Banking Law And Critical Financial Infrastructure Protection Spain .

Banking Law and Protection of Critical Financial Infrastructure in Spain

Spain's banking and critical-financial-infrastructure regime is not contained in one statute. It is a layered system combining Spanish banking legislation, directly applicable EU banking rules, EU crisis-management/resolution law, cybersecurity and digital-resilience legislation, payment-system oversight, and Spain's general critical-infrastructure framework.

The central objective is to protect two things simultaneously:

  1. The safety and solvency of individual financial institutions, and
  2. The continuity and resilience of the financial system and its critical infrastructure—including payment systems, securities infrastructure, banking IT systems and critical ICT providers.

The principal Spanish banking statute is Law 10/2014 of 26 June (Ley 10/2014) on the regulation, supervision and solvency of credit institutions. The Banco de España describes it as part of the core Spanish framework together with EU prudential legislation.

1. Constitutional and institutional framework

The Spanish framework operates within the European Banking Union.

The principal institutions are:

InstitutionPrincipal function
European Central Bank (ECB)Direct prudential supervision of significant banks under the Single Supervisory Mechanism
Banco de EspañaNational banking supervisor and authority for numerous less-significant institutions and financial-market/payment functions
Single Resolution Board (SRB)Resolution of banks within the Banking Union falling under its competence
FROBSpanish resolution authority/executing authority in the national framework
CNMVSecurities-market supervision
Ministry of EconomyCertain licensing, regulatory and governmental functions
INCIBE / National cybersecurity authoritiesCybersecurity support and coordination
National Security Department / CNPIC-related frameworkCritical infrastructure protection

The Banco de España's supervisory authority derives from several sources, including Law 13/1994 and the EU Single Supervisory Mechanism established by Regulation (EU) 1024/2013.

2. Law 10/2014: the foundation of Spanish banking law

Law 10/2014, of 26 June, on the regulation, supervision and solvency of credit institutions is one of the most important pieces of Spanish banking legislation.

BOE – Law 10/2014 consolidated text

It implements and complements the EU prudential framework, particularly:

  • Regulation (EU) 575/2013 (CRR);
  • Directive 2013/36/EU (CRD);
  • subsequent EU banking reforms.

The statute expressly identifies the banking sector as economically vital and emphasises that the failure of credit institutions can have serious consequences for the wider economy.

What is a credit institution?

Under Article 1, the principal categories include:

  • banks;
  • savings banks;
  • credit cooperatives;
  • Instituto de Crédito Oficial (ICO), subject to its specific legal regime.

The law reserves the activity of taking repayable funds from the public to authorised credit institutions.

This is important from an infrastructure perspective because banking is treated as a regulated activity rather than an ordinary commercial activity.

3. Prudential supervision and financial stability

Spanish banking law is based on the principle that banks must maintain sufficient financial resources and risk-management systems to withstand shocks.

The prudential framework covers:

A. Capital adequacy

Banks must maintain adequate regulatory capital against their risks.

The CRR is directly applicable throughout Spain, while Law 10/2014 and related regulations provide the Spanish supervisory framework.

B. Liquidity

Banks must maintain sufficient liquidity to meet their obligations.

C. Governance

Banks are subject to enhanced requirements concerning:

  • management bodies;
  • internal controls;
  • risk management;
  • suitability of directors and senior management;
  • remuneration;
  • corporate governance.

D. Risk management

Supervisors examine whether banks have adequate systems for managing:

  • credit risk;
  • market risk;
  • liquidity risk;
  • operational risk;
  • concentration risk;
  • technological and cyber risk.

The Banco de España has extensive intervention powers where prudential requirements are not met, including requiring additional capital, restricting distributions and, in sufficiently serious circumstances, intervening in the institution.

4. Why banking law is also infrastructure-protection law

A modern bank is not merely a building containing money.

Its operation depends on a highly interconnected technological ecosystem:

Customer → Bank → Payment system → Clearing/settlement infrastructure → Other bank → Central bank

A failure at one point can propagate throughout the system.

For example:

Cyberattack on Bank A → payment interruption → liquidity problems → inability to settle transactions → problems at Bank B → systemic financial disruption.

Consequently, operational resilience has become part of financial stability law.

This is particularly important in Spain because Banco de España's financial-market-infrastructure oversight expressly incorporates cyber-resilience and operational-continuity objectives.

5. Law 8/2011: protection of critical infrastructure

Spain also has a separate framework for critical infrastructure protection.

