Banking Law And Critical Financial Infrastructure Protection Spain .
Banking Law and Protection of Critical Financial Infrastructure in Spain
Spain's banking and critical-financial-infrastructure regime is not contained in one statute. It is a layered system combining Spanish banking legislation, directly applicable EU banking rules, EU crisis-management/resolution law, cybersecurity and digital-resilience legislation, payment-system oversight, and Spain's general critical-infrastructure framework.
The central objective is to protect two things simultaneously:
- The safety and solvency of individual financial institutions, and
- The continuity and resilience of the financial system and its critical infrastructure—including payment systems, securities infrastructure, banking IT systems and critical ICT providers.
The principal Spanish banking statute is Law 10/2014 of 26 June (Ley 10/2014) on the regulation, supervision and solvency of credit institutions. The Banco de España describes it as part of the core Spanish framework together with EU prudential legislation.
1. Constitutional and institutional framework
The Spanish framework operates within the European Banking Union.
The principal institutions are:
| Institution | Principal function |
|---|---|
| European Central Bank (ECB) | Direct prudential supervision of significant banks under the Single Supervisory Mechanism |
| Banco de España | National banking supervisor and authority for numerous less-significant institutions and financial-market/payment functions |
| Single Resolution Board (SRB) | Resolution of banks within the Banking Union falling under its competence |
| FROB | Spanish resolution authority/executing authority in the national framework |
| CNMV | Securities-market supervision |
| Ministry of Economy | Certain licensing, regulatory and governmental functions |
| INCIBE / National cybersecurity authorities | Cybersecurity support and coordination |
| National Security Department / CNPIC-related framework | Critical infrastructure protection |
The Banco de España's supervisory authority derives from several sources, including Law 13/1994 and the EU Single Supervisory Mechanism established by Regulation (EU) 1024/2013.
2. Law 10/2014: the foundation of Spanish banking law
Law 10/2014, of 26 June, on the regulation, supervision and solvency of credit institutions is one of the most important pieces of Spanish banking legislation.
BOE – Law 10/2014 consolidated text
It implements and complements the EU prudential framework, particularly:
- Regulation (EU) 575/2013 (CRR);
- Directive 2013/36/EU (CRD);
- subsequent EU banking reforms.
The statute expressly identifies the banking sector as economically vital and emphasises that the failure of credit institutions can have serious consequences for the wider economy.
What is a credit institution?
Under Article 1, the principal categories include:
- banks;
- savings banks;
- credit cooperatives;
- Instituto de Crédito Oficial (ICO), subject to its specific legal regime.
The law reserves the activity of taking repayable funds from the public to authorised credit institutions.
This is important from an infrastructure perspective because banking is treated as a regulated activity rather than an ordinary commercial activity.
3. Prudential supervision and financial stability
Spanish banking law is based on the principle that banks must maintain sufficient financial resources and risk-management systems to withstand shocks.
The prudential framework covers:
A. Capital adequacy
Banks must maintain adequate regulatory capital against their risks.
The CRR is directly applicable throughout Spain, while Law 10/2014 and related regulations provide the Spanish supervisory framework.
B. Liquidity
Banks must maintain sufficient liquidity to meet their obligations.
C. Governance
Banks are subject to enhanced requirements concerning:
- management bodies;
- internal controls;
- risk management;
- suitability of directors and senior management;
- remuneration;
- corporate governance.
D. Risk management
Supervisors examine whether banks have adequate systems for managing:
- credit risk;
- market risk;
- liquidity risk;
- operational risk;
- concentration risk;
- technological and cyber risk.
The Banco de España has extensive intervention powers where prudential requirements are not met, including requiring additional capital, restricting distributions and, in sufficiently serious circumstances, intervening in the institution.
4. Why banking law is also infrastructure-protection law
A modern bank is not merely a building containing money.
Its operation depends on a highly interconnected technological ecosystem:
Customer → Bank → Payment system → Clearing/settlement infrastructure → Other bank → Central bank
A failure at one point can propagate throughout the system.
For example:
Cyberattack on Bank A → payment interruption → liquidity problems → inability to settle transactions → problems at Bank B → systemic financial disruption.
Consequently, operational resilience has become part of financial stability law.
This is particularly important in Spain because Banco de España's financial-market-infrastructure oversight expressly incorporates cyber-resilience and operational-continuity objectives.
5. Law 8/2011: protection of critical infrastructure
Spain also has a separate framework for critical infrastructure protection.
