EIOPA · DORA 136 - 3193

Other DORA topics

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
2
Topic
Other DORA topics
Submitted
2024-11-25
Answered
2025-11-20

Question

If a company has both DORA regulated activities and other - non-regulated - activities, does DORA apply to those other non-regulated activities as well? If so, is there a minimum % that the DORA regulated activities should be of the overall company activities for the non-regulated activities to be regulated by DORA as well?

Answer

Article 2 of Regulation (EU) 2022/2554 (DORA) defines its scope by the type of entities, not by individual activities or services. Therefore, by default, entities as a whole are subject to DORA requirements. In practice, this means that if ICT systems, services, or processes are shared across both regulated and nonregulated activities, DORA obligations extend to those as well. Only where ICT environments are fully segregated and contagion risks are effectively prevented can those non-regulated activities be excluded outside the scope. That said, DORA does build in proportionality and explicit exemptions for certain categories of firms. Article 2(3) of DORA enumerates categories of entities that are excluded despite otherwise carrying out financial activities. Finally, it is also important to note that DORA provides specific requirements for ICT services supporting critical or important functions.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.