Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Chapter I – General provisions
Article 2
Scope
1. Without prejudice to paragraphs 3 and 4, this Regulation applies to the following entities:
(a) credit institutions;
(b) payment institutions, including payment institutions exempted pursuant to Payment Services Directive (PSD2);
(c) account information service providers;
(d) electronic money institutions, including electronic money institutions exempted pursuant to Electronic Money Directive (EMD2);
(e) investment firms;
(f) crypto-asset service providers as authorised under a Regulation of the European Parliament and of the Council on markets in crypto-assets, and amending European Banking Authority Regulation (EBA) and (EU) No 1095/2010 and Capital Requirements Directive (CRD IV) and (EU) 2019/1937 (‘the Regulation on markets in crypto-assets’) and issuers of asset-referenced tokens;
(g) central securities depositories;
(h) central counterparties;
(i) trading venues;
(j) trade repositories;
(k) managers of alternative investment funds;
(l) management companies;
(m) data reporting service providers;
(n) insurance and reinsurance undertakings;
(o) insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries;
(p) institutions for occupational retirement provision;
(q) credit rating agencies;
(r) administrators of critical benchmarks;
(s) crowdfunding service providers;
(t) securitisation repositories;
(u) ICT third-party service providers.
2. For the purposes of this Regulation, entities referred to in paragraph 1, points (a) to (t), shall collectively be referred to as ‘financial entities’.
3. This Regulation does not apply to:
(a) managers of alternative investment funds as referred to in Article 3(2) of Alternative Investment Fund Managers Directive (AIFMD);
(b) insurance and reinsurance undertakings as referred to in Article 4 of Solvency II Directive (Insurance);
(c) institutions for occupational retirement provision which operate pension schemes which together do not have more than 15 members in total;
(d) natural or legal persons exempted pursuant to Articles 2 and 3 of Markets in Financial Instruments Directive (MiFID II);
(e) insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries which are microenterprises or small or medium-sized enterprises;
(f) post office giro institutions as referred to in Article 2(5), point (3), of Capital Requirements Directive (CRD IV).
4. Member States may exclude from the scope of this Regulation entities referred to in Article 2(5), points (4) to (23), of Capital Requirements Directive (CRD IV) that are located within their respective territories. Where a Member State makes use of such option, it shall inform the Commission thereof as well as of any subsequent changes thereto. The Commission shall make that information publicly available on its website or other easily accessible means.