SkarpSkarp

Chapter 6 of 15

DORA Regulation (EU) 2022/2554 — Scope, Definitions, and General Provisions

Who is covered, who is excluded, and what does DORA mean by its core terminology? Chapter I establishes the boundaries and vocabulary that control every later obligation.

22 min readen

1. Chapter I: The Map for the Rest of DORA

Why Chapter I comes first

Chapter I of DORA establishes the legal perimeter for later obligations: subject matter, scope, definitions, and proportionality.

A four-layer filter

Read in order: what DORA regulates, who is covered, what its terms mean, then how proportionality applies.

Precision matters

Ordinary language is not enough. A provider is a critical ICT third-party service provider only if designated under Article 31.

What this extract does not do

Articles 1-4 create boundaries and vocabulary. They do not, in this extract, state a specific reporting deadline or require a named security technology.

2. Article 1: What DORA Regulates

Article 1's core rule

DORA says: "this Regulation lays down uniform requirements concerning the security of network and information systems supporting the business processes of financial entities".

Six financial-entity areas

Article 1 covers ICT risk management, incident reporting, payment-incident reporting, resilience testing, intelligence sharing, and ICT third-party risk.

A qualification to preserve

Significant cyber threats are notified on a voluntary basis. Do not restate that particular notification as an unconditional mandatory report.

Beyond the financial entity

Article 1 also addresses ICT-provider contracts, oversight of critical providers, and cooperation, supervision, and enforcement by competent authorities.

3. Article 1(2)-(3): NIS2 and State Functions

DORA's NIS2 position

For the specified NIS2-identified financial entities, DORA "shall be considered a sector-specific Union legal act" for Article 4 of Directive (EU) 2022/2555.

Keep the trigger

The rule concerns financial entities identified as essential or important entities under national rules transposing NIS2 Article 3.

Do not overgeneralise

Article 1(2) does not itself say that every organisation is covered by NIS2, nor that every financial entity has the relevant NIS2 identification.

State-functions boundary

Article 1(3) is without prejudice to Member State responsibility for essential State functions concerning public security, defence, and national security.

4. Article 2: Who Is Within DORA's Scope?

Start with the qualifier

Article 2(1) applies without prejudice to paragraphs 3 and 4. Check exclusions and Member State options before reaching a final scope conclusion.

The included sectors

The list spans banking, payments, investment and markets, crypto-assets, insurance, pensions, benchmarks, crowdfunding, repositories, and ICT providers.

Financial entity is narrower

Only Article 2(1)(a)-(t) are collectively financial entities. ICT third-party service providers in point (u) are in scope but outside that collective label.

Currency note: proposed scope addition

COM(2023) 360 final of June 28, 2023 proposes Article 2(1)(v) for financial information service providers. It is proposed, not in force, on July 24, 2026.

5. Article 2 Applied: Inclusion, Exclusion, and National Choice

Example A: small is not automatically out

A payment institution starts in Article 2(1)(b), even if exempted under the payment-services directive. Article 2(3) has no general small-payment-institution exclusion.

Example B: intermediary exclusion

An insurance, reinsurance, or ancillary insurance intermediary is excluded only where it is a microenterprise or small or medium-sized enterprise.

Example C: 15 versus 100

The exclusion is pension schemes with no more than 15 members. "Small institution" means fewer than 100 members; it is a different Article 3 definition.

Example D: national option

Article 2(4) lets Member States may exclude specified Directive 2013/36/EU institutions in their territory; it is not an automatic exclusion.

6. Article 3: Resilience, Systems, Assets, and Incidents

Digital operational resilience

It means the ability "to build, assure and review its operational integrity and reliability" through the ICT capabilities needed to sustain financial services, including disruptions.

Legacy and assets

A legacy ICT system can still support functions even though it is end-of-life, cannot be upgraded or fixed, or is no longer supported. Assets may be information or ICT assets.

Risk and incident

ICT risk is a reasonably identifiable circumstance that may cause adverse effects if materialised. An ICT-related incident is unplanned and compromises system security.

Major and significant

A major ICT-related incident has high adverse impact on systems supporting critical or important functions. A significant cyber threat has potential to cause a major incident.

7. Classification Lab: Name the DORA Concept

Classification lab

For each situation, pause before revealing the answer. Identify the most precise Article 3 term and state the feature that makes it fit.

Situation 1

A financial entity continues to use a settlement application. The supplier no longer supports it, patches are unavailable, but the application still supports a function.

Answer: This fits a legacy ICT system under Article 3(3). The system remains in use and supports functions, while supplier support and fixes are no longer available.

Situation 2

A phishing campaign has technical indicators showing it could disable an institution's online payment service, but the campaign has not yet done so.

Answer: This may fit a significant cyber threat under Article 3(13), provided its technical characteristics indicate potential to result in a major ICT-related incident or major operational or security payment-related incident. It is not necessarily an incident yet.

Situation 3

A cloud provider's outage prevents an investment firm from carrying out a function whose disruption would materially impair continuity of its services.

Answer: The affected activity is a critical or important function if the full Article 3(22) condition is met. The vendor dependence may also create ICT third-party risk and, depending on the dependency structure, ICT concentration risk.

Situation 4

A hardware supplier provides devices and continuing technical support through firmware updates.

Answer: That can fall within ICT services. Article 3(21) expressly includes hardware as a service and hardware services that include technical support through software or firmware updates. Traditional analogue telephone services are excluded.

