← Thought Leadership

Compliance Guides

Does DORA apply to my company?

The prospects who raise DORA with me usually think it does not reach them, and they are usually wrong. Two tests decide it, and here is what it requires once you are in scope.

Jan Jensen
Co-founder
· Updated on · 5 min read
The Frankfurt financial district skyline at sunset

Photo: Jan Jobczyk / Unsplash

New to the topic? Start with What sovereign compliance actually means.

Most company owners and CEOs I speak to about DORA open by explaining why it does not reach them. It might be a software firm that sells into a couple of banks, or a small payment company sure it sits under the size where anyone cares. They are usually wrong, and they are usually uncomfortable when I walk them through why. DORA, the Digital Operational Resilience Act, applies to you if you are a financial entity operating in the EU, or an ICT third-party provider serving those entities. It has applied since 17 January 2025. If you are a bank, insurer, investment firm, payment or e-money institution, crypto-asset service provider, or a technology company supplying any of them, you are very likely in scope. Two tests decide it, and I put them to work in almost every one of those conversations.

Who does DORA apply to?

Two groups. Financial entities authorised or operating in the EU, and the ICT third-party providers that serve them. The two tests below tell you which of them is you, or whether both are.

Test 1: are you a "financial entity"?

DORA does not leave this to interpretation. It lists the financial entities it covers: credit institutions, payment institutions, e-money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, and several more. If your firm holds an EU financial licence or authorisation, start from the assumption that you are in scope, and go looking for a specific exemption rather than hoping one applies to you.

Definition
Financial entity (DORA)
One of the categories of firm DORA lists directly, credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, and insurance and reinsurance undertakings among them. Holding an EU financial licence generally means you are a financial entity under DORA unless a specific exemption applies.

Test 2: are you an ICT third-party provider to financial entities?

If you supply ICT services to EU financial entities, cloud, software, data, or managed services, DORA reaches you through your customers' own third-party risk requirements. If a regulator designates you critical, it reaches you directly, through its own oversight. Being based outside the EU does not get you out of it: what matters is that your customer is an in-scope financial entity. This is the test that catches technology suppliers off guard, because they rarely thought of themselves as regulated until a banking client sent them a DORA clause to sign. If that is you, it is worth understanding how a tool ends up a regulated third party in the first place.

What DORA requires if it applies

Once either test catches you, DORA's requirements fall into five areas:

  • ICT risk management, a documented framework for identifying, protecting, detecting, and recovering.
  • ICT-related incident reporting, classifying and reporting major incidents to your competent authority.
  • Digital operational resilience testing, regular testing, up to threat-led penetration testing for larger entities.
  • ICT third-party risk management, including the specific contractual terms required under Article 30.
  • Information sharing, the voluntary exchange of cyber-threat intelligence.

Smaller and less complex entities get some relief here. DORA carries a proportionality principle, and in some cases lets them run a simplified ICT risk-management framework, so the weight scales with your size and complexity.

How COMPLY.Reg helps

The gap I see over and over is the distance between the PDF and the day job. DORA is a long regulation, and reading it does not tell your team what to actually do on Monday. Closing that gap is much of why we built COMPLY.Reg. It uses AI to pull DORA's individual requirements out of the text, maps each one to a control, and tracks the evidence that proves the control is working, so an audit reads as a traceable record instead of a last-minute scramble. Your source documents stay on your own systems, and your compliance data is processed in the EU, which for me is not negotiable. If you are not sure DORA is the only regime you have to worry about, start with which EU regulations apply to your company.

Frequently asked questions

Who does DORA apply to?
Two groups. Financial entities authorised or operating in the EU: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and others DORA lists. And the ICT third-party providers that serve them, including providers established outside the EU.
When did DORA start applying?
It has applied since 17 January 2025.
Does DORA apply to non-EU companies?
Yes, indirectly and sometimes directly. If you provide ICT services to EU financial entities, DORA's third-party requirements reach you through those relationships, wherever your head office sits.
Is there a lighter regime for small firms?
Yes. DORA carries a proportionality principle, and certain entities may run a simplified ICT risk-management framework, so the weight scales with your size and complexity.

Sources