DORA applies to around 20 categories of financial entity — from banks to crypto-asset service providers — and affects the ICT providers serving them. Most EU financial firms are in scope, but DORA includes exclusions and simplified regimes, so scope should be verified rather than assumed. In Ireland, DORA does not apply to credit unions until 17 January 2028.
If you work in an Irish financial firm, your first DORA question is simple: does this even apply to us? This page answers that — the categories in scope, how ICT providers are affected, where the exclusions sit, and the Irish specifics.
What “financial entity” means under DORA
DORA uses the term financial entity to describe the regulated firms it covers. It is a broad definition spanning most of the EU financial sector — not just banks. The regulation applies directly across the EU, so an Irish firm falls in scope by virtue of its activity and authorisation, not because of any national opt-in.
The categories of financial entity in scope
DORA lists approximately 20 categories. The most common in Ireland include:
Credit institutions (banks)
Payment institutions and electronic money institutions
Investment firms
Insurance and reinsurance undertakings, and insurance intermediaries
Crypto-asset service providers (CASPs)
Fund managers — UCITS management companies and AIFMs
Central securities depositories and central counterparties
Trading venues and trade repositories
Credit rating agencies, and others
Obligations are proportionate — they scale with size, risk profile and systemic importance. Micro-enterprises get lighter treatment, but “small” does not mean “exempt”: core ICT risk-management and testing expectations apply widely.
How ICT third-party providers are affected
DORA also reaches technology providers — but not all in the same way:
Most ICT providers are affected indirectly, through the contractual and risk-management obligations their financial-entity customers must impose. These requirements flow down the supply chain.
Providers designated as critical (“CTPPs”) by the European Supervisory Authorities enter a direct EU oversight framework and are supervised at EU level.
So if you are a technology supplier to financial firms, DORA almost certainly affects you — usually via your contracts, and directly only if you are formally designated as critical.
Not sure whether DORA applies to your firm, or whether you count as an affected ICT provider? Run our short scope checker.
Exclusions, simplified regimes and the Irish position
DORA is broad but not universal. It contains exclusions and simplified regimes, and certain entity types have specific arrangements. Two Irish points matter:
Credit unions — under S.I. 20/2025, DORA does not apply to Irish credit unions until 17 January 2028. The Central Bank still expects them to strengthen digital resilience in the meantime. See DORA for Irish credit unions.
Occupational pension schemes — institutions for occupational retirement provision fall under the Pensions Authority rather than the Central Bank of Ireland.
Because of these nuances, scope should be verified, not assumed.
Frequently asked questions
Is my company in scope for DORA?
If you are an EU-regulated financial firm, you are very likely in scope, though obligations are proportionate. ICT providers serving financial firms are affected too — usually through contracts. Because DORA includes exclusions and simplified regimes, the reliable way to check is to run the scope checker.
Does DORA apply to Irish credit unions?
Not yet. Under S.I. 20/2025, DORA does not apply to Irish credit unions until 17 January 2028, although the Central Bank expects them to prepare in the meantime.
Are small firms exempt?
No — but obligations are proportionate, and micro-enterprises follow a lighter, risk-based approach. The advanced testing obligation (TLPT) is limited to a subset of entities identified by the competent authority.
Want to confirm your position and obligations? Run the scope checker or book a readiness assessment.