Precise Scope Determination for DORA Compliance

DORA Scope of Application: Which Financial Entities Are Covered?

The DORA scope of application covers 20 types of financial entities, from credit institutions and insurers to crypto-asset service providers and ICT third-party providers.

  • 01Complete capture of all DORA-relevant entities and services
  • 02Systematic third-party classification and risk assessment
  • 03Cross-border compliance mapping for group structures
  • 04Continuous scope monitoring and adaptation
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

Understanding and Implementing DORA Scope of Application

The Digital Operational Resilience Act (DORA) defines a specific scope of application that encompasses various categories of financial institutions and their third-party providers. Precise scope determination is crucial for developing an effective compliance strategy and avoiding regulatory risks.

We offer comprehensive support in determining and managing the DORA scope of application. Our systematic approach ensures complete capture of all relevant entities and services as well as efficient implementation of corresponding compliance requirements.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

DORA Scope Assessment and Entity Classification

Systematic analysis and classification of all entities within your organization to determine DORA applicability and specific requirements.

  • Detailed analysis of organizational structure and business activities
  • Classification according to DORA entity categories and thresholds
  • Assessment of specific requirements for each identified entity
  • Documentation and justification of scope decisions
02

Third-Party Impact Analysis and Critical Service Identification

Comprehensive assessment of your third-party ecosystem to identify critical ICT services and their DORA implications.

  • Complete capture and categorization of all ICT third-party providers
  • Assessment of service criticality and dependencies
  • Analysis of DORA compliance requirements for critical third parties
  • Development of third-party management strategies
03

Cross-Border Compliance Mapping

Specialized analysis for international group structures to determine DORA applicability across different jurisdictions.

  • Analysis of group structure and cross-border activities
  • Assessment of DORA applicability for subsidiaries and branches
  • Coordination with local regulatory requirements
  • Development of group-wide compliance strategies
04

Scope Management Framework Development

Building solid governance structures and processes for continuous management and monitoring of the DORA scope of application.

  • Design of scope governance structures and responsibilities
  • Development of documentation and reporting standards
  • Implementation of change management processes
  • Integration into existing risk management frameworks
05

Continuous Scope Monitoring and Updates

Establishment of systematic monitoring processes to ensure continuous currency and completeness of your DORA scope determination.

  • Implementation of automated monitoring systems
  • Regular scope reviews and updates
  • Tracking regulatory developments and their impacts
  • Proactive adaptation to business or structural changes
06

DORA Readiness Assessment and Gap Analysis

Comprehensive assessment of your current compliance position and identification of specific action areas based on your individual DORA scope.

  • Scope-specific readiness assessment and maturity evaluation
  • Identification and prioritization of compliance gaps
  • Development of customized implementation roadmaps
  • Cost-benefit analysis of different compliance approaches

5 phases

Our Systematic Approach

We develop a customized strategy with you for precise determination and continuous management of your DORA scope of application.

  1. Comprehensive analysis of your organizational structure and business activities

  2. Systematic identification and classification of all DORA-relevant entities

  3. Detailed third-party analysis and critical service assessment

  4. Development of documentation and governance structures

  5. Implementation of continuous monitoring and update processes

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Precise DORA scope determination is the foundation of every successful compliance strategy. Our systematic approach ensures that all relevant entities and dependencies are captured while developing practical and efficient implementation pathways.

Our Expertise

  • 01In-depth knowledge of DORA regulation and its practical application
  • 02Proven methods for systematic scope analysis and entity classification
  • 03Experience with complex international financial services structures
  • 04Pragmatic solution approaches for efficient and sustainable compliance implementation

Expert Tip

Incomplete or incorrect scope determination can lead to significant compliance gaps. Especially with complex group structures and extensive third-party ecosystems, a systematic, documented approach is essential.

5 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA Scope of Application

Which companies does DORA apply to?

DORA covers nearly all regulated financial entities in the EU: credit institutions, investment firms, insurers, payment and e-money institutions, crypto-asset service providers, and other categories exhaustively listed in Article 2. Critical ICT third-party providers serving these entities also fall under direct EU oversight. Whether a specific entity is in scope should be checked against its actual license category, since the list is quite granular.

Are there exemptions or simplifications for smaller financial entities?

Yes, DORA includes a proportionality principle: small and non-complex entities can meet simplified requirements for certain elements of ICT risk management. This mainly affects the scope and frequency of some documentation and testing obligations, not the fundamental duty to implement DORA at all; there's no full exemption from DORA for regulated financial entities.

Do ICT third-party providers themselves fall within DORA's scope?

Only providers designated as critical by the EU supervisory authorities (the ESAs) are directly regulated, with their own direct oversight obligations. All other ICT third-party providers don't fall directly under DORA, but are indirectly affected, since their financial-entity customers must pass through contractual requirements from Articles 28‑30.

How is scope determined for groups with both regulated and unregulated entities?

DORA generally applies per legally separate, regulated entity, not automatically to the entire group. Unregulated group companies only fall under DORA if they themselves provide a covered financial service or act as an internal ICT provider to regulated entities within the group, in which case the third-party requirements apply internally.

What happens if a company enters DORA's scope partway through the year?

DORA doesn't provide an automatic transition period for entities newly entering scope, for example through a new license or growth past a threshold. In practice, implementation should be prepared in parallel with the licensing or approval process, since supervisors generally expect requirements to be met from the point of designation rather than after a grace period.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance