Skip to content
rPResiliencePilot
All resources
DORA6 min read·31 July 2026

Is your organisation in scope for DORA? Who the regulation actually covers

A plain-English guide to DORA scope: the financial entities named in Article 2, who's carved out, why small doesn't mean exempt, and how DORA reaches ICT providers that serve the sector.

The Frankfurt financial-district skyline at dusk, its banking towers lit against a grey sky

Unlike NIS2, DORA doesn't ask you to work out which sector you're in. It names its targets directly. The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applies to a defined list of financial entities, and it has applied since 17 January 2025. Roughly 22,000 firms across the EU are in scope.

So the scoping question splits cleanly in two. First: are you one of the financial entities named in the regulation? Second, and this is the part technology companies miss: even if you're not, does DORA reach you because you serve those entities?

Are you a "financial entity"?

Article 2 lists around twenty types of financial entity. Grouped into something readable, they are:

  • Banking and payments: credit institutions, payment institutions, account information service providers, and electronic money institutions.
  • Investment and markets: investment firms, central securities depositories, central counterparties, trading venues, trade repositories, data reporting service providers, managers of alternative investment funds, UCITS management companies, securitisation repositories, credit rating agencies, and administrators of critical benchmarks.
  • Insurance and pensions: insurance and reinsurance undertakings, insurance and ancillary insurance intermediaries, and institutions for occupational retirement provision (IORPs).
  • Crypto and crowdfunding: crypto-asset service providers and issuers of asset-referenced tokens under MiCA, and crowdfunding service providers.

If your firm is on that list, you're in scope. There's no sector test and no "critical operator" designation to wait for, the way there is under NIS2.

Who's carved out

Article 2(3) names a set of exclusions. The main ones are:

  • managers of alternative investment funds that fall under the sub-threshold registration regime,
  • certain insurance and reinsurance intermediaries that are micro, small or medium-sized enterprises,
  • IORPs operating pension schemes with fewer than 15 members in total,
  • post office giro institutions,
  • natural persons, and
  • persons already exempt under Articles 2 and 3 of MiFID II.

If one of these describes you, DORA's direct obligations don't apply, though you may still meet them indirectly through the firms you work with.

Small doesn't mean exempt

This is the most common misreading of DORA. Being small changes how much you have to do, not whether you're covered.

The regulation is built on a proportionality principle (Article 4): obligations scale with your size, risk profile, and the nature, scale and complexity of your services. Genuinely small players get a lighter regime rather than a pass. A simplified ICT risk-management framework (Article 16) is available to small and non-interconnected investment firms, certain small payment and e-money institutions, micro-to-medium insurance intermediaries, and IORPs with fewer than 100 members. And a microenterprise, defined as fewer than 10 staff and turnover or balance sheet of at most €2 million, is exempt from some specific requirements, such as elements of the testing regime, but not from DORA itself.

The takeaway: if you're a named financial entity, assume you're in and then work out which tier of obligation you fall into, not the other way round.

Not a financial entity? DORA may still reach you

Here's the part that surprises technology businesses. DORA governs how financial entities manage the risk in their ICT supply chain, and that pushes obligations outward to the providers themselves. If you sell cloud, software, data centre, or managed services to banks, insurers or investment firms, you'll meet DORA in two ways.

  • Indirectly, through your contracts. Your financial-sector clients have to hold contracts that meet DORA's requirements: specific mandatory clauses, audit and access rights, exit strategies, and inclusion in the register of information that every financial entity must maintain and report on their ICT third-party arrangements. In practice that means your agreements and your due-diligence answers have to change, even though the regulation never names you.
  • Directly, if you're designated critical. The European Supervisory Authorities can designate a provider a critical ICT third-party provider. Those firms come under a dedicated Oversight Framework, with a Lead Overseer that can examine them, issue recommendations and, ultimately, fine them. This is the one route by which a technology company can be regulated by DORA in its own right.

So the honest answer for a provider is: you probably won't be named, but you'll feel DORA through every financial client you have.

The date that already passed

DORA is not a future deadline to plan around. It entered into force in January 2023 and has applied since 17 January 2025. The first submissions of the register of information, and the expectation of a working ICT risk-management framework, are already behind us. If you're in scope and still treating this as upcoming, the gap to close is a compliance gap today, not a project for next year.

In scope, now what

DORA rests on five pillars: ICT risk management, incident reporting (classify and report major ICT-related incidents to your competent authority), digital operational resilience testing, ICT third-party risk management (the register of information and contractual requirements), and information sharing. If you want to know whether a given incident crosses the "major" threshold you have to report, our DORA incident reportability calculator walks the official criteria, and DORA Article 30 explained covers the contractual side.

Because DORA and NIS2 overlap heavily on continuity and testing, many groups run one ISO 22301 system across both rather than building twice. If you're weighing which applies to you, DORA vs NIS2 sets them side by side.

Not certain where you land?

Scope is usually clear for DORA, but the tier of obligation, and the exemptions around intermediaries and funds, repay a careful read. Our DORA readiness assessment walks the requirements clause by clause, and you can see how ResiliencePilot covers DORA across all five pillars. When you want to talk through your own position, book a demo.

See ResiliencePilot in action

See it on your own data and frameworks, with your security and data-residency questions answered.