The principal statute is:

Law 8/2011, of 28 April, establishing measures for the protection of critical infrastructures.

BOE – Law 8/2011 on Critical Infrastructure Protection

The law establishes a system designed to protect infrastructure whose disruption could seriously affect essential services.

Its framework includes:

  • identification of critical infrastructure;
  • the National Catalogue of Strategic Infrastructures;
  • national protection planning;
  • security planning;
  • cooperation between public authorities and infrastructure operators;
  • obligations imposed on operators of critical infrastructure.

The statute's purpose is to coordinate government authorities and infrastructure owners/operators in order to protect essential services.

6. Financial infrastructure under the critical-infrastructure concept

Financial infrastructure can include systems that support:

  • payments;
  • clearing;
  • settlement;
  • securities transactions;
  • banking operations;
  • financial-market functioning.

But an important legal distinction must be made.

Not every bank automatically becomes a "critical infrastructure" operator merely because banking is economically important.

There are different legal concepts:

Banking supervision

Concerned with:

"Is the bank financially sound and safely managed?"

Critical infrastructure protection

Concerned with:

"Would disruption of this infrastructure seriously impair an essential service?"

DORA

Concerned with:

"Can the financial entity continue operating despite ICT disruption or cyberattack?"

These regimes overlap but are not identical.

7. DORA — the most important modern development

The Digital Operational Resilience Act (DORA) is now central to financial-infrastructure protection.

It is Regulation (EU) 2022/2554.

BOE/EU text of DORA – Regulation 2022/2554

DORA became applicable on 17 January 2025. It is directly applicable in Spain because it is an EU Regulation.

This is extremely significant because DORA creates a harmonised EU framework for financial-sector ICT resilience.

8. What DORA requires

DORA is built around several major obligations.

A. ICT risk management

Financial entities must establish a framework for identifying, managing and controlling ICT risks.

This includes:

  • governance;
  • risk identification;
  • prevention;
  • detection;
  • response;
  • recovery;
  • backup;
  • business continuity.

B. Incident reporting

Significant ICT-related incidents must be reported to the relevant authorities.

Banco de España has established specific procedures for reporting serious incidents and significant cyber threats under DORA. These procedures apply to, among others:

  • credit institutions;
  • payment institutions;
  • electronic-money institutions;
  • account-information service providers. 

C. Digital operational resilience testing

Financial entities must test whether their systems can withstand disruption.

Testing may include:

  • vulnerability assessments;
  • penetration testing;
  • scenario testing;
  • resilience testing;
  • threat-led penetration testing for entities falling within the relevant requirements.

The philosophy is:

Do not assume that the system is resilient—test it.

9. ICT third-party risk

This is one of DORA's most important innovations.

Banks increasingly depend on:

  • cloud providers;
  • software providers;
  • telecommunications companies;
  • cybersecurity companies;
  • data centres;
  • payment technology providers.

Therefore, a bank can be perfectly capitalised but still become operationally incapable if its cloud or technology provider fails.

DORA consequently requires financial institutions to manage ICT third-party risk, including contractual arrangements supporting critical or important functions.

At EU level, certain ICT providers can be classified as critical ICT third-party service providers, bringing them within EU-level oversight.

This represents a major shift from traditional banking law:

The regulator increasingly looks beyond the bank's balance sheet and into the technology supply chain.

10. Spanish payment infrastructure and DORA

Spain has supplemented the EU framework through Royal Decree-Law 8/2023.

Banco de España explains that Article 4 of that Royal Decree-Law extends parts of DORA's ICT-risk requirements to certain participants in the payment ecosystem, including payment-system operators and other relevant actors.

This is important because payment systems are among the most obvious examples of systemically important financial infrastructure.

11. NIS2 and the financial sector

The NIS2 Directive (EU) 2022/2555 is another major cybersecurity instrument.

It establishes cybersecurity requirements for entities operating in critical sectors.

However, there is an important legal issue in the financial sector:

DORA is lex specialis for many financial entities

NIS2 and DORA were designed to interact rather than impose completely duplicative obligations.

For entities covered by DORA, DORA is the principal sector-specific digital-resilience regime.

Spain's implementation of NIS2 has also been delayed.

As of 2026, the European Commission reported that Spain had not notified full NIS2 transposition and, in July 2026, referred Spain and several other states to the CJEU over the failure to transpose the Directive.

This is an important current-law qualification if you are writing an academic paper in 2026.

