In short
DORA applies to the financial entities listed in Article 2(1), which is a closed list, with entities excluded in Article 2(3) and a simplified framework in Article 16.12 Applying for an authorisation does not by itself bring a firm inside DORA, so what an authority examines at application is the ICT and security evidence the sectoral framework requires. An applicant that already holds another authorisation may already be a listed financial entity, and DORA already binds it in that capacity.14
What the law requires
Who DORA actually binds
DORA applies to the financial entities listed in Article 2(1) and to ICT third-party service providers. The list is closed. Article 2(3) excludes certain entities from it entirely, and Article 16 applies a simplified ICT risk management framework to others.123
The practical effect is that the depth of what DORA requires is not uniform, and whether it applies is a conclusion to check against the entity types you already hold rather than one to assume either way.1
What the law requires
What is assessed at application, and what already binds
A payment institution applicant must submit a security policy document containing a risk assessment and a description of the security control and mitigation measures. Other frameworks set their own application content requirements.4
That is what an authority looks at where the applicant is not otherwise a listed financial entity. Where it is one already, for example an authorised institution applying for a further authorisation, DORA binds it in that existing capacity and the application does not change that.14
What the law requires
Third-party risk
For entities within scope, DORA requires ICT third-party risk to be managed and a register of information on contractual arrangements to be maintained, and it establishes an oversight framework for critical ICT third-party service providers.3
RenIQ practitioner observation
A practical approach
Build the ICT evidence the application asks for, and build it in a shape that carries over into the framework you will be subject to once authorised. Sequencing it that way avoids doing the work twice without claiming an obligation that has not yet attached.
Related regime guide: AML & DORA
This is a supporting note behind the decision guide A weak or stalled application: repair it, reset the scope, or stop.
Primary sources for this page
4 citations, each to the article or section the statement rests on. The numbers beside a statement point to the citation behind it. Always confirm against the current official text.
- 1Article 2(1), the list of financial entities to which DORA applies, and Article 2(3), the entities excluded from itRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
- 2Article 16, simplified ICT risk management framework for the entities it listsRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
- 3Chapter V, management of ICT third-party risk, including the register of information and the oversight framework for critical ICT third-party service providersRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
- 4Article 5(1), the contents of an application for authorisation as a payment institution, including point (j), the security policy documentDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union
Last updated 2026-08-21. 2 min read, calculated from 333 words.