for example, certain small and non-interconnected investment firms, small institutions for occupational retirement provision and micro-enterprises, to apply a simplified ICT risk management framework. The obligations therefore scale with an entity’s size, risk profile and systemic importance, but very few financial entities fall entirely outside the regime. Note that certain categories benefit from specific exemptions under DORA itself; scoping should be confirmed against the Regulation’s text and supervisory guidance.

Entity type Core DORA obligations
Credit institution Full ICT risk framework, incident reporting, resilience testing (including threat-led penetration testing where designated), third-party risk register
Payment / e-money institution Full framework; incident reporting; outsourcing contract controls; proportionate testing
Investment firm Full or simplified framework depending on size; CNMV as competent authority
Crypto-asset service provider Full framework; incident reporting; third-party controls
Small / micro financial entity Simplified ICT risk management framework; proportionate obligations
ICT third-party provider Contractual obligations via clients; direct EU oversight if designated “critical”

A crucial point for vendors: ICT providers are not generally subject to the full DORA framework in their own right, but they are bound by it indirectly through the mandatory contractual terms their financial-entity clients must impose. Providers designated as critical ICT third-party service providers are an exception, they are placed under a direct EU oversight regime led by the European Supervisory Authorities.

Key DORA requirements: technical and organisational measures

Achieving dora compliance spain means implementing a connected set of technical and organisational controls. The sections below walk through the core obligations.

ICT risk management framework

DORA requires each in-scope entity to maintain a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system. The framework must enable the entity to address ICT risk quickly, efficiently and comprehensively, and to ensure a high level of digital operational resilience. In practice this covers the familiar lifecycle: identify ICT-supported business functions and assets; protect them with appropriate security policies and controls; detect anomalous activity; respond and recover through business continuity and disaster recovery plans; and learn and evolve from incidents and tests.

Governance sits at the centre. The management body, the board or equivalent, bears ultimate responsibility for ICT risk and must define, approve, oversee and remain accountable for the framework. Board members are expected to maintain sufficient knowledge to understand and assess ICT risk and its impact. For Spanish entities, this means ICT resilience cannot be delegated wholesale to the IT function; it must be documented, owned at board level, and reviewed at least annually and after major incidents. Entities must also maintain business continuity policies, backup procedures, and recovery plans with clearly defined recovery objectives.

ICT incident management and reporting

DORA obliges entities to establish and implement an ICT-related incident management process to detect, manage and notify incidents, and to classify them according to criteria set out in the Regulation and its technical standards. Major incidents trigger mandatory reporting to the competent authority on a staged basis. Because this is the area attracting the most supervisory attention in Spain, it is covered in detail in its own section below.

Digital operational resilience testing

Entities must establish a sound and comprehensive digital operational resilience testing programme as an integral part of their ICT risk management framework. At a baseline, all in-scope entities must perform a range of appropriate tests, such as vulnerability assessments, scans, network security assessments, gap analyses, physical security reviews, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing and penetration testing. ICT tools and systems supporting critical or important functions must be tested at least annually.

A more demanding layer applies to significant entities: threat-led penetration testing (TLPT). Entities identified by competent authorities as needing to carry out TLPT must do so at least every three years, using testers who meet strict independence and competence requirements. The testing must cover several or all critical or important functions and be performed on live production systems. For Spanish firms, competent authorities will identify which entities fall into the TLPT population, so part of the compliance exercise is confirming your testing tier with Banco de España or the CNMV as relevant.

ICT third-party risk management and contractual controls

DORA treats dependency on ICT providers as a core source of systemic risk. Entities must manage ICT third-party risk as an integral component of their framework, maintain a register of information covering all contractual arrangements for the use of ICT services, and assess concentration risk before entering into arrangements. Before contracting, they must conduct due diligence, and before entering arrangements supporting critical or important functions, they must assess sub-outsourcing chains and exit strategies. These requirements flow directly into contract drafting, which the next section addresses in full.

ICT third-party risk and outsourcing contracts, a Spain practical checklist

The most immediate, concrete step towards dora compliance spain is revisiting ICT outsourcing contracts. DORA prescribes minimum contractual content for arrangements with ICT third-party providers, with enhanced requirements where the service supports a critical or important function. Financial entities are the ones legally obliged to secure these terms, but vendors should expect, and prepare for, repapering requests throughout 2026.

Use the following checklist when reviewing or redlining an ICT outsourcing agreement. The clause descriptions below are sample language for illustrative purposes only and do not constitute bespoke legal advice.

