SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
nisms. The Cyber Solidarity Act introduces an EU‑lev - el layer through the European SOC network and the emergency reserve, strengthening cross‑border situ - ational awareness and response capacity. The effec - tiveness of these mechanisms depends not only on their formal structure but on the timeliness, accuracy, and operational relevance of the intelligence they pro - vide. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation DORA is structurally unusual within EU financial regu - lation because it does not simply impose requirements on supervised financial entities; it also reshapes how the financial system governs the technology providers on which it depends. The regulatory logic is explicit: ICT disruption is no longer merely a firm‑level opera - tional risk but a systemic exposure that can propagate through shared dependencies such as cloud services, core banking systems, managed services, and critical data platforms. Understanding DORA’s scope there - fore requires understanding its ambition to regulate resilience across the financial value chain rather than limiting its reach to the legal perimeter of the regulated institution. The regulated population is deliberately broad. DORA applies across the financial ecosystem, including credit institutions, payment institutions, and electronic money institutions, as well as investment firms, trad - ing venues, central counterparties, insurance and rein - surance undertakings, insurance intermediaries, and IORPs. Its scope extends further to entities whose operational continuity is essential to market integrity, such as central securities depositories, data reporting service providers, credit rating agencies, and statutory auditors. It also captures crypto‑asset service provid - ers authorised under MiCA. This breadth is intentional: DORA is designed around interconnectedness and the understanding that resilience failures in “supporting” functions can still generate market‑wide disruption or consumer harm.
Spain’s implementation is multi‑authority by design. In practice, this means DORA is supervised by different competent authorities depending on the entity type: the Banco de España for credit and payment insti - tutions, the CNMV for investment firms and market infrastructure, and the DGSFP for insurance undertak - ings. This matters operationally because DORA is a horizontal framework, yet supervisory traditions and expectations differ. For institutions operating across subsectors, DORA becomes an exercise in aligning a single ICT risk framework with multiple supervisory interfaces, each with its own culture and reporting cadence. The extension to ICT third‑party service providers is the key innovation in scope. DORA’s most structur - ally significant feature is its two‑layer model for ICT providers. First, all financial entities must manage ICT third‑party relationships under strengthened govern - ance, contractual, and register obligations. Second, for ICT providers designated as critical third‑party providers (CTPPs) by the Joint Supervisory Commit - tee of the ESAs, DORA establishes direct EU‑level oversight by a Lead Overseer (EBA, ESMA, or EIOPA, depending on the predominant sector served). This “reach‑through” model reflects a policy view that cer - tain providers have become part of the EU financial system’s operational infrastructure and therefore can - not remain outside supervision. Extraterritoriality follows from dependency rather than establishment. DORA has a material extraterritorial effect where non‑EU ICT providers supply services to EU financial entities and are designated as CTPPs: they may be required to establish an EU subsidiary within a defined period and submit to EU superviso - ry oversight. The practical implication is that global cloud, data, and technology providers face a compli - ance perimeter defined by their systemic relevance to the EU financial sector rather than their place of incorporation. Proportionality is real but limited. DORA provides simplifications for microenterprises and smaller enti - ties, mainly reducing documentation and governance burdens. However, this is not a substantive exemp - tion: core obligations relating to ICT risk management, incident reporting, and baseline third‑party controls
334 CHAMBERS.COM
Powered by FlippingBook