Back to Guides
Guide16 September 2026

Who Must Comply with the EU Digital Operational Resilience Act (DORA)?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. Who is covered by DORA?
  3. Which financial entities must comply?
  4. What about ICT third - party service providers?
  5. Which entities are exempt?
  6. How to determine your organization’s DORA obligations
  7. Why DORA compliance matters for developers and security teams
  8. How Decloak helps you meet DORA requirements
  9. Next steps

Key takeaways

Who is covered by DORA?

DORA covers two broad groups: regulated financial entities in the EU and the ICT third - party service providers that serve them. The regulation’s Article 2 defines the scope and it is enforced across all EU Member States as of 2025 - 2026.

Which financial entities must comply?

The regulation lists 21 categories of financial entities, from banks to crypto - asset service providers. Below is a concise table of the categories and typical examples:

CategoryTypical examples
Credit institutionsBanks, savings - banks
Payment institutionsPayment service providers, e - money issuers
Account - information service providersAISPs under PSD2
Electronic - money institutionsE - money issuers
Investment firmsBroker - dealers, asset - management firms
Crypto - asset service providersCustodians, exchanges, issuers of asset - referenced tokens
Central securities depositoriesCSDs
Central counterpartiesCCPs
Trade repositoriesTrade - repo operators
Managers of alternative investment fundsFund managers
Management companiesUCITS managers
Data - reporting service providersRegulatory reporting platforms
Insurance and re - insurance undertakingsInsurers, reinsurers
Insurance intermediariesBrokers, agents
Institutions for occupational retirement provisionIORPs
Credit rating agenciesRating firms
Administrators of critical benchmarksBenchmark administrators
Crowdfunding service providersCrowdfunding platforms
Securitisation repositoriesSecuritisation platforms
ICT third - party service providersCloud, SaaS, data - centre providers

These entities must implement ICT risk - management frameworks, incident - reporting procedures, resilience testing, and third - party risk controls as required by DORA.

What about ICT third - party service providers?

Any company that provides ICT services - cloud hosting, data - centres, software, managed services, etc. - to the financial entities listed above falls within DORA’s scope, even if the provider is headquartered outside the EU. They must:

  1. Include DORA - compatible clauses in contracts (audit rights, incident - response support, exit - strategy provisions).
  2. Allow supervisory authorities to request information and perform oversight.
  3. If designated as a Critical ICT Third - Party Provider (CTPP), accept direct EU - wide supervision by the European Supervisory Authorities (EBA, ESMA, EIOPA).

Which entities are exempt?

DORA does not apply to certain micro - SME or small - scale financial entities, including:

How to determine your organization’s DORA obligations

  1. Identify your business model. If you are a bank, payment institution, crypto - asset service provider, or any of the other 20 categories, you are in scope.
  2. Map your ICT supply chain. List every vendor that provides cloud, SaaS, data - centre, or managed - service components to your core financial services.
  3. Check vendor status. Determine whether any vendor is classified as a Critical ICT Third - Party Provider; they will be subject to direct supervisory oversight.
  4. Review exemptions. Verify if your organization qualifies as a micro - SME under the exemption criteria.
  5. Update contracts. Ensure all ICT service agreements contain DORA - compliant clauses for audit, incident response, and exit strategies.

Why DORA compliance matters for developers and security teams

How Decloak helps you meet DORA requirements

Decloak’s free scan evaluates core security layers, including HTTP/TLS posture, static HTML analysis, rendered - page network behaviour, JavaScript CVE detection, tag - manager intelligence, third - party domain mapping, and vibe - coded platform security. The vibe - coded platform security layer identifies common misconfigurations in platforms such as Supabase, Bubble, and Next.js that often affect the ICT components of financial services. While Decloak does not replace full DORA compliance programs, its quick 15 - second graded report can surface critical issues in your web - application stack that need remediation before a formal DORA audit.

Next steps


References: EU DORA Article 2, Vanta, IBM, EIOPA, and other listed sources.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary