Skip to content
Banco de España · EU-wide

DORA in Spain — the sanctions regime, and the extension to payment processors and scheme operators

Fintech Passport
August 17, 2026 · 12-min read
DORA in Spain — the sanctions regime, and the extension to payment processors and scheme operators

DORA does not apply to payment processors and scheme operators — until a member state extends it to them, which is exactly what Spain is proposing to do. The proyecto de ley de digitalización y modernización del sector financiero, published in the Boletín Oficial de las Cortes Generales on 27 July 2026, does two things a payments firm should read closely: it pushes two chapters of Regulation (EU) 2022/2554 outside the population in DORA’s own Article 2, and it writes the Spanish infringement regime for DORA breaches that until now did not exist. This is a bill in parliamentary passage, not law — nothing below is a current obligation, and the numbering can still change.

1. A deliberately partial transposition

The bill’s second final provision states that it partially incorporates Directive (EU) 2022/2556 — the sibling directive that aligned the sectoral financial directives, including PSD2, with DORA — and that full transposition requires a further implementing royal decree. The exposición de motivos says the same in terms. There is no date for that royal decree in the text.

That matters for planning: the graded infringements and the scope extension described below sit in the bill, but the detail expected to sit in the royal decree does not exist yet in any published form. A Spanish firm reading this cannot assume the picture is complete, and should not build a compliance calendar on the assumption that the bill’s entry into force — twenty days after publication in the Boletín Oficial del Estado — is the end of the sequence.

2. The scope extension beyond DORA Article 2

Article 21 of the bill rewrites Article 4 of Real Decreto-ley 8/2023. In its new form it applies to four populations that DORA Article 2 does not itself capture: payment system operators, payment scheme operators, operators of electronic payment arrangements, and payment processors. Two conditions are cumulative — they must provide services in Spain, and they must be subject to supervision or oversight by national authorities.

Those entities must comply with Chapter II of Regulation (EU) 2022/2554, the ICT risk management framework, and Chapter V, Section I, the general principles on managing ICT third-party risk. And the drafting device that makes it work is worth noticing: references in DORA to financial entities are to be read as references to the entities in that paragraph. So an in-scope processor inherits the obligations written for a bank, mediated by proportionality rather than by a separate rulebook.

Facts: a payment processor with no licence of its own runs authorisation and clearing files for Spanish acquirers, and has concluded that DORA reaches it only indirectly, through the ICT third-party contracts its financial-entity clients impose under DORA Article 30.

What the rule says: that conclusion is right under DORA as it stands and wrong under the bill. If the processor provides services in Spain and is subject to national supervision or oversight, the new Article 4 applies Chapter II and Chapter V Section I to it directly, with the Banco de España as competent authority.

What the practitioner does: stops treating the DORA questionnaire from clients as the whole exposure, and runs a gap analysis against Chapter II in its own right — governance and control framework under Article 5, the documented ICT risk management framework under Article 6, systems and tools under Article 7, the asset and dependency mapping under Article 8, incident management under Article 17, classification under Article 18 and reporting under Article 19.

Outcome: the processor discovers its obligations are first-party, not contractual, and that the counterparty that will ask for evidence is a supervisor rather than a client.

3. Proportionality, joint standards, and the simplified framework

The extension is not applied flat. Paragraph 2 states that Chapter II and Chapter V Section I apply in line with the proportionality principle in DORA Article 4, and that the standards developed by the European Supervisory Authorities through the Joint Committee, in consultation with ENISA, under DORA Article 15 also apply to these entities.

It then gives the Banco de España a discretion that is the single most consequential line in the article for a small in-scope firm: it may apply the simplified ICT risk management framework and not require Articles 5 to 15 of the regulation, in accordance with DORA Article 16, to entities falling within DORA Article 16(1) that involve a reduced risk to the payments ecosystem — at that authority’s discretion. Two things follow. The relief is not self-assessed, and it is not automatic for anyone who fits Article 16(1) on size; it turns on the supervisor’s view of risk to the ecosystem.

4. The carve-out at the top of the market

Paragraph 5 excludes payment system operators considered systemically important by the European Central Bank under Regulation (EU) 2025/1355 of 2 July 2025 (ECB/2025/22) on oversight requirements for systemically important payment systems — the recast that replaced Regulation (EU) No 795/2014 and was published in the Official Journal on 14 July 2025.