The principal statute is:
Law 8/2011, of 28 April, establishing measures for the protection of critical infrastructures.
BOE – Law 8/2011 on Critical Infrastructure Protection
The law establishes a system designed to protect infrastructure whose disruption could seriously affect essential services.
Its framework includes:
- identification of critical infrastructure;
- the National Catalogue of Strategic Infrastructures;
- national protection planning;
- security planning;
- cooperation between public authorities and infrastructure operators;
- obligations imposed on operators of critical infrastructure.
The statute's purpose is to coordinate government authorities and infrastructure owners/operators in order to protect essential services.
6. Financial infrastructure under the critical-infrastructure concept
Financial infrastructure can include systems that support:
- payments;
- clearing;
- settlement;
- securities transactions;
- banking operations;
- financial-market functioning.
But an important legal distinction must be made.
Not every bank automatically becomes a "critical infrastructure" operator merely because banking is economically important.
There are different legal concepts:
Banking supervision
Concerned with:
"Is the bank financially sound and safely managed?"
Critical infrastructure protection
Concerned with:
"Would disruption of this infrastructure seriously impair an essential service?"
DORA
Concerned with:
"Can the financial entity continue operating despite ICT disruption or cyberattack?"
These regimes overlap but are not identical.
7. DORA — the most important modern development
The Digital Operational Resilience Act (DORA) is now central to financial-infrastructure protection.
It is Regulation (EU) 2022/2554.
BOE/EU text of DORA – Regulation 2022/2554
DORA became applicable on 17 January 2025. It is directly applicable in Spain because it is an EU Regulation.
This is extremely significant because DORA creates a harmonised EU framework for financial-sector ICT resilience.
8. What DORA requires
DORA is built around several major obligations.
A. ICT risk management
Financial entities must establish a framework for identifying, managing and controlling ICT risks.
This includes:
- governance;
- risk identification;
- prevention;
- detection;
- response;
- recovery;
- backup;
- business continuity.
B. Incident reporting
Significant ICT-related incidents must be reported to the relevant authorities.
Banco de España has established specific procedures for reporting serious incidents and significant cyber threats under DORA. These procedures apply to, among others:
- credit institutions;
- payment institutions;
- electronic-money institutions;
- account-information service providers.
C. Digital operational resilience testing
Financial entities must test whether their systems can withstand disruption.
Testing may include:
- vulnerability assessments;
- penetration testing;
- scenario testing;
- resilience testing;
- threat-led penetration testing for entities falling within the relevant requirements.
The philosophy is:
Do not assume that the system is resilient—test it.
9. ICT third-party risk
This is one of DORA's most important innovations.
Banks increasingly depend on:
- cloud providers;
- software providers;
- telecommunications companies;
- cybersecurity companies;
- data centres;
- payment technology providers.
Therefore, a bank can be perfectly capitalised but still become operationally incapable if its cloud or technology provider fails.
DORA consequently requires financial institutions to manage ICT third-party risk, including contractual arrangements supporting critical or important functions.
At EU level, certain ICT providers can be classified as critical ICT third-party service providers, bringing them within EU-level oversight.
This represents a major shift from traditional banking law:
The regulator increasingly looks beyond the bank's balance sheet and into the technology supply chain.
10. Spanish payment infrastructure and DORA
Spain has supplemented the EU framework through Royal Decree-Law 8/2023.
Banco de España explains that Article 4 of that Royal Decree-Law extends parts of DORA's ICT-risk requirements to certain participants in the payment ecosystem, including payment-system operators and other relevant actors.
This is important because payment systems are among the most obvious examples of systemically important financial infrastructure.
11. NIS2 and the financial sector
The NIS2 Directive (EU) 2022/2555 is another major cybersecurity instrument.
It establishes cybersecurity requirements for entities operating in critical sectors.
However, there is an important legal issue in the financial sector:
DORA is lex specialis for many financial entities
NIS2 and DORA were designed to interact rather than impose completely duplicative obligations.
For entities covered by DORA, DORA is the principal sector-specific digital-resilience regime.
Spain's implementation of NIS2 has also been delayed.
As of 2026, the European Commission reported that Spain had not notified full NIS2 transposition and, in July 2026, referred Spain and several other states to the CJEU over the failure to transpose the Directive.
This is an important current-law qualification if you are writing an academic paper in 2026.
