DORA for Financial Entities in Spain: Compliance Guide 2026
DORA (Regulation (EU) 2022/2554) has been mandatory since January 2025 for all EU financial entities. Five pillars: ICT risk management framework, incident management and notification (4h initial / 72h intermediate / 1 month final to Banco de España, CNMV or DGSFP), digital operational resilience testing (annual basic + TLPT every 3 years for significant entities), ICT third-party risk management (mandatory contract clauses under art. 30, critical provider supervision), and information sharing on cyber threats. Maximum fines: 10% of annual group turnover.