Get Demo
↑

Who Does DORA Apply To? The 20 Types of Financial Entities and Their ICT Providers

Article 2 of Regulation (EU) 2022/2554 lists 20 financial entity types (points a–t) plus ICT third-party service providers (point u).

Published: September 2026 Compliance · DORA 8–12 min read

Article 2 of Regulation (EU) 2022/2554 defines who DORA applies to. In practice: 20 types of financial entities (points (a)–(t)) plus ICT third-party service providers (point (u)).

Related: DORA hub · What is DORA? · For ICT providers.

Scope count: Article 2(1) lists 20 financial entity categories (a–t) that the Regulation collectively calls “financial entities,” and separately includes ICT third-party service providers (u). Paragraphs 3–4 set exclusions and Member State options — confirm your legal analysis against the Official Journal text.

Financial Entity Categories (a–t)

  1. Credit institutions
  2. Payment institutions (including certain exempted payment institutions)
  3. Account information service providers
  4. Electronic money institutions (including certain exempted e-money institutions)
  5. Investment firms
  6. Crypto-asset service providers and issuers of asset-referenced tokens (as referenced in Article 2)
  7. Central securities depositories
  8. Central counterparties
  9. Trading venues
  10. Trade repositories
  11. Managers of alternative investment funds
  12. Management companies
  13. Data reporting service providers
  14. Insurance and reinsurance undertakings
  15. Insurance, reinsurance and ancillary insurance intermediaries
  16. Institutions for occupational retirement provision
  17. Credit rating agencies
  18. Administrators of critical benchmarks
  19. Crowdfunding service providers
  20. Securitisation repositories

ICT Third-Party Service Providers (u)

Providers of ICT services to financial entities are in scope of the Regulation’s ICT third-party chapter and may face CTPP designation. They are not labelled “financial entities” under Article 2(2), but contractual and oversight consequences are real — see DORA for ICT service providers.

Exclusions

Article 2(3)–(4) exclude or allow exclusion of certain small intermediaries, small IORPs, and other specified cases. Do not assume exemption without legal review.

How CyberSilo Helps

Confirm Scope Before Building Controls

Map your entity type and ICT providers, then evidence the five pillars in CSA.

Frequently Asked Questions

How many financial entity types does Article 2 list?

Twenty categories in points (a) to (t), plus ICT third-party service providers in point (u).

Are ICT providers ‘financial entities’?

No under Article 2(2)’s definition — but they are still within the Regulation’s scope as ICT third-party service providers.

Does DORA apply outside the EU?

DORA binds EU-regulated entities and shapes contracts with non-EU ICT providers serving those entities. Non-EU groups with EU subsidiaries or services commonly face flow-down requirements.

Hub · Checklist · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!