DORA applies to the financial entities listed in Article 2 of Regulation (EU) 2022/2554, including banks, payment institutions, investment firms, insurers, crypto-asset service providers and several other regulated financial-sector entities. The Regulation also creates obligations and an oversight framework relevant to ICT third-party service providers. Article 2 contains specific exclusions, so organisations should confirm scope against their legal entity type and applicable national framework.
FAQ
Regulatory Compliance