The lesson: classify events by Article 3's legal ingredients, not by a dramatic label such as "major outage" or "cyber crisis."

8. Article 3: Providers, Functions, Groups, and Size

Testing and third-party chains

TLPT is an intelligence-led red-team test of critical live production systems. ICT third-party risk includes risk from providers and their subcontractors, including outsourcing.

ICT services

ICT services are ongoing digital and data services through ICT systems. Specified hardware services are included; traditional analogue telephone services are excluded.

Critical or important function

The definition covers material impairment to financial performance, soundness, continuity, or continuing compliance with authorisation conditions and applicable financial-services law.

Enterprise thresholds

A microenterprise has fewer than 10 persons and turnover and/or balance sheet no more than EUR 2 million, subject to exclusions for four specified entity types.

9. Quiz: Scope and Definitions

Check your understanding

Choose the best answer. Read every qualifier carefully.

Which statement most accurately reflects Article 2(2)?

  1. All entities in Article 2(1)(a)-(u), including ICT third-party service providers, are collectively called financial entities.
  2. Entities in Article 2(1)(a)-(t) are collectively called financial entities; ICT third-party service providers in point (u) are within scope but outside that collective definition.
  3. Only credit institutions, payment institutions, and electronic money institutions are financial entities.
  4. ICT third-party service providers are excluded unless they are designated critical.
Show Answer

Answer: B) Entities in Article 2(1)(a)-(t) are collectively called financial entities; ICT third-party service providers in point (u) are within scope but outside that collective definition.

Article 2(2) expressly limits the collective term "financial entities" to Article 2(1)(a)-(t). Article 2(1)(u) lists ICT third-party service providers within DORA's scope, but they are not included in that collective label.

10. Quiz: Proportionality

Check your understanding

Select the answer that preserves Article 4's structure and qualifiers.

Under Article 4(1), how shall financial entities implement the rules laid down in Chapter II?

  1. In exactly the same way, regardless of size, risk, or services.
  2. Only if they qualify as microenterprises.
  3. In accordance with proportionality, taking account of size and overall risk profile and the nature, scale, and complexity of services, activities, and operations.
  4. Only after a competent authority grants a proportionality exemption.
Show Answer

Answer: C) In accordance with proportionality, taking account of size and overall risk profile and the nature, scale, and complexity of services, activities, and operations.

Article 4(1) says financial entities shall implement Chapter II rules in accordance with proportionality, "taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations." It does not create a general exemption.

11. Flashcards: Article 3 and Article 4 Recall

Rapid review

Flip each card, then explain the legal trigger or qualification aloud before moving on.

Digital operational resilience
The ability of a financial entity to build, assure and review operational integrity and reliability by ensuring the full range of ICT-related capabilities needed for system security and continued financial services and quality, including throughout disruptions.
ICT-related incident
A single event or linked series of events unplanned by the financial entity that compromises system security and adversely affects availability, authenticity, integrity, confidentiality of data, or services.
Major ICT-related incident
An ICT-related incident with a high adverse impact on the network and information systems that support critical or important functions.
Critical or important function
A function whose disruption materially impairs financial performance, soundness, or continuity, or whose discontinued, defective, or failed performance materially impairs continuing legal compliance.
ICT third-party risk
ICT risk arising from use of ICT services provided by ICT third-party service providers or their subcontractors, including outsourcing arrangements.
Microenterprise
A financial entity, except a trading venue, central counterparty, trade repository, or central securities depository, with fewer than 10 persons and turnover and/or balance sheet total not exceeding EUR 2 million.
Article 2(3)(c) pension exclusion
DORA does not apply to an institution for occupational retirement provision operating pension schemes which together do not have more than 15 members in total.
Article 4 proportionality
Chapter II shall be implemented taking into account size and overall risk profile, and the nature, scale, and complexity of services, activities, and operations. Chapters III, IV, and V Section I apply proportionately as specifically provided in their rules.

Key Terms

DORA
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector.
ICT risk
A reasonably identifiable circumstance related to use of network and information systems which may cause the specified adverse effects if materialised.
ICT services
Ongoing digital and data services provided through ICT systems to internal or external users; the definition includes specified hardware services and excludes traditional analogue telephone services.
microenterprise
A qualifying financial entity with fewer than 10 persons and annual turnover and/or balance sheet total not exceeding EUR 2 million, subject to the entity-type exclusions in Article 3(60).
financial entity
Collective term in Article 2(2) for entities listed in Article 2(1)(a)-(t).
ICT-related incident
An unplanned single event or linked series that compromises system security and adversely affects data or services.
ICT concentration risk
Dependency on individual or related critical ICT third-party service providers that may endanger critical or important functions or create other specified adverse effects.
significant cyber threat
A cyber threat whose technical characteristics indicate potential to result in a major ICT-related incident or major operational or security payment-related incident.
proportionality principle
The Article 4 principle requiring application of the relevant DORA rules with regard to size, overall risk profile, and the nature, scale, and complexity of services, activities, and operations.
critical or important function
A function whose disruption or failed performance would materially impair specified financial performance, continuity, soundness, or continuing compliance outcomes.
digital operational resilience
The ability of a financial entity to build, assure and review operational integrity and reliability through the required range of ICT-related capabilities.
ICT third-party service provider
An undertaking providing ICT services.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself