NIS2 Compliance in Madrid

Madrid is Spain's financial capital and home to two of the world's largest banks: Banco Santander (€1.8T in assets, 170M+ customers globally) and BBVA (€760B in assets, operations in 25 countries). CaixaBank — formed by the 2021 merger with Bankia — is Spain's largest domestic bank. The IBEX 35 stock index, traded on Bolsas y Mercados Españoles (BME), lists most major Spanish financial institutions. Spain's Banco de España and CNMV (Comisión Nacional del Mercado de Valores) provide complementary oversight for banks and capital markets respectively, with additional supervision from DGSFP for insurance.

Request a demo
€1.8T
Santander total assets
€760B
BBVA total assets
35
Listed IBEX companies
180,000+
Financial sector employees

Why NIS2 matters in Madrid

The NIS2 Directive (EU 2022/2555) is the EU's updated cybersecurity legislation covering essential and important entities across 18 sectors. With penalties up to €10M or 2% of global turnover for essential entities, and personal liability for management bodies, NIS2 represents a significant escalation in EU cybersecurity enforcement. Germany's national transposition (NIS2UmsuCG) adds sector-specific requirements.

Santander and BBVA, operating across Latin America, Europe, and the US, face DORA compliance across dozens of subsidiaries with different regulatory regimes — making automated compliance platforms essential rather than optional. Spain transposed NIS2 through the Ley de Coordinación y Gobernanza de la Ciberseguridad in 2024, with INCIBE (National Cybersecurity Institute) handling incident coordination. The CNMV has been increasingly active in digital finance regulation, publishing guidance on cloud outsourcing and algorithmic trading that aligns with DORA. Madrid's thriving FinTech ecosystem — Bizum (mobile payments), Flywire, Aplazame — operates under PSD2 and DORA, requiring compliance automation to scale. The Banco de España's fintech sandbox has accelerated digital innovation while simultaneously raising compliance expectations.

Supervisory Bodies

Banco de España, CNMV, DGSFP

Key Industries

  • Global Banking & G-SIBs
  • Insurance & Asset Management
  • Capital Markets & BME
  • FinTech & Payments

Notable financial institutions in Madrid

Banco SantanderBBVACaixaBankBankinterMapfreMutua MadrileñaBolsas y MercadosBizum

NIS2 Key Requirements

Cybersecurity risk management measures (Art. 21)
24-hour early warning + 72-hour full incident notification
Supply chain and third-party security assessment
Vulnerability disclosure and coordinated handling
Management body training and personal accountability
Business continuity and crisis management plans