12. Critical Entities Resilience Directive — CER
Another relevant EU instrument is the Critical Entities Resilience Directive (EU) 2022/2557.
It covers resilience against a broad range of threats:
- natural disasters;
- accidents;
- cyber-related risks;
- malicious attacks;
- other disruptive events.
The Directive specifically contains provisions concerning:
banking, financial market infrastructure and digital infrastructure.
Member States were required to identify relevant critical entities by 17 July 2026.
Thus, the legal architecture is moving from a traditional concept of "critical infrastructure" toward a broader concept of resilience of critical entities.
13. Bank resolution: Law 11/2015
A critical component of financial-infrastructure protection is preventing the failure of one bank from becoming a systemic crisis.
Spain's principal national statute is:
Law 11/2015 of 18 June on the recovery and resolution of credit institutions and investment firms.
Banco de España identifies this as part of the Spanish framework implementing the EU bank-recovery and resolution system.
The system is closely connected to:
- Directive 2014/59/EU — Bank Recovery and Resolution Directive (BRRD);
- Single Resolution Mechanism;
- Single Resolution Board;
- Spanish FROB.
14. The principle of "bail-in"
Modern EU/Spanish resolution law seeks to avoid the old model:
Bank fails → Government automatically uses taxpayers' money.
Instead, resolution law generally follows the hierarchy:
- shareholders bear losses;
- subordinated creditors may bear losses;
- other eligible creditors may be subject to bail-in;
- public funds are not the first resort.
This is particularly important for financial infrastructure protection because the law seeks to preserve the bank's critical functions while allocating losses appropriately.
15. Banco Popular — the leading Spanish case
The most important Spanish case study is undoubtedly the resolution of Banco Popular Español in June 2017.
The bank was declared failing or likely to fail and was resolved through the EU Single Resolution Mechanism.
Its shares were written down and the bank was transferred to Banco Santander for €1.
This generated extensive litigation.
The Banco Popular litigation is important because it tested:
- shareholder protection;
- property rights;
- resolution powers;
- valuation;
- due process;
- legitimate expectations;
- the relationship between EU resolution law and national private law.
16. General Court: Banco Popular litigation
The EU General Court dealt with several challenges to the resolution.
Important cases included:
- T-481/17
- T-510/17
- T-523/17
- T-570/17
- T-628/17
The General Court dismissed the challenges to the resolution scheme in June 2022.
The central lesson is that financial stability and resolution objectives can justify very significant interference with shareholders' and creditors' economic interests, provided the statutory and EU-law requirements are satisfied.
17. CJEU litigation and Banco Popular
The litigation continued before the Court of Justice.
The case law concerning Banco Popular has subsequently influenced Spanish Supreme Court litigation.
The CJEU's approach has been particularly important concerning the interaction between:
- resolution law;
- shareholder claims;
- prospectus liability;
- restitution;
- the principle that resolution should not be undermined by subsequent private-law claims.
The Spanish Supreme Court has expressly applied the CJEU's Banco Popular jurisprudence in subsequent cases.
18. Supreme Court: Banco Popular and shareholder claims
The Spanish Supreme Court has issued numerous judgments following the CJEU's interpretation.
For example, the Supreme Court's later jurisprudence recognises that claims based upon the acquisition of Banco Popular shares can be affected by the consequences of the EU resolution framework.
The Court has referred to judgments including:
- STS 1135/2023;
- STS 1137/2023;
- STS 1138/2023;
- STS 1139/2023;
- STS 1212/2023;
- STS 1214/2023.
The Supreme Court continued applying that doctrine in 2025.
Legal significance
This demonstrates an important principle:
National private-law remedies cannot necessarily be exercised in a way that defeats the effects of an EU bank-resolution measure.
That is one of the most important lessons from the Banco Popular litigation.
19. An important later development: preferred instruments
The Banco Popular jurisprudence did not stop with ordinary shareholders.
In 2024, the CJEU considered questions concerning financial instruments that had been converted into Banco Popular shares before resolution.
The Spanish Supreme Court's 2025 case-law discusses the CJEU judgment of 5 September 2024 in joined cases C-775/22, C-779/22 and C-794/22.
The Court clarified circumstances in which holders of certain capital instruments could pursue claims concerning defective information even after resolution.
This demonstrates that resolution law does not automatically extinguish every possible national-law or EU-law claim; the precise nature of the liability and the instrument involved matters.