12. Critical Entities Resilience Directive — CER

Another relevant EU instrument is the Critical Entities Resilience Directive (EU) 2022/2557.

It covers resilience against a broad range of threats:

  • natural disasters;
  • accidents;
  • cyber-related risks;
  • malicious attacks;
  • other disruptive events.

The Directive specifically contains provisions concerning:

banking, financial market infrastructure and digital infrastructure.

 

Member States were required to identify relevant critical entities by 17 July 2026.

Thus, the legal architecture is moving from a traditional concept of "critical infrastructure" toward a broader concept of resilience of critical entities.

13. Bank resolution: Law 11/2015

A critical component of financial-infrastructure protection is preventing the failure of one bank from becoming a systemic crisis.

Spain's principal national statute is:

Law 11/2015 of 18 June on the recovery and resolution of credit institutions and investment firms.

Banco de España identifies this as part of the Spanish framework implementing the EU bank-recovery and resolution system.

The system is closely connected to:

  • Directive 2014/59/EU — Bank Recovery and Resolution Directive (BRRD);
  • Single Resolution Mechanism;
  • Single Resolution Board;
  • Spanish FROB.

14. The principle of "bail-in"

Modern EU/Spanish resolution law seeks to avoid the old model:

Bank fails → Government automatically uses taxpayers' money.

Instead, resolution law generally follows the hierarchy:

  1. shareholders bear losses;
  2. subordinated creditors may bear losses;
  3. other eligible creditors may be subject to bail-in;
  4. public funds are not the first resort.

This is particularly important for financial infrastructure protection because the law seeks to preserve the bank's critical functions while allocating losses appropriately.

15. Banco Popular — the leading Spanish case

The most important Spanish case study is undoubtedly the resolution of Banco Popular Español in June 2017.

The bank was declared failing or likely to fail and was resolved through the EU Single Resolution Mechanism.

Its shares were written down and the bank was transferred to Banco Santander for €1.

This generated extensive litigation.

The Banco Popular litigation is important because it tested:

  • shareholder protection;
  • property rights;
  • resolution powers;
  • valuation;
  • due process;
  • legitimate expectations;
  • the relationship between EU resolution law and national private law.

16. General Court: Banco Popular litigation

The EU General Court dealt with several challenges to the resolution.

Important cases included:

  • T-481/17
  • T-510/17
  • T-523/17
  • T-570/17
  • T-628/17

The General Court dismissed the challenges to the resolution scheme in June 2022.

The central lesson is that financial stability and resolution objectives can justify very significant interference with shareholders' and creditors' economic interests, provided the statutory and EU-law requirements are satisfied.

17. CJEU litigation and Banco Popular

The litigation continued before the Court of Justice.

The case law concerning Banco Popular has subsequently influenced Spanish Supreme Court litigation.

The CJEU's approach has been particularly important concerning the interaction between:

  • resolution law;
  • shareholder claims;
  • prospectus liability;
  • restitution;
  • the principle that resolution should not be undermined by subsequent private-law claims.

The Spanish Supreme Court has expressly applied the CJEU's Banco Popular jurisprudence in subsequent cases.

18. Supreme Court: Banco Popular and shareholder claims

The Spanish Supreme Court has issued numerous judgments following the CJEU's interpretation.

For example, the Supreme Court's later jurisprudence recognises that claims based upon the acquisition of Banco Popular shares can be affected by the consequences of the EU resolution framework.

The Court has referred to judgments including:

  • STS 1135/2023;
  • STS 1137/2023;
  • STS 1138/2023;
  • STS 1139/2023;
  • STS 1212/2023;
  • STS 1214/2023.

The Supreme Court continued applying that doctrine in 2025.

Legal significance

This demonstrates an important principle:

National private-law remedies cannot necessarily be exercised in a way that defeats the effects of an EU bank-resolution measure.

That is one of the most important lessons from the Banco Popular litigation.

19. An important later development: preferred instruments

The Banco Popular jurisprudence did not stop with ordinary shareholders.

In 2024, the CJEU considered questions concerning financial instruments that had been converted into Banco Popular shares before resolution.

The Spanish Supreme Court's 2025 case-law discusses the CJEU judgment of 5 September 2024 in joined cases C-775/22, C-779/22 and C-794/22.

The Court clarified circumstances in which holders of certain capital instruments could pursue claims concerning defective information even after resolution.

This demonstrates that resolution law does not automatically extinguish every possible national-law or EU-law claim; the precise nature of the liability and the instrument involved matters.

