Scope, proportionality, accountability
Who is in scope
DORA applies to some twenty categories of financial entities: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, trade repositories, fund managers, insurance and reinsurance undertakings, insurance intermediaries, institutions for occupational retirement provision, credit rating agencies, benchmark administrators, crowdfunding service providers, and securitisation repositories.
Added to these, by designation, are critical ICT third-party service providers, subject to a direct European oversight framework.
A few entities benefit from a simplified framework under Article 16 — notably small investment firms and certain pension institutions. Simplified does not mean exempt: the fundamental requirements remain.
Proportionality
Article 4 allows requirements to be applied taking account of size, risk profile and the nature of activities. It modulates effort, it does not grant a dispensation.
The practical rule: any decision to simplify must be written, reasoned and approved. A three-page proportionality note, approved by the management body, explaining article by article what is simplified and why, is worth infinitely more than a general assertion in a meeting.
Article 5, the first one examined
DORA innovates by making the management body personally accountable for the ICT risk management framework. It must:
- define, approve and oversee its implementation;
- allocate an identified budget to it;
- keep its own knowledge current through regular training;
- receive periodic reporting on ICT risk.
The director-training obligation is new and often overlooked. It is demonstrated by dated records, not by a mention in the minutes.
The five pillars and their deliverables
| Pillar | Articles | Principal deliverable |
|---|---|---|
| ICT risk management | 5–16 | Documented framework + digital resilience strategy |
| Incidents | 17–23 | Classification and reporting procedure |
| Testing | 24–27 | Multi-year testing programme, TLPT if designated |
| ICT third-party risk | 28–44 | Register of information + compliant contracts |
| Information sharing | 45 | Optional |
The pillar-4 register of information is by far the costliest deliverable to produce and the most underestimated at the outset.
The regulatory architecture
DORA is completed by regulatory technical standards and implementing technical standards developed by the European Supervisory Authorities. They specify the content of the risk framework, incident classification criteria, the register-of-information template, and the oversight arrangements for critical providers.
Practical consequence: reading the regulation is not enough. The operational templates and thresholds sit in the technical standards, and they determine the exact format of the expected deliverables.
Key takeaways
- Some twenty entity categories, plus designated critical ICT providers
- Proportionality is documented, not merely invoked
- The management body is personally accountable and must be trained