20. Banco Popular and "No Creditor Worse Off"
A fundamental principle of EU resolution law is the No Creditor Worse Off (NCWO) principle.
Broadly:
A creditor should not ultimately suffer a greater loss through resolution than it would have suffered if the institution had instead been wound up under normal insolvency proceedings.
This creates an important judicial safeguard.
It attempts to balance:
Financial stability
against
Property and creditor rights.
Therefore, resolution authorities possess substantial powers, but those powers are not unlimited.
21. Judicial review of banking regulators
Spanish and EU courts play an important role in reviewing regulatory decisions.
Judicial review can involve questions such as:
- Did the regulator have legal authority?
- Was the decision based on sufficient evidence?
- Was the correct procedure followed?
- Was the decision proportionate?
- Were fundamental rights respected?
- Was the authority's technical assessment manifestly erroneous?
- Were shareholders and creditors afforded the protections required by EU law?
But courts generally recognise that banking supervision involves complex economic and technical judgments.
Consequently, regulators receive significant room for technical assessment, subject to legality and judicial review.
22. Banco Popular and systemic-risk lessons
The Banco Popular case illustrates a fundamental distinction:
Normal insolvency
The objective is primarily:
maximise/allocate value among creditors.
Bank resolution
The objective is broader:
preserve critical functions + protect financial stability + minimise systemic disruption + allocate losses according to the statutory hierarchy.
This is why ordinary insolvency law cannot simply be applied mechanically to a systemically important bank.
23. Cybersecurity as financial stability law
The modern concept of financial infrastructure protection therefore includes cybersecurity.
Banco de España's cyber-resilience strategy operates around three pillars:
Pillar 1 — Individual preparedness
Each institution must be capable of resisting and recovering from cyber incidents.
Pillar 2 — Sectoral resilience
Authorities examine interconnections and dependencies between financial institutions and third-party providers.
Pillar 3 — Strategic cooperation
Authorities cooperate internationally and conduct crisis and operational-continuity exercises.
Banco de España expressly identifies DORA and payment-system oversight as components of this resilience architecture.
24. TIBER-ES and cyber testing
Spain also participates in the Eurosystem's TIBER framework.
TIBER is designed for controlled threat-led penetration testing of financial institutions.
The purpose is not simply to ask:
"Does the bank have cybersecurity policies?"
Instead:
"Can the bank actually withstand a realistic sophisticated cyberattack?"
Banco de España states that TIBER-EU is implemented domestically through TIBER-ES.
25. Payment systems as critical infrastructure
Payment infrastructure deserves special attention.
Examples include:
- payment systems;
- clearing arrangements;
- settlement systems;
- card-payment infrastructure;
- instant-payment infrastructure;
- central-bank payment infrastructure.
The reason is simple:
A bank can survive temporary losses more easily than the economy can survive the collapse of its payment system.
Consequently, payment-system operators face special oversight.
Banco de España's framework specifically links payment-system oversight with cyber resilience and operational continuity.
26. The legal architecture — simplified diagram
EUROPEAN UNION │ ┌─────────────────┼──────────────────┐ │ │ │ CRR / CRD BRRD DORA │ │ │ ▼ ▼ ▼ Prudential Bank recovery ICT / cyber regulation & resolution resilience │ │ │ └─────────────────┼──────────────────┘ │ ▼ SPAIN │ ┌─────────────────┼──────────────────┐ │ │ │ Law 10/2014 Law 11/2015 Law 8/2011 Banking Resolution Critical supervision framework infrastructure │ │ │ ▼ ▼ ▼ Banco de España FROB/SRB Critical-infrastructure / ECB / CNMV protection system │ ▼ Financial institutions + payment systems + ICT providers + financial-market infrastructure
27. Relationship between the principal laws
| Legal instrument | Main objective | Infrastructure relevance |
|---|---|---|
| Law 10/2014 | Banking supervision and solvency | Prevents bank failure |
| CRR/CRD | Prudential requirements | Capital/liquidity/risk resilience |
| Law 11/2015 | Recovery and resolution | Prevents disorderly bank failure |
| BRRD | EU resolution framework | Systemic stability |
| Law 8/2011 | Critical infrastructure protection | Protection of essential infrastructure |
| DORA | Digital operational resilience | Cyber/ICT resilience |
| NIS2 | Cybersecurity | Wider network-security framework |
| CER Directive | Critical-entity resilience | Resilience against multiple threats |
| Royal Decree-Law 8/2023 | Payment/ICT resilience | Extends certain DORA requirements |
| TIBER-ES | Threat-led testing | Practical cyber resilience |
28. Key case law to cite
For an academic answer or examination, I would prioritise the following authorities.
