Compliance Guides
Does DORA apply to my company?
The prospects who raise DORA with me usually think it does not reach them, and they are usually wrong. Two tests decide it, and here is what it requires once you are in scope.
Most company owners and CEOs I speak to about DORA open by explaining why it does not reach them. It might be a software firm that sells into a couple of banks, or a small payment company sure it sits under the size where anyone cares. They are usually wrong, and they are usually uncomfortable when I walk them through why. DORA, the Digital Operational Resilience Act, applies to you if you are a financial entity operating in the EU, or an ICT third-party provider serving those entities. It has applied since 17 January 2025. If you are a bank, insurer, investment firm, payment or e-money institution, crypto-asset service provider, or a technology company supplying any of them, you are very likely in scope. Two tests decide it, and I put them to work in almost every one of those conversations.
Who does DORA apply to?
Two groups. Financial entities authorised or operating in the EU, and the ICT third-party providers that serve them. The two tests below tell you which of them is you, or whether both are.
Test 1: are you a "financial entity"?
DORA does not leave this to interpretation. It lists the financial entities it covers: credit institutions, payment institutions, e-money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, and several more. If your firm holds an EU financial licence or authorisation, start from the assumption that you are in scope, and go looking for a specific exemption rather than hoping one applies to you.
- Definition
- Financial entity (DORA)
- One of the categories of firm DORA lists directly, credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, and insurance and reinsurance undertakings among them. Holding an EU financial licence generally means you are a financial entity under DORA unless a specific exemption applies.
Article 2(1) names 20 types of financial entity. When I go through them with company owners, I group them by sector, because that is how they recognise themselves:
| Sector | Financial entities in scope (Article 2(1)) |
|---|---|
| Banking and payments | Credit institutions; payment institutions, including exempted ones; account information service providers; electronic money institutions, including exempted ones |
| Investment and market infrastructure | Investment firms; trading venues; central counterparties; central securities depositories; trade repositories; data reporting service providers; securitisation repositories; credit rating agencies; administrators of critical benchmarks |
| Funds | Managers of alternative investment funds; UCITS management companies |
| Insurance and pensions | Insurance and reinsurance undertakings; insurance, reinsurance and ancillary insurance intermediaries; institutions for occupational retirement provision |
| Crypto and crowdfunding | Crypto-asset service providers authorised under MiCA, and issuers of asset-referenced tokens; crowdfunding service providers |
Then read the exclusions in Article 2(3), because that is where most of the wishful thinking ends. Only six groups are out: small alternative investment fund managers under Article 3(2) of the AIFM Directive, insurers exempted under Article 4 of Solvency II, pension institutions whose schemes have no more than 15 members in total, persons exempted under Articles 2 and 3 of MiFID II, insurance and reinsurance intermediaries that are micro, small or medium-sized enterprises, and post office giro institutions. Member states may also exclude a few entities listed in the Capital Requirements Directive. If you are not on that list, being small does not take you out. It only makes the load lighter.
Test 2: are you an ICT third-party provider to financial entities?
If you supply ICT services to EU financial entities, cloud, software, data, or managed services, DORA reaches you through your customers' own third-party risk requirements. If a regulator designates you critical, it reaches you directly, through its own oversight. Being based outside the EU does not get you out of it: what matters is that your customer is an in-scope financial entity. The direct route is no longer theoretical, either. On 18 November 2025 the three European Supervisory Authorities designated the first 19 critical ICT third-party providers, Amazon Web Services, Google Cloud and Microsoft among them. A critical provider that ignores its Lead Overseer can be charged up to 1% of its average daily worldwide turnover, every day, for up to six months. This is the test that catches technology suppliers off guard, because they rarely thought of themselves as regulated until a banking client sent them a DORA clause to sign. If that is you, it is worth understanding how a tool ends up a regulated third party in the first place.
What DORA requires if it applies
Once either test catches you, DORA's requirements fall into five areas:
- ICT risk management, a documented framework for identifying, protecting, detecting, and recovering.