20. Banco Popular and "No Creditor Worse Off"

A fundamental principle of EU resolution law is the No Creditor Worse Off (NCWO) principle.

Broadly:

A creditor should not ultimately suffer a greater loss through resolution than it would have suffered if the institution had instead been wound up under normal insolvency proceedings.

This creates an important judicial safeguard.

It attempts to balance:

Financial stability

against

Property and creditor rights.

Therefore, resolution authorities possess substantial powers, but those powers are not unlimited.

21. Judicial review of banking regulators

Spanish and EU courts play an important role in reviewing regulatory decisions.

Judicial review can involve questions such as:

  • Did the regulator have legal authority?
  • Was the decision based on sufficient evidence?
  • Was the correct procedure followed?
  • Was the decision proportionate?
  • Were fundamental rights respected?
  • Was the authority's technical assessment manifestly erroneous?
  • Were shareholders and creditors afforded the protections required by EU law?

But courts generally recognise that banking supervision involves complex economic and technical judgments.

Consequently, regulators receive significant room for technical assessment, subject to legality and judicial review.

22. Banco Popular and systemic-risk lessons

The Banco Popular case illustrates a fundamental distinction:

Normal insolvency

The objective is primarily:

maximise/allocate value among creditors.

Bank resolution

The objective is broader:

preserve critical functions + protect financial stability + minimise systemic disruption + allocate losses according to the statutory hierarchy.

This is why ordinary insolvency law cannot simply be applied mechanically to a systemically important bank.

23. Cybersecurity as financial stability law

The modern concept of financial infrastructure protection therefore includes cybersecurity.

Banco de España's cyber-resilience strategy operates around three pillars:

Pillar 1 — Individual preparedness

Each institution must be capable of resisting and recovering from cyber incidents.

Pillar 2 — Sectoral resilience

Authorities examine interconnections and dependencies between financial institutions and third-party providers.

Pillar 3 — Strategic cooperation

Authorities cooperate internationally and conduct crisis and operational-continuity exercises.

Banco de España expressly identifies DORA and payment-system oversight as components of this resilience architecture.

24. TIBER-ES and cyber testing

Spain also participates in the Eurosystem's TIBER framework.

TIBER is designed for controlled threat-led penetration testing of financial institutions.

The purpose is not simply to ask:

"Does the bank have cybersecurity policies?"

Instead:

"Can the bank actually withstand a realistic sophisticated cyberattack?"

Banco de España states that TIBER-EU is implemented domestically through TIBER-ES.

25. Payment systems as critical infrastructure

Payment infrastructure deserves special attention.

Examples include:

  • payment systems;
  • clearing arrangements;
  • settlement systems;
  • card-payment infrastructure;
  • instant-payment infrastructure;
  • central-bank payment infrastructure.

The reason is simple:

A bank can survive temporary losses more easily than the economy can survive the collapse of its payment system.

Consequently, payment-system operators face special oversight.

Banco de España's framework specifically links payment-system oversight with cyber resilience and operational continuity.

26. The legal architecture — simplified diagram

                    EUROPEAN UNION                         │       ┌─────────────────┼──────────────────┐       │                 │                  │   CRR / CRD           BRRD              DORA       │                 │                  │       ▼                 ▼                  ▼ Prudential          Bank recovery      ICT / cyber regulation          & resolution       resilience       │                 │                  │       └─────────────────┼──────────────────┘                         │                         ▼                       SPAIN                         │       ┌─────────────────┼──────────────────┐       │                 │                  │  Law 10/2014        Law 11/2015        Law 8/2011  Banking            Resolution         Critical  supervision        framework          infrastructure       │                 │                  │       ▼                 ▼                  ▼ Banco de España      FROB/SRB        Critical-infrastructure / ECB                / CNMV          protection system       │       ▼ Financial institutions + payment systems + ICT providers + financial-market infrastructure

 

27. Relationship between the principal laws

Legal instrumentMain objectiveInfrastructure relevance
Law 10/2014Banking supervision and solvencyPrevents bank failure
CRR/CRDPrudential requirementsCapital/liquidity/risk resilience
Law 11/2015Recovery and resolutionPrevents disorderly bank failure
BRRDEU resolution frameworkSystemic stability
Law 8/2011Critical infrastructure protectionProtection of essential infrastructure
DORADigital operational resilienceCyber/ICT resilience
NIS2CybersecurityWider network-security framework
CER DirectiveCritical-entity resilienceResilience against multiple threats
Royal Decree-Law 8/2023Payment/ICT resilienceExtends certain DORA requirements
TIBER-ESThreat-led testingPractical cyber resilience

28. Key case law to cite

For an academic answer or examination, I would prioritise the following authorities.

