RegTech

DORA Entities Guide: Is Your Organisation In Scope?

Igera Solutions
June 17, 2026
8 min read
DORA entities scope guide EU 2022/2554 financial entities in scope

Last updated: June 2026 · 8 min read · Author: Igera Solutions RegTech Team

Direct answer: DORA (Regulation EU 2022/2554) applies to over 20 categories of financial entities operating in the EU, as well as ICT third-party service providers designated as "critical" by the European Supervisory Authorities (ESAs). It has been mandatory since 17 January 2025 with no grace period. The key question is not whether DORA applies to financial services broadly — it does — but which specific obligations apply to your entity category and size, and whether any proportionality or exemption provisions reduce your compliance burden.

DORA scope — Art. 2: Article 2 of DORA lists all in-scope entities. The regulation applies to all entities authorised or registered under specific EU Directives (CRD, Solvency II, MiFID II, PSD2, AIFMD, UCITS, etc.) and to ICT third-party service providers serving them. It does not apply to entities providing only physical infrastructure (datacentre landlords, cable operators) unless they also provide ICT services.

1. Financial entities in scope — the full list

DORA Art. 2(1) covers the following entity types (references are to the EU Directives under which they are authorised):

Banking and credit

  • Credit institutions (banks, building societies — CRD IV/VI)
  • Payment institutions (including e-money institutions — PSD2)
  • Account information service providers (AISPs — PSD2)

Investment and markets

  • Investment firms (MiFID II)
  • Crypto-asset service providers (MiCA — from 30 December 2024)
  • Central securities depositories (CSDR)
  • Central counterparties / CCPs (EMIR)
  • Trading venues — regulated markets, MTFs, OTFs (MiFID II)
  • Trade repositories (EMIR)
  • Data reporting services providers (MiFID II Art. 59)

Insurance and pensions

  • Insurance and reinsurance undertakings (Solvency II)
  • Insurance holding companies (Solvency II)
  • Insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries (IDD)
  • Institutions for occupational retirement provision / IORPs (IORP II) — only if they have more than 15 members

Fund management

  • Alternative investment fund managers / AIFMs (AIFMD)
  • UCITS management companies (UCITS Directive)

Other financial entities

  • Credit rating agencies (CRA Regulation)
  • Administrators of critical benchmarks (BMR)
  • Crowdfunding service providers (ECSPR)
  • Securitisation repositories (Securitisation Regulation)
  • Managers of alternative investment funds not authorised under AIFMD (certain sub-threshold AIFMs)

2. ICT third-party service providers — who is affected

DORA distinguishes between:

  • All ICT third-party service providers: Must comply with contractual requirements in Art. 28–30 (minimum contract clauses, exit strategies, audit rights). This applies broadly to any provider of cloud, SaaS, data analytics or hardware services to in-scope financial entities.
  • Critical ICT third-party service providers (CTPPs): Designated by the ESAs based on systemic importance. CTPPs are subject to an EU-level oversight framework under Art. 31–44, including on-site inspections by a Lead Overseer (EBA, ESMA or EIOPA). As of June 2026, a first batch of CTPPs has been designated — including major cloud providers serving EU financial institutions.

Key point: Being a CTPP does not make a provider a regulated financial entity — they remain subject to their own sector regulation. However, CTPP designation triggers a binding oversight relationship with the relevant ESA Lead Overseer. Recommendations issued by the Lead Overseer are not formally binding but non-compliance must be explained to the financial entities they serve.

3. Exemptions and proportionality

Micro-enterprises (Art. 16)

Micro-enterprises — defined as fewer than 10 employees and annual turnover or balance sheet total not exceeding €2 million — benefit from a simplified ICT risk management framework under Art. 16. They may:

  • Adopt a simplified, documented ICT risk management framework (not the full five-pillar Art. 5–16 framework)
  • Use a combined ICT risk and information security policy document
  • Apply lighter testing requirements (basic vulnerability assessments in place of TLPT)

However, micro-enterprises are not exempt from: Art. 17–23 incident reporting obligations, Art. 28–30 ICT third-party contractual requirements (though simplified), or general governance and board-level ICT risk oversight.