  • Clear service description and locations. A full description of functions and services, and an indication of the countries and locations where services are provided and where data is processed or stored. Sample: “The Provider shall perform the Services from the locations listed in Annex A and shall notify the Client in advance of any proposed change of processing location.”
  • Service levels, RTO and RPO. Define Recovery Time Objective (RTO, the maximum tolerable time to restore a service) and Recovery Point Objective (RPO, the maximum tolerable data loss measured in time), with measurable KPIs and remedies for breach.
  • Audit and inspection rights. Unrestricted rights of access, inspection and audit for the financial entity and the competent authority, including on-premises inspections. Sample: “The Provider grants the Client, its appointed auditors and the competent authority full rights of access, inspection and audit in relation to the Services.”
  • Access to data and logs. Rights of access to relevant information, security logs and documentation necessary to monitor the service and demonstrate compliance.
  • Sub-outsourcing transparency. Conditions under which sub-contracting of ICT services supporting critical or important functions is permitted, prior notification of material changes, and the right to object. Visibility over the full supply chain is required.
  • Resilience testing cooperation. An obligation on the provider to participate in, and fully cooperate with, the financial entity’s digital operational resilience testing, including TLPT where applicable.
  • Security obligations. Commitments to implement and maintain appropriate information security standards, incident cooperation, and support during ICT incidents, including assistance with incident reporting.
  • Termination and exit planning. Clear termination rights (including for supervisory reasons), transition assistance, and a documented exit strategy ensuring continuity and orderly migration. Sample: “On termination for any reason, the Provider shall provide transition assistance for a minimum period of [X] months and return or securely delete Client data in a usable, portable format.”
  • Data portability and return. Guaranteed return or portability of data in a structured, commonly used machine-readable format on exit.
  • Cross-border data transfer controls. Safeguards for transfers outside the EEA, aligned with GDPR, with transparency over processing locations.
  • Local or EU point of contact. For material arrangements, a designated contact to interface with the Spanish financial entity and, where relevant, the competent authority.

Practical tip: rather than amend each contract individually, many Spanish financial entities are deploying a DORA addendum or standardised annex that layers the mandatory terms over existing master agreements. This accelerates repapering and gives supervisors a consistent, auditable artefact. Vendors who proactively draft a DORA-ready annex pack, covering audit, termination and testing rights, can differentiate themselves and shorten sales cycles with regulated clients.

Incident reporting under DORA, timelines, thresholds and Spanish supervisory practice

Incident reporting is where theory meets the clock. DORA requires financial entities to classify ICT-related incidents and to report major ICT-related incidents to the relevant competent authority. A “major” incident is one that meets the materiality thresholds defined in DORA and its regulatory technical standards, assessed against criteria such as the number of clients and financial counterparts affected, data losses, geographical spread, duration and service downtime, economic impact and reputational effect.

DORA establishes a staged, time-bound reporting model. Rather than a single deadline, entities submit a sequence of notifications to the competent authority:

  • Initial notification. Submitted after the incident has been classified as major, within the deadline set in the applicable technical standards.
  • Intermediate report. Provided once the situation has materially changed or recovery activities are under way, updating the authority on status and impact.
  • Final report. Delivered when the root-cause analysis is complete and the actual impact figures are available, regardless of whether mitigation measures have been fully implemented.

The precise time-based deadlines for each stage are fixed by the regulatory and implementing technical standards that supplement DORA, and the specific submission channels and templates are operated through the competent authority. Because DORA leaves certain procedural details to be specified by these standards and by competent authorities, Spanish entities should confirm current deadlines and reporting templates directly through Banco de España or the CNMV according to their supervisor, and monitor the European Supervisory Authorities’ materials on operational resilience for updated technical guidance.

To be ready, every in-scope entity should maintain a tested incident playbook that pre-maps the data fields DORA requires, incident identification and classification, affected functions and services, number of users and counterparts impacted, start time and duration, economic and reputational impact, actions taken, and root-cause findings. A rehearsed internal workflow, with named decision-makers empowered to classify an incident as “major” and trigger the reporting clock, is the single most valuable preparation a Spanish fintech can make. Where an incident also involves personal data, a parallel notification pathway to the Agencia Española de Protección de Datos (AEPD) may be required, as discussed below.

