“Who does DORA apply to?” is one of the most important questions in EU financial regulation right now — because the Digital Operational Resilience Act reaches further than many organizations expect. It covers not only financial firms but also the technology providers that serve them. This guide explains exactly who is in scope and how to check your own status.

For the full picture of the regulation, see our complete DORA guide.
The financial entities in scope
DORA applies to a very wide range of regulated financial entities operating in the EU. That includes credit institutions and banks, payment and electronic-money institutions, investment firms, insurance and reinsurance undertakings and intermediaries, crypto-asset service providers, central securities depositories, trading venues, fund and asset managers, credit rating agencies, and more. If your organization holds an EU financial-services authorisation, you should assume DORA applies and confirm the specifics for your category.
ICT third-party providers
DORA’s reach does not stop at financial firms. It extends to the ICT third-party providers that supply technology to them — cloud service providers, software vendors, data centre operators, and managed service providers. These suppliers feel DORA indirectly through the contractual and oversight obligations their financial customers must impose, covering audit rights, service levels, security, and exit strategies. Technology vendors serving EU finance therefore need to understand DORA even though they are not financial entities themselves.
Critical ICT third-party providers under direct oversight
A subset of the largest, most systemically important technology suppliers can be formally designated as critical ICT third-party providers. Once designated, they fall under direct oversight by the European Supervisory Authorities, which can assess their resilience, issue recommendations, and impose penalties. This is a significant development: for the first time, major technology platforms serving the financial sector face direct EU supervision of their operational resilience.
Proportionality: how DORA scales
DORA applies a principle of proportionality. While the core obligations apply broadly, the depth of what is expected scales with an entity’s size, risk profile, and systemic importance. Smaller entities benefit from a simplified ICT risk-management framework, whereas large, complex institutions face the full set of requirements including advanced threat-led penetration testing. Understanding where you sit on this spectrum is key to a proportionate, defensible compliance programme.
Are you in scope? A quick check
Ask two questions. First, are you a regulated financial entity authorised in the EU — or do you provide financial services to EU customers? If yes, DORA applies directly. Second, do you provide ICT services to EU financial entities? If yes, DORA reaches you through your customers’ obligations, and you may even face direct oversight if designated critical. Either answer means DORA belongs on your compliance roadmap now.
In scope? Get compliant faster.
Our DORA Toolkit gives financial entities and their suppliers the policies, procedures, and third-party register to meet DORA across all five pillars — editable in Word and Excel.
Frequently asked questions
Who does DORA apply to?
Nearly all EU-regulated financial entities — banks, insurers, investment firms, payment and crypto-asset providers and more — and the ICT third-party providers that serve them, including cloud and software vendors.
Does DORA apply to technology providers?
Yes, indirectly through their financial customers’ contractual and oversight obligations, and directly for those designated as critical ICT third-party providers under EU supervision.
Does DORA apply to small firms?
Yes, but proportionately. Smaller entities can use a simplified ICT risk-management framework, while large institutions face the full requirements.