Calculator · DORA / 2022/2554
DORA's scope is a closed list of entities and six exclusions. We go through them; at the end you see whether you are a financial entity, an ICT provider, or out.
Step by step we go through the list of entities in Article 2(1), the exclusions in Article 2(3) and (4) and finally the test for the simplified framework under Article 16. At the end you will see whether you are a financial entity, an ICT third-party service provider, or outside the scope — and what follows from that. The result is free and nobody asks you for an e-mail address.
The calculator works with Regulation (EU) 2022/2554 and with the acts its exclusions refer to. It does not reproduce their wording — every statement carries the article where you can check it. Your answers stay in your browser, nothing is sent anywhere.
The scope of the Regulation is a closed list. Article 2(1) enumerates entities under points (a) to (u); the entities under points (a) to (t) are collectively called financial entities (Article 2(2)), point (u) covers ICT third-party service providers. Anyone not on the list is outside the scope.
Article 2(3) has six points and Article 2(4) adds the option for a Member State to exclude the institutions it lists. We only ask what is relevant for your type of entity — the other questions are not displayed.
The simplified ICT risk management framework under Article 16 is not a general relief for small entities, it is a named list. Alongside it we ask about size, because a microenterprise as defined in Article 3(60) has a narrower set of obligations in several places in the Regulation.
This output is an orientation aid, not a legal assessment. It is based solely on what you entered in the form; whether you actually belong to the list in Article 2(1), whether an exclusion applies and whether the simplified framework is available are decided on details a form cannot capture. Borderline cases need an individual assessment, and the binding text is always the wording of Regulation (EU) 2022/2554.
CypherOn provides cybersecurity consulting services; it is not a law firm. For legal opinions, turn to an attorney registered with the Czech Bar Association.
The five areas of the Regulation, the risk management framework under Article 6, incident reporting, testing, the supply chain and the register of information — in plain words, with links to the exact wording.
Open the guideThe materiality thresholds of Regulation 2024/1772 and the deadlines tied to them under Regulation 2025/301, including the regime in which the deferral over a weekend does not apply.
Open the decision treeAn analysis of the provisions the bank has to have in the contract under Article 30: audit rights, exit plan, data location, incident reporting, subcontractors — and what can be negotiated.
Open the checklistThe decision logic of the calculator is based on these sources, as of 9 August 2026. What binds is the wording of the act, not our reading of it.
When the result comes out as obligations
ICT risk assessment against the framework in Article 6, setting up incident classification and reporting within the four-hour deadline, and, on the provider side, support with contract amendments and security questionnaires from banks. The initial consultation is free of charge.