DORA compliance Spain and its interaction with NIS2, GDPR and the Cyber Resilience Act

DORA does not operate in isolation. Companies serving financial entities in Spain frequently sit at the intersection of several EU regimes, and understanding the overlap is essential for correct scoping. As a general principle, DORA acts as lex specialis for the financial sector in relation to ICT risk: where DORA applies, its specific ICT and incident rules generally take precedence over the more general cyber rules for the relevant entities. GDPR obligations on personal data, however, apply in parallel and are not displaced.

Regime Primary scope Key obligations for ICT providers Incident reporting Lead regulator (Spain)
DORA (Reg. (EU) 2022/2554) Financial entities and their ICT providers Contractual controls; cooperation on testing and incidents; direct oversight if “critical” Staged reporting of major ICT incidents to competent authority Banco de España / CNMV
NIS2 Directive Essential and important entities across critical sectors Cybersecurity risk management and supply-chain security measures Early warning and incident notification to national CSIRT/authority National competent authorities / CSIRT
GDPR (Reg. (EU) 2016/679) Any processing of personal data Processor obligations; security of processing; breach assistance Personal data breach notification (generally within 72 hours) AEPD
Cyber Resilience Act (CRA) Manufacturers of products with digital elements Security-by-design, vulnerability handling for hardware/software products Reporting of actively exploited vulnerabilities and incidents Market surveillance authorities

For a SaaS or ICT provider in Spain, the practical scoping exercise is to map each regime against your activity. If you supply services to regulated financial entities, DORA’s contractual obligations will reach you through your clients. If your organisation independently qualifies as an essential or important entity under NIS2, you carry direct cybersecurity duties. If you process personal data, GDPR applies regardless. And if you manufacture products with digital elements, the CRA’s security-by-design and vulnerability-handling obligations come into play (noting that the CRA’s main obligations are phased in over a transitional period). Many providers will sit under two or more regimes simultaneously, which is why a consolidated compliance register, mapping obligations, deadlines and lead regulators, is a worthwhile investment.

Supervisory expectations and enforcement in Spain (2026 focus)

In 2026, DORA compliance in Spain is being embedded into live supervisory practice. Banco de España, as the competent authority for credit institutions and payment service providers, and the CNMV, for investment firms and market participants, are the entities that will request evidence of compliance during inspections and ongoing supervision. The AEPD remains the data protection authority where incidents touch personal data.

During supervisory engagement, entities should expect requests covering:

  • Evidence of a documented, board-approved ICT risk management framework and governance records.
  • The register of information covering all ICT third-party arrangements, including identification of those supporting critical or important functions.
  • Updated outsourcing contracts demonstrating the mandatory DORA clauses, with particular attention to audit rights, sub-outsourcing and exit strategies.
  • The incident classification and reporting procedure, together with records of any major incidents and their staged reports.
  • The digital operational resilience testing programme, test results, and remediation of findings, plus TLPT where the entity is in that population.

DORA provides that competent authorities have supervisory and enforcement powers, including the ability to require entities to adopt measures to remedy breaches and to impose administrative penalties and remedial measures proportionate to the infringement. For critical ICT third-party providers under the direct EU oversight regime, the Lead Overseer can impose periodic penalty payments to compel compliance. Because specific penalty levels and enforcement decisions in Spain will depend on the measures each supervisor adopts under its national powers, entities should treat published supervisory statements from Banco de España and the CNMV as the authoritative source for current expectations.

Consider an illustrative scenario: a mid-sized Spanish payment institution relies on a cloud provider for its core ledger. During a routine inspection, Banco de España asks for the DORA contractual annex and the exit plan. If the contract lacks audit rights or a tested exit strategy, the institution faces a remediation demand, a repapering exercise under time pressure, and heightened scrutiny of its wider third-party estate. The lesson is that supervisory readiness is as much about documentation and evidence as about the underlying controls.

A practical 90-day compliance roadmap for dora compliance spain

For fintechs and ICT providers that need to close gaps quickly, the following phased plan structures the work into a manageable sequence. Treat it as a starting framework to adapt to your size and risk profile.

  1. Days 1–30, Scope and gap analysis. Confirm whether you are a financial entity, an ICT provider, or both. Build the register of information for all ICT arrangements. Run a gap analysis against the five DORA pillars. Identify which contracts support critical or important functions and prioritise them. Establish board sponsorship and a cross-functional working group spanning legal, compliance, IT security and procurement.
  2. Days 31–60, Remediate contracts and incident readiness. Deploy a standardised DORA addendum and begin repapering priority vendor contracts, focusing on audit rights, sub-outsourcing transparency, exit planning and testing cooperation. Draft or refresh the incident classification and reporting playbook, pre-mapping DORA data fields and naming the decision-makers who can declare a major incident. Confirm reporting channels and current deadlines with your competent authority.
  3. Days 61–90, Test, document and evidence. Execute baseline resilience tests on systems supporting critical or important functions and remediate findings. Confirm whether you fall into the TLPT population. Assemble a supervisory evidence pack, framework documentation, register, updated contracts, incident playbook and test results, ready for inspection. Schedule the annual review cycle and assign ongoing ownership.

