{"id":19688,"date":"2025-12-15T08:00:17","date_gmt":"2025-12-15T08:00:17","guid":{"rendered":"https:\/\/letslaw.es\/reglamento-dora-sector-financiero\/"},"modified":"2025-12-15T15:56:43","modified_gmt":"2025-12-15T15:56:43","slug":"dora-regulation-financial-sector","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/dora-regulation-financial-sector\/","title":{"rendered":"The DORA Regulation: legal implications for ICT risk management in the financial sector"},"content":{"rendered":"<p>Regulation (EU) 2022\/2554, known as DORA (Digital Operational Resilience Act), has been fully applicable since 17 January 2025 and marks a <strong>milestone in the regulation of digital operational resilience within the European financial sector<\/strong>. Its purpose is to strengthen the ability of entities to prevent, withstand, respond to, and recover from incidents related to information and communication technologies.<\/p>\n<p>To understand the true scope of this Regulation and its obligations, it is essential to analyse its subjective scope of application, the elements required to prepare for an audit, and the legal implications of non-compliance.<\/p>\n<h2>Who must comply?<\/h2>\n<p>The scope of application of the Regulation is set out in Article 2, which includes <strong>more than twenty categories of financial entities subject to European supervision<\/strong>. These include credit institutions, investment firms, payment institutions and electronic money institutions, insurance and reinsurance undertakings, fund management companies, and market infrastructures such as trading venues and clearing houses. Also covered by DORA are crypto-asset service providers and certain providers of financial data services. This breadth makes DORA one of the most transversal regulatory frameworks in European financial law.<\/p>\n<p>Although the Regulation expressly refers to external ICT service providers, <strong>the primary responsibility for compliance lies with financial entities<\/strong>, which must effectively manage and supervise the risks associated with these third parties. Article 28 and the following provisions establish that financial entities must comprehensively manage the risks arising from the use of third-party ICT services. This includes maintaining a full register of ICT agreements, identifying those supporting critical or important functions, and ensuring that contracts include minimum requirements on security, audit rights, access, data localisation, and subcontracting. When a provider is designated as \u201ccritical\u201d, it becomes subject to the supervision regime under Chapter V, coordinated by the EBA, ESMA, or EIOPA.<\/p>\n<p>In Spain, this oversight is aligned with guidelines and <strong>criteria issued by the Bank of Spain, the CNMV, and the DGSFP<\/strong>, which have strengthened monitoring of ICT operational risk and the proper management of dependencies on technology providers.<\/p>\n<h2>Preparing your entity for an audit<\/h2>\n<p>Preparing a financial institution for a DORA audit requires a <strong>robust, coherent and traceable ICT risk management framework<\/strong>. Articles 5 to 14 set out the minimum requirements, including the identification of essential assets, ongoing risk assessments, the maintenance of security policies and controls, continuity and recovery plans, and the regular performance of resilience tests, including advanced \u201cthreat-led\u201d penetration testing where applicable.<\/p>\n<p>This is complemented by the <strong>obligation to manage and report major incidents<\/strong> in accordance with Articles 17 to 23, ensuring that reporting flows to the financial supervisor are consistent with those required under the GDPR when the incident involves personal data. In this regard, the Spanish Data Protection Authority (AEPD) has reiterated that data breaches involving personal data must be reported within 72 hours, which requires internal coordination between DORA and GDPR reporting procedures.<\/p>\n<h2>Non-compliance with DORA<\/h2>\n<p>From a legal standpoint, the consequences of non-compliance are particularly significant. Article 50 of the Regulation requires Member States to establish \u201ceffective, proportionate and dissuasive\u201d sanctions. In Spain, this translates into the application of the sector-specific sanctioning regimes of the Bank of Spain, the CNMV, and the DGSFP, which may impose <strong>substantial fines, restrictions on activity, public warnings or even sanctions<\/strong> directly targeting members of the management body when serious breaches of their obligations are demonstrated.<\/p>\n<p>If the incident also involves a personal data breach, sanctions under DORA may be combined with those established under the GDPR and the Spanish Data Protection Act (LOPDGDD), considerably increasing the financial and reputational risk.<\/p>\n<p>In summary, compliance with the <a title=\"DORA Regulation\" href=\"https:\/\/letslaw.es\/en\/dora-regulation-digital-operational-resilience-financial-sector\/\">DORA Regulation<\/a> requires deep organisational transformation, proactive governance, and documentation aligned with European standards. Entities that approach this process strategically will not only avoid sanctions but also gain a competitive advantage in an increasingly demanding digital environment.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/19688#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The DORA Regulation: legal implications for ICT risk management in the financial sector. Regulation of digital operational resilience.<\/p>\n","protected":false},"author":2,"featured_media":19690,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[760],"tags":[],"class_list":["post-19688","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-delitos-informaticos-en"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/19688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=19688"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/19688\/revisions"}],"predecessor-version":[{"id":19693,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/19688\/revisions\/19693"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/19690"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=19688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=19688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=19688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}