Excluded entities (Art. 2(3))

DORA explicitly excludes:

  • Managers of alternative investment funds (AIFMs) that are sub-threshold and not required to be authorised under AIFMD — unless they are in scope as another entity type
  • Insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries that are microenterprises or small/medium-sized enterprises — unless a Member State opts them in under national law
  • Post offices providing financial services — explicitly excluded
  • Central banks — explicitly excluded
  • National competent authorities — excluded

4. Obligations by entity size — summary

Obligation Standard entities Micro-enterprises
ICT risk management framework (Art. 5–16) Full Simplified (Art. 16)
Major incident reporting (Art. 17–23) Full (4h/72h/1m) Full — no exemption
Digital operational resilience testing (Art. 24–27) Full (incl. TLPT for significant) Basic vulnerability assessment only
ICT third-party risk (Art. 28–30) Full contract requirements Simplified
Information sharing (Art. 45) Voluntary Voluntary

5. UK position post-Brexit

DORA is an EU regulation and does not directly apply in the UK. However, UK regulators have introduced parallel requirements:

  • FCA/PRA Operational Resilience Policy (SS1/21, PS6/21): In force since 31 March 2022, requires firms to set impact tolerances for important business services and test their ability to remain within them. Full compliance required by 31 March 2025.
  • FCA Critical Third Parties (CTP) Regime: Designation framework for systemic ICT providers under the Financial Services and Markets Act 2023. Parallel to DORA's CTPP regime but UK-specific.
  • Equivalence: The UK has not formally recognised DORA as equivalent. UK firms with EU branches must comply with DORA for their EU operations. EU groups with UK subsidiaries must comply with both regimes.

FAQs

Does DORA apply to non-EU companies serving EU financial entities?

Yes, indirectly. Non-EU ICT third-party service providers that provide services to EU financial entities are subject to DORA's contractual requirements (Art. 28–30). If designated as a critical third-party provider, non-EU providers must establish a subsidiary or representative within the EU to engage with the Lead Overseer. The ESAs cannot enforce against a non-EU provider directly, but EU financial entities may be penalised if they use non-compliant providers.

Is a SaaS provider to a bank automatically in scope for DORA?

Yes, to the extent that it must comply with DORA Art. 28–30 contractual requirements — minimum contract content, audit rights, exit strategies, and business continuity obligations. Whether the SaaS provider is designated as a critical third-party provider (CTPP) depends on an ESA assessment of its systemic importance. Most SaaS providers will not be designated as CTPPs but must still ensure their contracts with in-scope financial entities meet DORA standards.

Are fintechs subject to DORA?

Yes, if they are authorised under any of the directives listed in DORA Art. 2(1). Payment institutions and e-money institutions authorised under PSD2 are in scope. Crypto-asset service providers authorised under MiCA (from 30 December 2024) are in scope. Unlicensed fintechs providing no regulated financial services are not directly in scope as financial entities, but may be in scope as ICT third-party providers if they serve regulated entities.

Last updated: June 2026 | Sources: Regulation (EU) 2022/2554 (DORA) Art. 2, 16, 28–31; EBA/ESMA/EIOPA Joint Guidelines on DORA; ESA DORA Q&A (2025); FCA/PRA PS6/21 Operational Resilience; Financial Services and Markets Act 2023 (CTP regime) | Author: Igera Solutions RegTech Team | IgeraRegTech DORA — DORA readiness assessment available.

#DORA entities in scope#DORA scope financial entities#DORA who must comply#DORA exemptions#DORA third party ICT providers#DORA microenterprises exemption#EU 2022/2554 scope#DORA insurance in scope#DORA fintech scope#digital operational resilience act entities

COMPARTIR

Comparte el conocimiento con tu red