- ICT-related incident reporting, classifying and reporting major incidents to your competent authority.
- Digital operational resilience testing, regular testing, up to threat-led penetration testing for larger entities.
- ICT third-party risk management, including the specific contractual terms required under Article 30.
- Information sharing, the voluntary exchange of cyber-threat intelligence.
Smaller entities get some relief. Under Article 16, small and non-interconnected investment firms, exempted payment and e-money institutions and small pension institutions may run a simplified ICT risk-management framework instead of Articles 5 to 15. Proportionality applies across the rest of DORA too, so the weight scales with your size and complexity.
The dates and clocks that matter
| What | When |
|---|---|
| DORA enters into force | 16 January 2023 |
| DORA applies | 17 January 2025 |
| First critical ICT third-party providers designated | 18 November 2025 (19 providers) |
| Major ICT incident, initial notification | Within 4 hours of classifying it as major, and no later than 24 hours after becoming aware of it |
| Major ICT incident, intermediate report | Within 72 hours of the initial notification |
| Major ICT incident, final report | Within one month of the latest intermediate report |
| Threat-led penetration testing | At least every 3 years, for the financial entities authorities identify for it |
The incident clock is the one that hurts in practice. Four hours is not long enough to find out who is allowed to classify an incident as major, so settle that before you need it.
How COMPLY.Reg helps
The gap I see over and over is the distance between the PDF and the day job. DORA is a long regulation, and reading it does not tell your team what to actually do on Monday. Closing that gap is much of why we built COMPLY.Reg. It uses AI to pull DORA's individual requirements out of the text, maps each one to a control, and tracks the evidence that proves the control is working, so an audit reads as a traceable record instead of a last-minute scramble. You can keep your source documents on your own systems, and your compliance data is processed in the EU, which for me is not negotiable. If you are not sure DORA is the only regime you have to worry about, start with which EU regulations apply to your company.
Frequently asked questions
- Who does DORA apply to?
- Two groups. Financial entities authorised or operating in the EU: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and others DORA lists. And the ICT third-party providers that serve them, including providers established outside the EU.
- When did DORA start applying?
- It has applied since 17 January 2025.
- Does DORA apply to non-EU companies?
- Yes, indirectly and sometimes directly. If you provide ICT services to EU financial entities, DORA's third-party requirements reach you through those relationships, wherever your head office sits.
- Which companies are excluded from DORA?
- Article 2(3) excludes six groups: small alternative investment fund managers under Article 3(2) of the AIFM Directive, insurers exempted under Article 4 of Solvency II, pension institutions whose schemes have no more than 15 members in total, persons exempted under Articles 2 and 3 of MiFID II, insurance and reinsurance intermediaries that are micro, small or medium-sized enterprises, and post office giro institutions. Member states may also exclude certain entities listed in the Capital Requirements Directive.
- Is there a lighter regime for small firms?
- Yes. Under Article 16, small and non-interconnected investment firms, exempted payment and e-money institutions and small pension institutions may run a simplified ICT risk-management framework instead of Articles 5 to 15. Proportionality also applies across DORA, so the weight scales with size and complexity.
- Who are the critical ICT third-party providers under DORA?
- On 18 November 2025 the three European Supervisory Authorities designated the first 19 critical ICT third-party providers, including Amazon Web Services, Google Cloud and Microsoft. They are overseen directly by a Lead Overseer, which can impose a periodic penalty of up to 1% of average daily worldwide turnover for up to six months.
Sources
- DORA, Regulation (EU) 2022/2554
- DORA Article 2, scope and exclusions
- DORA Article 16, simplified ICT risk management framework
- DORA Article 26, threat-led penetration testing
- DORA Article 30, contractual arrangements for ICT services
- DORA Article 35, oversight powers and periodic penalty payments
- Commission Delegated Regulation (EU) 2025/301, incident reporting time limits
- ESAs designate critical ICT third-party providers (18 November 2025)
