DORA Article 2 lists the covered financial entity categories and separately includes ICT third-party service providers. The financial-entity list covers banks, payment and e-money institutions, account information service providers, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, trade repositories, fund managers and management companies, data reporting service providers, insurance and reinsurance undertakings, insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries, IORPs, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers, and securitisation repositories.
A scope record should therefore identify the exact authorised entity, its regulated category, its competent-authority perimeter, and any branch or group role. Do not classify a product team, platform, or supplier as in scope until the legal entity using or providing the ICT service has been named.