Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Who is covered by DORA?
- Which financial entities must comply?
- What about ICT third - party service providers?
- Which entities are exempt?
- How to determine your organization’s DORA obligations
- Why DORA compliance matters for developers and security teams
- How Decloak helps you meet DORA requirements
- Next steps
Key takeaways
- All EU - authorized financial entities (21 categories) must follow DORA’s ICT risk - management, incident - reporting, and resilience testing rules.
- Any ICT third - party service provider that supplies those entities, regardless of location, is in scope and must embed DORA - compatible contract clauses.
- Small - scale or micro - SME financial firms are exempt, but may still face contractual DORA obligations from their clients.
Who is covered by DORA?
DORA covers two broad groups: regulated financial entities in the EU and the ICT third - party service providers that serve them. The regulation’s Article 2 defines the scope and it is enforced across all EU Member States as of 2025 - 2026.
Which financial entities must comply?
The regulation lists 21 categories of financial entities, from banks to crypto - asset service providers. Below is a concise table of the categories and typical examples:
| Category | Typical examples |
|---|---|
| Credit institutions | Banks, savings - banks |
| Payment institutions | Payment service providers, e - money issuers |
| Account - information service providers | AISPs under PSD2 |
| Electronic - money institutions | E - money issuers |
| Investment firms | Broker - dealers, asset - management firms |
| Crypto - asset service providers | Custodians, exchanges, issuers of asset - referenced tokens |
| Central securities depositories | CSDs |
| Central counterparties | CCPs |
| Trade repositories | Trade - repo operators |
| Managers of alternative investment funds | Fund managers |
| Management companies | UCITS managers |
| Data - reporting service providers | Regulatory reporting platforms |
| Insurance and re - insurance undertakings | Insurers, reinsurers |
| Insurance intermediaries | Brokers, agents |
| Institutions for occupational retirement provision | IORPs |
| Credit rating agencies | Rating firms |
| Administrators of critical benchmarks | Benchmark administrators |
| Crowdfunding service providers | Crowdfunding platforms |
| Securitisation repositories | Securitisation platforms |
| ICT third - party service providers | Cloud, SaaS, data - centre providers |
These entities must implement ICT risk - management frameworks, incident - reporting procedures, resilience testing, and third - party risk controls as required by DORA.
What about ICT third - party service providers?
Any company that provides ICT services - cloud hosting, data - centres, software, managed services, etc. - to the financial entities listed above falls within DORA’s scope, even if the provider is headquartered outside the EU. They must:
- Include DORA - compatible clauses in contracts (audit rights, incident - response support, exit - strategy provisions).
- Allow supervisory authorities to request information and perform oversight.
- If designated as a Critical ICT Third - Party Provider (CTPP), accept direct EU - wide supervision by the European Supervisory Authorities (EBA, ESMA, EIOPA).
Which entities are exempt?
DORA does not apply to certain micro - SME or small - scale financial entities, including:
- Small insurance or re - insurance undertakings classified as micro - SMEs.
- Insurance intermediaries that are micro - SMEs or SMEs.
- Institutions for occupational retirement provision with fewer than 15 members.
- Certain natural or legal persons covered only by MiFID II.
- Post - office giro institutions. These entities are not subject to DORA’s mandatory requirements, though they may still need to comply with contract clauses imposed by in - scope clients.
How to determine your organization’s DORA obligations
- Identify your business model. If you are a bank, payment institution, crypto - asset service provider, or any of the other 20 categories, you are in scope.
- Map your ICT supply chain. List every vendor that provides cloud, SaaS, data - centre, or managed - service components to your core financial services.
- Check vendor status. Determine whether any vendor is classified as a Critical ICT Third - Party Provider; they will be subject to direct supervisory oversight.
- Review exemptions. Verify if your organization qualifies as a micro - SME under the exemption criteria.
- Update contracts. Ensure all ICT service agreements contain DORA - compliant clauses for audit, incident response, and exit strategies.
Why DORA compliance matters for developers and security teams
- Regulatory risk: Non - compliance can lead to fines, enforcement actions, and loss of market access.
- Supply - chain security: The act forces explicit risk - management and monitoring of third - party services, reducing hidden vulnerabilities.
- Operational resilience: Implementing DORA’s testing and incident - response requirements improves your ability to withstand cyber incidents.
How Decloak helps you meet DORA requirements
Decloak’s free scan evaluates core security layers, including HTTP/TLS posture, static HTML analysis, rendered - page network behaviour, JavaScript CVE detection, tag - manager intelligence, third - party domain mapping, and vibe - coded platform security. The vibe - coded platform security layer identifies common misconfigurations in platforms such as Supabase, Bubble, and Next.js that often affect the ICT components of financial services. While Decloak does not replace full DORA compliance programs, its quick 15 - second graded report can surface critical issues in your web - application stack that need remediation before a formal DORA audit.
Next steps
- Run a free Decloak scan on your public URLs to get an immediate security posture snapshot.
- Conduct a detailed DORA gap analysis for each financial entity and ICT provider in scope.
- Incorporate DORA - compliant clauses into all third - party contracts.
- Establish an ongoing monitoring program using Decloak’s paid tiers for multi - page crawling, evidence packages, and active testing if deeper validation is required.
References: EU DORA Article 2, Vanta, IBM, EIOPA, and other listed sources.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.