Which financial entities may be identified for DORA TLPT?
Delegated Regulation 2025/1190 starts from the financial entity's impact, systemic character, and ICT risk profile. It points the TLPT authority to impact-related factors such as size, cross-border services, interconnectedness, criticality, substitutability, business-model complexity, and whether the entity belongs to a systemic group sharing ICT systems.
It also points to ICT-risk factors such as the entity's threat landscape, dependence of critical or important functions on ICT, ICT architecture complexity, use of ICT third-party or intra-group providers, supervisory review outcomes, business-continuity maturity, response-and-recovery maturity, and real-time monitoring, detection, analysis, and response capability.
- The RTS starts with specified categories and thresholds: G-SIIs, O-SIIs, and their member credit institutions; payment institutions above EUR 150 billion in payment transactions in each of the prior 2 calendar years; electronic money institutions above that payment threshold or EUR 40 billion in outstanding electronic money for each of those years; central securities depositories; central counterparties; qualifying electronic trading venues; and a subset of large insurance or reinsurance undertakings.
- The RTS also allows TLPT authorities to assess other types of financial entities where qualitative factors make TLPT appropriate.
- Meeting an entity-category or quantitative criterion is not the end of the analysis. The TLPT authority can release an entity where its overall impact, related financial-stability concerns, or ICT risk profile does not justify TLPT.
- Microenterprises and entities under the Article 16 simplified ICT risk management framework are excluded from TLPT by DORA Article 26(1); this is not an authority-discretion test.
Are DORA TLPT selection criteria just revenue, employee count, or generic security maturity?
No. The RTS uses sector-specific quantitative gates for some categories and an authority assessment of financial-sector impact, systemic character, ICT risk profile, ICT maturity, critical or important functions, shared systems, and group structure. Generic revenue, headcount, or cyber-maturity thresholds cannot replace that test.
Supports the impact, systemic-character, ICT-risk, entity-category, group/shared-system, and qualitative assessment criteria used for TLPT identification.
Supports that only identified financial entities perform advanced TLPT and that microenterprises and simplified-framework entities are not the target of TLPT selection.