The logic is that a designated SIPS already carries a Eurosystem oversight regime with its own cyber-resilience and testing expectations, so layering the national extension on top would duplicate it. The practical reading for everyone else is the mirror image: the further you sit from SIPS designation, the more likely the national extension is the regime that actually binds you.

5. The sanctions regime, and who it catches

Article 9 of the bill inserts a new disposición adicional vigesimoquinta into Ley 10/2014, the credit institutions law, dedicated to DORA breaches. Its first paragraph sets the population, and it is broader than “banks”: credit institutions; payment institutions, including those exempt under PSD2; account information service providers; and electronic money institutions, including those exempt under Directive 2009/110/EC — together with the people holding administration or management positions in them. Personal liability is on the face of the provision, not an inference from it.

The route in for e-money institutions is separate and explicit. Article 8 of the bill rewrites Article 23 of Ley 21/2011 so that the new disposición adicional vigesimoquinta regime applies to EMIs’ DORA breaches, and extends the sanctioning regime to third parties to whom the institution has subcontracted operational functions or activities, including third-party ICT service providers. The same article widens the Banco de España’s inspection powers under Article 20(1) of that law to reach group companies and any entity to which activities have been outsourced, including the ICT third-party providers referred to in DORA Chapter V.

One drafting point is worth flagging rather than glossing. The new Article 4(3) and (4) of Real Decreto-ley 8/2023 route the supervision and infringement machinery for the extended population to the disposición adicional vigesimocuarta of Ley 10/2014 — but in the bill as published, that twenty-fourth additional provision is the sanctions regime for Regulation (EU) 2023/1114 (MiCA), and the DORA regime is the twenty-fifth. Anyone reading the two provisions together should check the cross-reference against whatever text emerges from the amendment stage.

6. Very serious, serious, minor — how the line is drawn

The three lists are long and keyed article by article to DORA. What makes them useful rather than decorative is that the same underlying failure appears in more than one grade, separated by a qualifier — most often whether the deficiency significantly compromises the entity’s digital operational resilience objective, or whether it makes the entity vulnerable to a disruptive incident.

GradeRepresentative anchors in the bill’s lists
Very seriousFailure to apply the Article 5 governance and control framework; failure to apply the sound, comprehensive, documented ICT risk management framework under Article 6; ICT systems under Article 7 inadequate to the point of being inoperative; failure to identify, classify or document ICT-supported business functions and assets under Article 8; absence of the Article 10 anomaly-detection mechanisms; failure to apply Article 12 backup and recovery policies; absence of the Article 24 testing programme where that leaves the entity more vulnerable; no threat-led penetration test in a three-year period under Article 26; failure to apply the Article 17 incident management process; documentary deficiencies or substantial delay in reporting major incidents under Article 19; absence of the Article 19 communication to clients whose financial interests are affected
SeriousInadequacy of the Article 17 incident process where it does not seriously hinder detection, management or reporting; delay or incompleteness in the Article 19 client communication; deficiencies in resilience testing under Articles 24 and 25 that do not leave the entity vulnerable to a disruptive incident; failure to observe an Article 28 general principle where non-significant risks may arise on contracts for critical ICT services
MinorPurely formal documentation defects, a late annual review, or purely formal defects in the periodic internal audit of the Article 6 framework; failure to update the Article 11 ICT business continuity policy, or to test continuity and response plans, where resilience is not significantly compromised; failure to test crisis communication plans; Article 28 breaches on non-critical ICT contracts; failure to include the Article 30 minimum contractual content for non-critical ICT services; and a residual catch-all for any DORA breach that is neither very serious nor serious

Facts: an electronic money institution has a written ICT risk management framework, but it was last reviewed two years ago, it has never been through internal audit, and there is no formal process for closing out audit findings.

What the rule says: the very serious list treats a “very serious deficiency” in the Article 6 framework as made out where, among other situations, the framework is not documented or reviewed annually, is not subject to periodic internal audit, or has no formal follow-up process to verify and correct problematic audit findings. The minor list, by contrast, catches a merely late annual review and purely formal audit defects.

What the practitioner does: stops treating “framework exists” as the control and starts evidencing the three named cycle steps — annual documented review, internal audit, closed-loop remediation — because the difference between the minor list and the very serious list is whether those steps happened at all.

