Auditen
Home / Frameworks / DORA / Who is in scope: financial entities and ICT providers
DORA · Art. 2

Who is in scope: financial entities and ICT providers

DORA requires that nearly all EU-based financial entities and the ICT third-party service providers they rely on adhere to a unified set of digital resilience standards. It establishes a broad jurisdictional net to ensure that both the regulated firm and its technology supply chain can withstand, respond to, and recover from ICT-related disruptions.

What it means

The intent is to eliminate regulatory fragmentation across the EU financial sector by creating a single rulebook for operational resilience. Rather than relying on various national laws or specific sectoral guidelines, DORA applies a comprehensive set of requirements to almost every type of financial institution operating within the Union.

In practice, "financial entities" include credit institutions, payment and electronic money institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers (CASPs), and others listed in Article 2. While some exemptions exist for very small or non-interconnected firms, most traditional and fintech organizations are captured.

Crucially, the scope extends beyond the financial entity to "ICT third-party service providers." This means any company providing data processing, cloud services, software, or network infrastructure to a financial entity is brought into the regulatory orbit, particularly if they support "critical or important functions."

How to meet it

Evidence an auditor asks for

  • A signed Applicability Assessment or Compliance Scope document confirming the organization's status under Article 2.
  • An updated Register of Information containing a full list of all contracted ICT third-party service providers.
  • The methodology and records used to categorize services as "critical or important" versus non-critical.
  • Contractual addendums or letters of acknowledgement from ICT providers confirming their awareness of DORA requirements.

Common pitfalls

  • Assuming a firm is exempt simply because it is small, without verifying if it meets the specific legal thresholds for exemption.
  • Defining "ICT provider" too narrowly (e.g., only thinking of cloud hosts) and ignoring managed service providers or specialized software vendors.
  • Failing to distinguish between general ICT services and those supporting critical functions, leading to either excessive overhead for low-risk vendors or insufficient oversight for high-risk ones.