Digital transformation is reshaping the financial sector at an unprecedented pace. The emergence of new business models, the growth of digital services, the rise of crypto-assets and the increase in technology-related risks have driven a major overhaul of the European regulatory framework.

Against this backdrop, the Spanish Council of Ministers has approved the Bill on the Digitalisation and Modernisation of the Financial Sector, which now begins its parliamentary process. Rather than introducing an entirely new regulatory framework, the bill adapts Spanish legislation to several European regulations that are already in force and strengthens key areas such as cybersecurity, operational resilience, transparency and financial innovation.

Below, we examine the main developments and explain what organisations should begin reviewing to prepare for this new regulatory landscape.

A further step towards a more digital and resilient financial system

The bill pursues a twofold objective. On the one hand, it aims to align Spanish legislation with the European regulatory framework that is transforming the financial sector. On the other, it seeks to promote innovation and competitiveness while maintaining user protection and the stability of the financial system.

To achieve this, the future legislation introduces amendments to several laws in order to facilitate the practical implementation of European regulations that are already shaping the future of the sector, including:

  • The Markets in Crypto-Assets Regulation (MiCA).
  • The Digital Operational Resilience Act (DORA).
  • European legislation on instant payments.
  • The future European Single Access Point (ESAP), which will improve access to companies’ financial and corporate information.

Overall, the bill confirms a clear trend: the digitalisation of the financial system must be accompanied by stronger safeguards in terms of supervision, technological security and regulatory compliance.

Five key developments you should know about

1. Cybersecurity takes centre stage

One of the most significant aspects of the bill is the strengthening of the financial sector’s digital operational resilience.

The legislation aligns Spanish law with the DORA Regulation, which establishes a common framework for managing risks related to information and communication technologies (ICT).

This means that financial institutions will need to strengthen areas such as:

  • Technology risk management.
  • Oversight of ICT service providers.
  • Business continuity plans.
  • Cybersecurity incident response.
  • Governance of technology risks.

Cybersecurity is no longer solely a technological issue; it has become a fundamental element of regulatory compliance.

2. New safeguards for the crypto-assets market

The bill also completes the implementation of the MiCA Regulation in Spain.

Among other measures, crypto-asset service providers will become fully integrated into the anti-money laundering framework, while the Spanish National Securities Market Commission (CNMV) will strengthen its supervisory powers over this market.

In addition, the CNMV will be able to take action against crypto-asset advertising where it considers that it does not comply with the applicable requirements or may pose risks to investors.

The aim is to provide greater legal certainty in a market that continues to grow while enhancing investor protection.

 

I would like more information

3. A more open and competitive payments market

The future legislation also introduces measures designed to promote competition in payment services.

One of the main developments is that certain payment institutions and electronic money institutions will be allowed to access payment systems directly, without having to operate through a banking institution.

At the same time, the protection of strategic infrastructures such as Iberpay will be strengthened, with changes in control becoming subject to prior administrative authorisation in certain corporate transactions.

4. Greater transparency for investors and markets

Another important feature of the bill is its alignment with the future European Single Access Point (ESAP).

This platform will provide a single point of access to financial and non-financial information published by companies across the European Union.

The initiative will make it easier for investors, analysts and other market participants to access standardised corporate information, promoting greater transparency and better integration of European capital markets.

5. A more flexible Financial Sandbox to foster innovation

The bill also introduces improvements to the operation of Spain’s Financial Sandbox.

Among the proposed changes are:

  • Year-round submission of projects.
  • Simplification of certain administrative procedures.
  • Lower access costs.
  • The creation of thematic cohorts to encourage the development of innovative solutions.

These measures are intended to strengthen the role of the Financial Sandbox as a secure environment for testing new financial business models before they are launched onto the market.

Beyond the legislation: what organisations should start reviewing

Although the bill still has to complete the parliamentary approval process, its content already provides a clear indication of the direction in which the European regulatory framework is evolving.

For this reason, organisations should begin reviewing a number of particularly sensitive areas, including:

  • Their cybersecurity and technological resilience policies.
  • Incident management procedures.
  • Contracts with critical technology providers.
  • Compliance processes relating to MiCA and anti-money laundering requirements, where applicable.
  • Technology risk governance and oversight mechanisms.
  • Corporate transparency and reporting obligations arising from European legislation.

Taking a proactive approach will enable organisations to address future regulatory obligations with greater confidence and reduce the risks associated with digital transformation.

A regulatory framework increasingly focused on digital trust

The digitalisation of the financial sector is no longer just about adopting new technologies. It also involves strengthening security, operational resilience, transparency and regulatory compliance in order to create a more trustworthy environment for both businesses and users.

The new bill represents another step in that direction and confirms the European Union’s commitment to a digital, competitive and secure financial ecosystem, where innovation and regulation evolve hand in hand.

At Adlanter, we help financial institutions, fintech companies and businesses navigate these changes from a legal, regulatory and compliance perspective, anticipating risks and supporting a smooth transition to the new European framework.

If you would like to assess how these developments may affect your organisation, our team of specialists will be happy to help.

Nuestros expertos

  • Adlanter

    Expertos en asesoría fiscal, laboral, mercantil, contable, movilidad internacional y gestión del talento. Compartimos análisis, novedades normativas y contenido especializado para ayudar a empresas y profesionales a tomar decisiones informadas y afrontar con seguridad los retos de un entorno empresarial en constante evolución.

Conversation

Do you have any questions?

If you have any questions after reading "Financial sector digitalisation: key aspects of the new bill and how to prepare for the upcoming regulatory changes", we are here to help you.

Let's talk. We guide you clearly and step by step.