Cybersecurity 2026

SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal

3.3 Key Operational Resilience Obligations DORA’s core contribution is not any single obligation but the integrated discipline it imposes across gov - ernance, ICT risk management, incident management and resilience testing. The regulation aims to address a common weakness in financial regulation: sophisti - cated documentation that does not translate into real capability to absorb and recover from disruption. To prevent this, DORA connects operational resilience directly to board accountability, continuous risk gov - ernance, rapid incident classification and reporting, and testing regimes designed to produce practical learning rather than compliance artefacts. Governance: Accountability That Cannot Be Delegated DORA places ICT risk management firmly under the responsibility of the management body. The board (or equivalent) must approve ICT strategy, set ICT risk appetite, allocate adequate resources and receive regular reporting on incidents and testing outcomes. This is not satisfied through occasional “cyber updates”; it requires active, continuous oversight of resilience as a strategic priority. In Spain – where many institutions historically treated technology governance as a management‑level concern – DORA represents a structural shift: resilience becomes a board‑owned obligation with direct consequences for supervisory assessments of governance maturity. ICT Risk Management: A Living Framework DORA requires a comprehensive documented ICT risk management framework, but its defining feature is the emphasis on continuous updating. The framework must reflect the institution’s actual ICT environment as it evolves: new services, architectural changes, shift - ing supply chains and emerging threats. The regula - tory assumption is clear: in a transformation‑heavy sector, a static framework quickly becomes mislead - ing and therefore cannot be relied upon as evidence of genuine control. Incident Classification and Reporting: Speed Over Certainty DORA’s incident regime turns classification into a high‑stakes operational decision. Major incidents are defined using criteria such as client impact, duration, geographic spread, data loss, service criticality and

economic impact. The challenge is not the criteria themselves but applying them during an active inci - dent, when information is incomplete and incentives to delay classification are strongest. DORA deliberate - ly imposes strict timelines: an initial notification must be made within four hours of classifying an incident as major, followed by an intermediate report within 72 hours and a final report within one month. This struc - ture forces institutions to establish predefined deci - sion protocols and ensure that responsible roles are always available, rather than relying on “after action” reporting when facts are clearer. Resilience Testing as Capability Building DORA requires annual basic testing for all in‑scope entities and more demanding threat‑led penetration testing (at least every three years) for significant enti - ties. The regulatory logic is that testing exposes oper - ational realities that policies and audits may overlook. Its value lies in identifying genuine detection gaps, response delays and recovery weaknesses under real - istic conditions – not in producing a “pass” certificate. For supervisors, testing outcomes become evidence of governance seriousness: whether institutions treat resilience as a measurable performance area rather than an abstract policy concept. 3.4 Operational Resilience Enforcement DORA’s enforcement framework is designed to bal - ance credible deterrence with the recognition that resilience gaps are often structural rather than wil - ful. In Spain, the Banco de España , CNMV and DGS - FP hold broad investigative and corrective powers over supervised entities. These include information requests, on‑site inspections, binding remediation orders and administrative sanctions. For critical ICT third‑party providers, the EU Lead Overseer can exercise comparable powers, includ - ing the ability to impose periodic penalty payments for ongoing non‑compliance. The supervisory archi - tecture is deliberately graduated: deficiencies are expected to prompt supervisory engagement and the development of remediation plans before any punitive action is taken. However, the sanctioning framework itself remains meaningful.

336 CHAMBERS.COM

Powered by