Calculator · DORA / 2022/2554

DOES DORA APPLY TO YOU?

DORA's scope is a closed list of entities and six exclusions. We go through them; at the end you see whether you are a financial entity, an ICT provider, or out.

This calculator builds on what is explained in the guide to the DORA Regulation

Step by step we go through the list of entities in Article 2(1), the exclusions in Article 2(3) and (4) and finally the test for the simplified framework under Article 16. At the end you will see whether you are a financial entity, an ICT third-party service provider, or outside the scope — and what follows from that. The result is free and nobody asks you for an e-mail address.

The calculator works with Regulation (EU) 2022/2554 and with the acts its exclusions refer to. It does not reproduce their wording — every statement carries the article where you can check it. Your answers stay in your browser, nothing is sent anywhere.

An orientation aid, not a legal assessment The result is an orientation aid, not a legal assessment and not a position of a supervisory authority. Whether a particular organisation belongs to the list in Article 2(1), whether an exclusion under Article 2(3) applies and whether the simplified framework under Article 16 is available are all decided on details a form cannot capture. The binding text is the wording of Regulation (EU) 2022/2554 in the Official Journal; the links are in the Official sources section. CypherOn is a cybersecurity consultancy, not a law firm.
1Type of entity
2Exclusions
3Regime
4Result

What is your organisation?

The scope of the Regulation is a closed list. Article 2(1) enumerates entities under points (a) to (u); the entities under points (a) to (t) are collectively called financial entities (Article 2(2)), point (u) covers ICT third-party service providers. Anyone not on the list is outside the scope.

Which category does your organisation belong to?

Pick the category under which you hold an authorisation, a registration or an entry in a register. What decides is the regulatory category, not the commercial label: a fintech running payments on the strength of a payment institution authorisation is, for the Regulation, a payment institution.

ICT third-party service providers are on the list too, under point (u) — but do not look for them in this selection. The next question asks about them, because a provider is inside the scope of the Regulation while not being a financial entity under Article 2(2), and its obligations arise in a different way.

Does one of the exclusions apply to you?

Article 2(3) has six points and Article 2(4) adds the option for a Member State to exclude the institutions it lists. We only ask what is relevant for your type of entity — the other questions are not displayed.

Category selected

Which regime applies to you?

The simplified ICT risk management framework under Article 16 is not a general relief for small entities, it is a named list. Alongside it we ask about size, because a microenterprise as defined in Article 3(60) has a narrower set of obligations in several places in the Regulation.

Category selected

An indicative result. It does not replace a legal assessment or a position of a supervisory authority, and borderline cases need an individual assessment.

What to do next

    This output is an orientation aid, not a legal assessment. It is based solely on what you entered in the form; whether you actually belong to the list in Article 2(1), whether an exclusion applies and whether the simplified framework is available are decided on details a form cannot capture. Borderline cases need an individual assessment, and the binding text is always the wording of Regulation (EU) 2022/2554.

    Open the DORA guide →

    Guide to the DORA Regulation

    The five areas of the Regulation, the risk management framework under Article 6, incident reporting, testing, the supply chain and the register of information — in plain words, with links to the exact wording.

    Open the guide

    Incident classification and deadlines

    The materiality thresholds of Regulation 2024/1772 and the deadlines tied to them under Regulation 2025/301, including the regime in which the deferral over a weekend does not apply.

    Open the decision tree

    Your bank sent you an amendment

    An analysis of the provisions the bank has to have in the contract under Article 30: audit rights, exit plan, data location, incident reporting, subcontractors — and what can be negotiated.

    Open the checklist

    Official sources

    The decision logic of the calculator is based on these sources, as of 9 August 2026. What binds is the wording of the act, not our reading of it.

    Regulation (EU) 2022/2554 (DORA) ↗ The authentic English text. Scope Article 2, definitions Article 3 (among them points (19), (20), (21), (22), (32), (34), (36), (39), (53), (57) and (60)), governance Article 5, framework Article 6, simplified framework Article 16, incidents Articles 17 to 23, testing Articles 24 to 26, third parties Article 28, contractual provisions Article 30, critical providers Article 31, information sharing Article 45, application Article 64. Directive 2011/61/EU (AIFMD) ↗ Article 3(2) — the thresholds of EUR 100 million including leverage and EUR 500 million unleveraged with a five-year lock-up on redemptions; Article 3(3) registration. The basis for the exclusion in Article 2(3), point (a), of DORA. Directive 2009/138/EC (Solvency II) ↗ Article 4 — exclusion from scope on size grounds: written premiums up to EUR 5 million, technical provisions up to EUR 25 million and further cumulative conditions. The basis for the exclusion in Article 2(3), point (b), of DORA. Directive (EU) 2015/2366 (PSD2) ↗ Article 32(1) — the waiver for persons whose monthly average of payment transactions does not exceed the Member State limit and in any case no more than EUR 3 million. The basis for the simplified framework for exempted payment institutions. Directive 2009/110/EC (electronic money) ↗ Article 9(1) — the optional waiver where average outstanding electronic money is no more than EUR 5 million. The basis for the simplified framework for exempted electronic money institutions. Regulation (EU) 2019/2033 (IFR) ↗ Article 12(1) — the nine conditions for a small and non-interconnected investment firm, among them assets under management below EUR 1.2 billion, a balance sheet total below EUR 100 million and gross annual revenues below EUR 30 million. The basis for the simplified framework for investment firms. Directive 2014/65/EU (MiFID II) ↗ Articles 2 and 3 — the categories of exempted persons and the optional exemption for persons who may not hold client funds and provide only the reception and transmission of orders or advice. The basis for the exclusion in Article 2(3), point (d), of DORA. Directive 2013/36/EU (CRD IV) ↗ Article 2(5) — the named list of institutions excluded from the scope of the Directive. Point (3) (post office giro institutions) is the exclusion in Article 2(3), point (f), of DORA; points (4) to (23) are the subject of the Member State option in Article 2(4). Delegated Regulation (EU) 2024/1774 ↗ ICT risk management tools, methods, processes and policies, and the details of the simplified framework under Article 16. The most detailed text on what the individual measures actually mean. Delegated Regulation (EU) 2024/1772 ↗ The criteria for classifying major incidents and the materiality thresholds. The basis for the statement that incident reporting applies regardless of the Article 16 regime. Delegated Regulation (EU) 2025/301 ↗ The content and time limits for the initial notification and the intermediate and final reports. The decision tree on deadlines is on the Incident classification and deadlines page. Implementing Regulation (EU) 2024/2956 ↗ The templates for the register of information, the code lists for types of ICT services and the rules for supply chain rank and identifiers. The basis for the statements about the content of the register under Article 28(3). Act No. 31/2025 Coll. in the e-Sbírka ↗ The Act on the digitalisation of the financial market. The Czech National Bank as the competent authority, its powers, and offences of financial entities and providers. Promulgated on 14 February 2025, in force since 15 February 2025.
    Content valid as of 9 August 2026

    When the result comes out as obligations

    Operational resilience shows
    in an incident,
    not in documentation.

    ICT risk assessment against the framework in Article 6, setting up incident classification and reporting within the four-hour deadline, and, on the provider side, support with contract amendments and security questionnaires from banks. The initial consultation is free of charge.