Resourcing matters: this is not an IT-only project. The most successful programmes pair legal and procurement expertise (for the contractual repapering) with security and operations expertise (for testing and incident response), under clear board accountability. ICT providers should mirror this by preparing a client-facing DORA annex pack and standing cooperation procedures, so they can respond to repapering requests at scale rather than negotiating each one from scratch.

Conclusion and next steps

DORA compliance Spain is now a core operational discipline for every fintech, financial entity and ICT provider operating in the Spanish market. With DORA applicable since 17 January 2025 and Spanish supervisors actively testing implementation through 2026, the priorities are clear: document a board-owned ICT risk framework, repaper outsourcing contracts to include the mandatory DORA terms, build and rehearse a staged incident-reporting playbook, and run resilience testing with the evidence to prove it. The organisations that treat operational resilience in Spain as an integrated legal and technical programme, rather than a box-ticking exercise, will be the ones that pass supervisory scrutiny and win trust with regulated clients.

If you are unsure where your gaps lie, start with a focused scope-and-contract review, then work methodically through the roadmap above.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. EUR-Lex, Regulation (EU) 2022/2554 (DORA)
  2. European Commission, Digital Operational Resilience Act (DORA)
  3. European Banking Authority
  4. Banco de España
  5. Comisión Nacional del Mercado de Valores (CNMV)
  6. Agencia Española de Protección de Datos (AEPD)

FAQs

What is DORA and does it apply to Spanish fintechs?
DORA is the Digital Operational Resilience Act, Regulation (EU) 2022/2554, applicable across the EU since 17 January 2025. As an EU Regulation it has direct effect in Spain, so Spanish fintechs that are financial entities, including payment institutions and crypto-asset service providers, are in scope and must comply with its ICT risk, incident reporting, testing and third-party requirements. See the EUR-Lex text for the full legal framework.
For most ICT providers, DORA applies indirectly through the mandatory contractual terms their financial-entity clients must impose, covering audit, sub-outsourcing, testing and exit rights. However, providers designated as critical ICT third-party service providers are placed under a direct EU oversight regime led by the European Supervisory Authorities, which brings direct obligations and potential penalty payments.
DORA uses a staged model: an initial notification once an incident is classified as major, an intermediate report as the situation develops, and a final report after root-cause analysis. The exact deadlines are set in the technical standards supplementing DORA and operated through the competent authority. Spanish entities should confirm current deadlines and templates with Banco de España or the CNMV.
At minimum, outsourcing contracts should address: (1) clear service and location descriptions; (2) service levels with RTO and RPO; (3) audit and inspection rights for the entity and the competent authority; (4) sub-outsourcing transparency; (5) resilience-testing cooperation; and (6) termination, exit planning and data portability. See the contract checklist in this guide for illustrative sample language.
Both regimes apply in parallel. DORA governs the reporting of major ICT-related incidents to the financial competent authority, while GDPR governs personal data breach notification, generally within 72 hours to the supervisory authority, the AEPD in Spain, where the breach is likely to risk individuals’ rights. Entities must satisfy both pathways, so incident playbooks should map DORA and GDPR reporting triggers side by side.
All in-scope entities must test ICT tools and systems supporting critical or important functions at least annually, using methods such as vulnerability assessments and penetration testing. Entities identified by competent authorities as requiring threat-led penetration testing must carry it out at least every three years, using testers meeting strict independence and competence requirements. Consult the European Supervisory Authorities’ operational resilience materials for technical detail.
The authoritative legal text is Regulation (EU) 2022/2554 on EUR-Lex. Policy background is published by the European Commission, and technical and supervisory convergence materials by the European Supervisory Authorities (including the European Banking Authority). For Spain-specific supervisory expectations, consult Banco de España, the CNMV and, for data protection intersections, the AEPD.
challenge annul shareholder resolutions polish sp
By Wojciech Kowalczuk

posted 29 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

DORA Compliance Spain: 2026 Requirements for Fintechs & ICT Providers

Send welcome message

Custom Message