DORA's core operational-resilience duties apply to the listed financial entities, including credit institutions, payment institutions, account information service providers, electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, trade repositories, fund managers, management companies, insurance and reinsurance undertakings, insurance intermediaries, occupational pension institutions, credit rating agencies, critical benchmark administrators, crowdfunding service providers, and securitisation repositories. Article 2 lists ICT third-party service providers separately: financial entities must govern those dependencies and contracts, while providers designated as critical are subject to the Union oversight framework.
DORA also contains specific exclusions and proportionality rules. Small size alone does not create an exclusion or make an entity eligible for the Article 16 simplified framework. In-scope financial entities apply the relevant ICT risk management, incident, testing, and ICT third-party-risk rules proportionately, but fixed duties and minimum frequencies still apply where DORA states them.
Which organisations are in scope of EU DORA?
DORA's financial-entity duties cover the regulated categories listed in Article 2, including banks, payment and e-money institutions, investment firms, trading venues, central counterparties, central securities depositories, insurers, relevant intermediaries, fund managers, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers, securitisation repositories, and crypto-asset service providers. ICT third-party service providers are listed separately. Their services are governed through financial-entity third-party controls and contracts; only providers designated as critical enter DORA's Union oversight framework.
Does EU DORA apply the same way to every financial entity?
No. Article 4 requires proportionality based on the entity's size, overall risk profile, and the nature, scale, and complexity of its services, activities, and operations. Proportionality can change the design and depth of controls, but it does not remove fixed duties such as reporting a major ICT-related incident, maintaining the register of information, or meeting an express testing minimum.
What is a critical or important function under EU DORA?
A critical or important function is one where disruption would materially impair the entity's financial performance, service continuity, authorisation conditions, or other obligations under financial services law. This classification drives contract clauses, exit plans, subcontractor review, register data, and TLPT scoping.