D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Spain's AML/CFT regime rests on Law 10/2010 and its implementing regulation, with Sepblac acting as both FIU and primary AML/CFT supervisor.
Law made at European Economic Area level that applies in Spain is covered once, on the European Economic Area page. This page covers Spain’s own layer: implementation, national authorities, national options and local enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Spain's MiCA transitional period for legacy virtual-asset service providers concluded on 1 July 2026, a fact stated directly in the CNMV's own FAQ documentation covering the transitional close-out. From that date, only CNMV-authorised crypto-asset service providers, or those authorised elsewhere in the EU and passported into Spain, may lawfully provide crypto-asset services in the jurisdiction. Read through the financial-integrity lens, this is not primarily a licensing-architecture story but an on-ramp-surface story: the population of entities through which value can move into and out of the crypto-asset ecosystem in Spain has just been narrowed and consolidated under a single supervisory authority, replacing what had previously been a dual Banco de España/CNMV structure.
That consolidation matters for AML/CFT exposure because a fragmented authorisation landscape, with legacy registrants operating alongside newly authorised CASPs, tends to create exactly the kind of supervisory seams that illicit finance typologies exploit -- entities that are technically registered somewhere but not subject to the full weight of MiCA's substantive AML-adjacent obligations. With the transitional period closed, that seam should in principle narrow considerably, provided enforcement follow-through actually displaces any legacy registrant that failed to secure full CNMV authorisation. Whether any such registrant currently continues to operate outside the lawful perimeter was not established this cycle; this is an evidentiary gap rather than either a finding of continued non-compliance or a clean bill of health, and it should be read as exactly that pending further verification.
The structural significance of this development is best understood in light of the standing AMLA architecture that governs the broader EU framework within which Spain's crypto-specific consolidation sits. The EU AML Package consists of three distinct instruments: the AML Regulation, or AMLR (Regulation (EU) 2024/1624), which applies directly across the EU including in Spain without need for national transposition; the sixth AML Directive, or 6AMLD, which each member state transposes into its own national law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and begins shifting supervision of certain higher-risk obliged entities from purely national authorities toward a hybrid EU-level regime combining direct and indirect AMLA supervision. Spain's binding to AMLR's direct-application mechanism as an EU-27 EEA member is a confirmed structural fact; no Spain-specific 6AMLD transposition delta, nor any AMLA direct-supervision designation bearing on Spain's crypto-asset sector specifically, was independently retrieved this cycle. That absence should be read as an unestablished item rather than as evidence either that transposition is complete or that it remains outstanding.
Against this backdrop, Spain's MiCA-driven crypto consolidation is best read as a jurisdiction-level implementation of a framework, MiCA itself, that sits alongside rather than inside the AMLR/6AMLD/AMLA architecture, though the two frameworks share an evident policy objective of narrowing the space in which illicit finance can exploit fragmented or dual-track authorisation regimes. The practical AML/CFT question going forward is less about the legal architecture, which is now reasonably clear, and more about enforcement follow-through against any residual legacy activity.
The item most worth tracking is whether the CNMV, now sole gatekeeper, takes any enforcement action against a legacy Banco de España registrant that failed to secure full CASP authorisation before the 1 July 2026 cliff. General industry practice is understood to require wind-down of unauthorised legacy activity following such a transitional close-out, but the distance between that general expectation and the actual practice of any specific firm operating in Spain was not assessed this cycle, leaving this as the key open question for the crypto/AML intersection going into the next reporting period. Confirmation of Spain's specific 6AMLD transposition status, and clarity on whether any AMLA supervisory designation will bear on Spain's crypto-asset sector, would further sharpen the picture of how the broader EU AML Package architecture interacts with the newly consolidated national crypto licensing gate.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
AML/CTF Regime is not yet covered for this jurisdiction in this report.
Commercial Activity is not yet covered for this jurisdiction in this report.
The population of entities through which crypto-asset value can enter or exit the Spanish financial system has consolidated under a single supervisory authority. MLROs should confirm counterparty CASP authorisation status when onboarding or continuing relationships with Spanish crypto-asset entities, given the closed transitional window.
Compliance functions maintaining Spain-facing crypto-asset relationships should update internal registers to reflect that legacy Banco de España registration alone no longer evidences a valid crypto-asset services licence.
No material change for this persona this cycle
The board-level risk picture for Spain remains favourable overall but should note the standing sanctions-implementation gap as a residual jurisdictional risk factor, distinct from the generally strong compliance rating across the bulk of FATF's 40 Recommendations.
Technical integration and counterparty-screening infrastructure connecting to Spanish crypto-asset service providers should be updated to reflect the single-gate CNMV authorisation model, replacing any legacy dual-track verification logic built around the former Banco de España register.
Risk functions should treat the population of Spain-facing crypto counterparties as requiring active authorisation-status verification, since the evidence base does not establish whether any legacy registrant continues to operate outside the lawful perimeter.
No material change for this persona this cycle
Audit should note this as an open documentation gap rather than an assumed-complete transposition, when assessing the adequacy of jurisdictional AML-framework coverage for Spain.
CNMV becomes sole CASP-authorisation gate in Spain from 1 July 2026, narrowing the crypto AML on-ramp surface.
Spain's dual Banco de España/CNMV crypto authorisation architecture has narrowed to a single CNMV gate.
No material change this cycle.
FATF continues to rate Spain strongly on AML/CFT overall, but flags a persistent gap in targeted financial sanctions implementation.
Spain's crypto-asset authorisation architecture consolidated to a single CNMV technical gatekeeper as of 1 July 2026.
Legacy VASP registrants that did not secure CNMV CASP authorisation before 1 July 2026 present an unquantified residual exposure.
No material change this cycle.
Spain's EEA binding to direct AMLR application is confirmed, but 6AMLD transposition status and AMLA designation remain unverified for this cycle.
Illustrative scenario for analytical orientation only: as the AMLA Regulation's direct and indirect supervision perimeter continues to consolidate across the EU, a jurisdiction like Spain, currently bound only through AMLR's direct-application mechanism with no confirmed AMLA-specific designation, could see certain cross-border-active obliged entities, potentially including crypto-asset service providers operating across multiple EEA states, shift toward AMLA direct supervision rather than purely national CNMV oversight. This would not replace CNMV's role as national CASP-authorising authority but could layer an additional EU-level supervisory dimension onto the largest or most cross-border-exposed entities. This is illustration of a structural possibility, not an observed development or a prediction of Spain-specific AMLA designation.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | no_change | No material Spain-specific signal this cycle. |
| T2 · EU AML Package / AMLA | watch | Spain's EEA chain_parent binding to AMLR direct application confirmed structurally; no Spain-specific 6AMLD transposition delta retrieved this cycle. |
| T3 · FATF Grey List | no_change | Spain not grey-listed; June 2026 plenary changes do not bear on Spain. |
| T4 · Beneficial-Ownership Register Status | no_change | No Spain-specific BO-register effectiveness change surfaced this cycle. |
| T5 · Crypto / VASP Regulatory Framework | material_change | CNMV becomes sole CASP-authorising gate as Spain's MiCA transitional period concludes. |
| T6 · Sanctions Regime Divergence | no_change | No Spain-specific autonomous-listing divergence signal surfaced this cycle. |