EIOPA · DORA 136 - 3193
Other DORA topics
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 2
- Topic
- Other DORA topics
- Submitted
- 2024-11-25
- Answered
- 2025-11-20
Question
If a company has both DORA regulated activities and other - non-regulated - activities, does DORA apply to those other non-regulated activities as well? If so, is there a minimum % that the DORA regulated activities should be of the overall company activities for the non-regulated activities to be regulated by DORA as well?
Answer
Article 2 of Regulation (EU) 2022/2554 (DORA) defines its scope by the type of entities, not by individual activities or services. Therefore, by default, entities as a whole are subject to DORA requirements. In practice, this means that if ICT systems, services, or processes are shared across both regulated and nonregulated activities, DORA obligations extend to those as well. Only where ICT environments are fully segregated and contagion risks are effectively prevented can those non-regulated activities be excluded outside the scope. That said, DORA does build in proportionality and explicit exemptions for certain categories of firms. Article 2(3) of DORA enumerates categories of entities that are excluded despite otherwise carrying out financial activities. Finally, it is also important to note that DORA provides specific requirements for ICT services supporting critical or important functions.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.