Outcome: the remediation plan is about audit trail and cadence, not about rewriting the policy.

7. What the Banco de España can do besides fine you

Paragraph 5 of the new additional provision applies Article 50(3) of Ley 10/2014 and, for anything the provision does not cover, the sanctioning regime in Title IV of that law — the credit-institution regime, imported wholesale. There is no single DORA penalty figure in the bill; the amount depends on the sectoral law that applies to the entity.

On top of that the Banco de España may require the provisional or definitive cessation of any practice it considers contrary to DORA and prevent its repetition; it may require data traffic records held by a telecommunications operator, other than the content of the communication, where there are well-founded indications of a DORA breach and the records may be relevant to the investigation — with prior judicial authorisation required to hand over that data; and it may impose multas coercitivas, periodic penalty payments, under the conditions in the law. In setting the type and level of a sanction it must take into account the circumstances in DORA Article 51(2), and publication follows DORA Article 54.

One governance detail completes the picture. The bill’s sole additional provision makes the Banco de España the national authority whose staff provides Spain’s high-level representative on the DORA Oversight Forum under Article 32(4), with the CNMV and the Dirección General de Seguros y Fondos de Pensiones taking part as observers, and the Banco de España coordinating and facilitating a Spanish position agreed by consensus among the three.

8. FAQ

Does DORA apply to payment processors?

Not under DORA’s own Article 2. The bill would extend Chapter II and Chapter V Section I of Regulation (EU) 2022/2554 to payment processors, payment system operators, payment scheme operators and operators of electronic payment arrangements that provide services in Spain and are subject to national supervision or oversight. That is a national extension, not settled EU law, and it is still a bill.

How large are the fines?

The bill does not set a DORA-specific figure. It imports Article 50(3) and Title IV of Ley 10/2014 for anything the new additional provision does not cover, so the amount turns on the sectoral regime applicable to the entity. The bill does add cease-and-desist powers, multas coercitivas, and publication under DORA Article 54.

Are individual managers exposed?

Yes, on the face of the provision: the new disposición adicional vigesimoquinta names people holding administration or management positions in the listed entities alongside the entities themselves.

Can a small payment institution rely on the simplified framework?

Not by self-assessment. Under the bill the Banco de España may apply the DORA Article 16 simplified framework and not require Articles 5 to 15 for entities within Article 16(1) that involve a reduced risk to the payments ecosystem, at its discretion. Where it applies, the infringement lists narrow substantially.

Does any of this reach our ICT suppliers directly?

For e-money institutions the bill’s rewrite of Article 23 of Ley 21/2011 extends the sanctioning regime to third parties to which operational functions or activities have been subcontracted, including third-party ICT service providers, and widens the Banco de España’s inspection powers to reach them.

Is Spain late on this?

DORA has applied since 17 January 2025 as a regulation, so the substantive obligations do not wait for national law. What the bill supplies is the domestic infringement regime, the competent-authority designations and the scope extension — and it says expressly that the transposition of Directive (EU) 2022/2556 is partial and needs a further royal decree.

9. What to do, today

Three moves are safe to make while the text is still in the Cortes.

  • Settle whether you are in the extended population. The test is not what you call yourself; it is whether you provide services in Spain as a payment system, scheme, electronic payment arrangement operator or processor, and are subject to supervision or oversight by a national authority. Write the answer down with reasons, because it decides whether Chapter II is a first-party obligation or a contractual one.
  • Map your evidence to the grade boundaries, not to DORA generally. The lists turn on qualifiers — documented and reviewed annually, subject to internal audit, with formal follow-up; substantial delay versus delay; critical versus non-critical ICT contracts. Those are the artefacts a file will be judged on.
  • Check the Article 30 contractual minimum on your non-critical ICT contracts. Omitting it is on the minor list, which means it is a named infringement rather than a housekeeping point — and non-critical contracts are where those clauses are usually missing.

Then diarise mid-September. The amendment window closes on 9 September 2026, the bill still goes to the Senado afterwards, and the cross-reference noted in section 5 is exactly the kind of thing that stage exists to fix.

Related: DORA and ZAIT for German payment firms · DORA Article 30 ICT contracts · major ICT incident reporting under PSD2 and DORA · threat-led penetration testing

Related reads.