Who is in scope: financial entities and ICT providers
DORA requires that nearly all EU-based financial entities and the ICT third-party service providers they rely on adhere to a unified set of digital resilience standards. It establishes a broad jurisdictional net to ensure that both the regulated firm and its technology supply chain can withstand, respond to, and recover from ICT-related disruptions.
What it means
The intent is to eliminate regulatory fragmentation across the EU financial sector by creating a single rulebook for operational resilience. Rather than relying on various national laws or specific sectoral guidelines, DORA applies a comprehensive set of requirements to almost every type of financial institution operating within the Union.
In practice, "financial entities" include credit institutions, payment and electronic money institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers (CASPs), and others listed in Article 2. While some exemptions exist for very small or non-interconnected firms, most traditional and fintech organizations are captured.
Crucially, the scope extends beyond the financial entity to "ICT third-party service providers." This means any company providing data processing, cloud services, software, or network infrastructure to a financial entity is brought into the regulatory orbit, particularly if they support "critical or important functions."
How to meet it
- Perform a formal legal gap analysis against Article 2 to confirm whether your organization qualifies as a "financial entity" or an "ICT third-party service provider."
- Document any claims of exemption (e.g., for small and non-interconnected investment firms) based on the specific criteria provided in the regulation.
- Create a comprehensive inventory of all ICT third-party service providers currently engaged by the organization.
- Classify each ICT provider based on whether the services they provide support "critical or important functions" as defined by DORA.
- Notify existing ICT vendors of their status under DORA to ensure they are preparing for potential oversight and contractual alignment.
- Map the flow of data and dependencies between your entity and its ICT providers to visualize the scope of the operational resilience perimeter.
Evidence an auditor asks for
- A signed Applicability Assessment or Compliance Scope document confirming the organization's status under Article 2.
- An updated Register of Information containing a full list of all contracted ICT third-party service providers.
- The methodology and records used to categorize services as "critical or important" versus non-critical.
- Contractual addendums or letters of acknowledgement from ICT providers confirming their awareness of DORA requirements.
Common pitfalls
- Assuming a firm is exempt simply because it is small, without verifying if it meets the specific legal thresholds for exemption.
- Defining "ICT provider" too narrowly (e.g., only thinking of cloud hosts) and ignoring managed service providers or specialized software vendors.
- Failing to distinguish between general ICT services and those supporting critical functions, leading to either excessive overhead for low-risk vendors or insufficient oversight for high-risk ones.