1. Banco Popular — General Court

T-481/17, T-510/17, T-523/17, T-570/17 and T-628/17

These cases concern challenges to the Banco Popular resolution and were dismissed by the General Court in 2022.

2. CJEU — Banco Popular resolution litigation

The CJEU's subsequent judgments are important for the compatibility of resolution measures with shareholder and creditor rights.

3. CJEU, 5 September 2024

Joined Cases C-775/22, C-779/22 and C-794/22

Important for claims relating to capital instruments converted into Banco Popular shares before resolution.

4. Spanish Supreme Court — 2023 Banco Popular jurisprudence

Important judgments include:

  • STS 1135/2023
  • STS 1137/2023
  • STS 1138/2023
  • STS 1139/2023
  • STS 1212/2023
  • STS 1214/2023

They apply the CJEU's interpretation to Spanish litigation.

5. Spanish Supreme Court, 2025

The Supreme Court continued applying the Banco Popular resolution doctrine, including in STS 61/2025 and other 2025 judgments.

29. Broader banking-law case: CNMV and customer-service obligations

Another useful Spanish Supreme Court authority is the Banco Popular customer-service case.

The Supreme Court upheld a €500,000 CNMV fine relating to deficiencies in Banco Popular's customer complaint-handling system. The CNMV had found serious shortcomings in handling customer complaints, including failures to respond within the applicable period.

This case illustrates another dimension of banking regulation:

Banking supervision is not limited to capital and solvency; conduct and internal-control systems can also attract regulatory sanctions.

30. The most important legal principles

From the Spanish legislation and case law, several principles emerge.

Principle 1 — Banking is a specially regulated activity

A bank cannot be treated simply as an ordinary company because its failure can have systemic consequences.

Principle 2 — Financial stability is a legitimate public interest

Regulators can intervene substantially to protect financial stability.

Principle 3 — Shareholder rights are not absolute

In resolution, shareholders can lose their entire investment.

Principle 4 — Creditors also bear losses

The resolution framework seeks to avoid automatic taxpayer-funded bailouts.

Principle 5 — Resolution must respect legal safeguards

Regulatory discretion remains subject to EU and national judicial review.

Principle 6 — Operational resilience is now part of financial regulation

Cybersecurity, business continuity and ICT risk are no longer merely technical IT matters.

Principle 7 — Third-party technology providers can create systemic risk

Cloud and technology concentration is increasingly treated as a financial-stability issue.

Principle 8 — Critical infrastructure protection is broader than banking supervision

A bank may be prudentially sound while an essential infrastructure on which it depends is vulnerable.

31. Current legal trend in Spain

The direction of Spanish and EU law is clear:

Old model

Capital + solvency + supervision

Modern model

Capital + liquidity + governance + resolution + cybersecurity + operational resilience + third-party ICT risk + infrastructure continuity.

DORA is particularly significant because it treats the financial system as an interconnected technological ecosystem rather than a collection of isolated banks. Banco de España itself emphasises the interconnections between financial institutions and critical third-party providers.

At the same time, Spain's incomplete NIS2 transposition as of 2026 demonstrates that the national implementation layer is still evolving.

Conclusion

Spanish banking law and critical financial-infrastructure protection form a multi-layered system.

At the institutional level, Law 10/2014 establishes the core prudential and supervisory regime. Law 11/2015 and the EU resolution framework address the failure of banks without necessarily relying on taxpayer-funded rescue. Law 8/2011 provides the general critical-infrastructure protection architecture. DORA, applicable since 17 January 2025, adds a comprehensive digital-operational-resilience regime covering ICT risk, incident reporting, testing and third-party technology risk.

The Banco Popular litigation is the key case study because it demonstrates how the law balances financial stability against property rights, shareholder rights, creditor rights and judicial review. The General Court upheld the core resolution decisions, while later CJEU and Spanish Supreme Court judgments refined the treatment of private-law claims after resolution.

For an exam or dissertation, the central proposition can therefore be stated as:

Spain protects critical financial infrastructure not through a single banking statute, but through an integrated framework of prudential supervision, bank resolution, critical-infrastructure protection, payment-system oversight and digital operational resilience, operating within the EU Banking Union.

LEAVE A COMMENT