1. Banco Popular — General Court
T-481/17, T-510/17, T-523/17, T-570/17 and T-628/17
These cases concern challenges to the Banco Popular resolution and were dismissed by the General Court in 2022.
2. CJEU — Banco Popular resolution litigation
The CJEU's subsequent judgments are important for the compatibility of resolution measures with shareholder and creditor rights.
3. CJEU, 5 September 2024
Joined Cases C-775/22, C-779/22 and C-794/22
Important for claims relating to capital instruments converted into Banco Popular shares before resolution.
4. Spanish Supreme Court — 2023 Banco Popular jurisprudence
Important judgments include:
- STS 1135/2023
- STS 1137/2023
- STS 1138/2023
- STS 1139/2023
- STS 1212/2023
- STS 1214/2023
They apply the CJEU's interpretation to Spanish litigation.
5. Spanish Supreme Court, 2025
The Supreme Court continued applying the Banco Popular resolution doctrine, including in STS 61/2025 and other 2025 judgments.
29. Broader banking-law case: CNMV and customer-service obligations
Another useful Spanish Supreme Court authority is the Banco Popular customer-service case.
The Supreme Court upheld a €500,000 CNMV fine relating to deficiencies in Banco Popular's customer complaint-handling system. The CNMV had found serious shortcomings in handling customer complaints, including failures to respond within the applicable period.
This case illustrates another dimension of banking regulation:
Banking supervision is not limited to capital and solvency; conduct and internal-control systems can also attract regulatory sanctions.
30. The most important legal principles
From the Spanish legislation and case law, several principles emerge.
Principle 1 — Banking is a specially regulated activity
A bank cannot be treated simply as an ordinary company because its failure can have systemic consequences.
Principle 2 — Financial stability is a legitimate public interest
Regulators can intervene substantially to protect financial stability.
Principle 3 — Shareholder rights are not absolute
In resolution, shareholders can lose their entire investment.
Principle 4 — Creditors also bear losses
The resolution framework seeks to avoid automatic taxpayer-funded bailouts.
Principle 5 — Resolution must respect legal safeguards
Regulatory discretion remains subject to EU and national judicial review.
Principle 6 — Operational resilience is now part of financial regulation
Cybersecurity, business continuity and ICT risk are no longer merely technical IT matters.
Principle 7 — Third-party technology providers can create systemic risk
Cloud and technology concentration is increasingly treated as a financial-stability issue.
Principle 8 — Critical infrastructure protection is broader than banking supervision
A bank may be prudentially sound while an essential infrastructure on which it depends is vulnerable.
31. Current legal trend in Spain
The direction of Spanish and EU law is clear:
Old model
Capital + solvency + supervision
Modern model
Capital + liquidity + governance + resolution + cybersecurity + operational resilience + third-party ICT risk + infrastructure continuity.
DORA is particularly significant because it treats the financial system as an interconnected technological ecosystem rather than a collection of isolated banks. Banco de España itself emphasises the interconnections between financial institutions and critical third-party providers.
At the same time, Spain's incomplete NIS2 transposition as of 2026 demonstrates that the national implementation layer is still evolving.
Conclusion
Spanish banking law and critical financial-infrastructure protection form a multi-layered system.
At the institutional level, Law 10/2014 establishes the core prudential and supervisory regime. Law 11/2015 and the EU resolution framework address the failure of banks without necessarily relying on taxpayer-funded rescue. Law 8/2011 provides the general critical-infrastructure protection architecture. DORA, applicable since 17 January 2025, adds a comprehensive digital-operational-resilience regime covering ICT risk, incident reporting, testing and third-party technology risk.
The Banco Popular litigation is the key case study because it demonstrates how the law balances financial stability against property rights, shareholder rights, creditor rights and judicial review. The General Court upheld the core resolution decisions, while later CJEU and Spanish Supreme Court judgments refined the treatment of private-law claims after resolution.
For an exam or dissertation, the central proposition can therefore be stated as:
Spain protects critical financial infrastructure not through a single banking statute, but through an integrated framework of prudential supervision, bank resolution, critical-infrastructure protection, payment-system oversight and digital operational resilience, operating within the EU Banking Union.

comments