DORA for Crowdfunding Service Providers (ECSPR)
Proportionate DORA compliance for lean, ECSPR-authorised crowdfunding platforms.
Proportionate DORA compliance for lean, ECSPR-authorised crowdfunding platforms.
Crowdfunding service providers authorised under Regulation (EU) 2020/1503 (ECSPR) are financial entities within the scope of DORA from 17 January 2025. Because the platform itself is the entire service, ICT resilience is not a back-office concern for a CSP, it is the core of the business model: if the platform is down, no investment offers can be made, no investors can be onboarded, and no funds can flow to project owners.
DORA is proportionate, but not through Article 16. The simplified framework of Article 16 is reserved to a closed list (small and non-interconnected investment firms, exempted payment and e-money institutions, certain exempted credit institutions and small IORPs) and crowdfunding service providers are not on it. A CSP applies the full framework of Articles 5 to 15 and gets its proportionality from Article 4, which requires implementation in proportion to size, risk profile and the nature, scale and complexity of services, and from the specific reliefs DORA grants to microenterprises. The challenge is translating a regulation written with large banks in mind into a workable, affordable programme for a team that may number a dozen people, all while keeping the platform available and investor data secure.
DORA applies to crowdfunding service providers authorised under ECSPR (Regulation (EU) 2020/1503), per Article 2(1)(p) of DORA, regardless of size and regardless of whether they hold client funds. The simplified framework of Article 16 does not extend to CSPs: Article 16(1) is a closed list and crowdfunding is not on it. A CSP therefore applies Articles 5 to 15, detailed in Delegated Regulation (EU) 2024/1774, scaled through the proportionality principle of Article 4 and the provisions that expressly relieve microenterprises (definition in Article 3 of DORA), for example on the independent internal-audit review of the framework and on the use of independent testers. The supervisory expectation is a full framework scaled down with documented reasons, not a lighter regime claimed by category.
DORA layers on top of, and does not replace, the operational and organisational requirements that CSPs already meet under ECSPR Articles 4 to 12 (sound governance, business continuity, conflicts of interest, and the use of third parties). Most CSPs do not hold client funds directly and rely on an authorised payment service provider or e-money institution to execute investor payments, so PSP dependency becomes a critical ICT third-party relationship that must be mapped and contractually managed under DORA. Platform availability, the integrity of the bulletin board, and accurate processing of investment commitments are where ECSPR conduct duties and DORA resilience obligations most clearly converge.
For a CSP the website or app is the entire service offering, so uptime and recovery objectives sit at the heart of the DORA ICT business continuity requirements (Articles 11 and 12). An outage during an active offer can stop investment commitments, freeze the bulletin board, and trigger conduct issues under ECSPR. Set realistic RTO and RPO targets and test that the hosting and CDN configuration can meet them.
The entry-knowledge test, appropriateness assessment and AML or KYC checks under ECSPR run through ICT systems that must be resilient and protected under DORA. A failure or compromise here can let unsuitable investors through or expose identity documents. Treat the onboarding pipeline as a high-criticality function in your asset and risk inventory.
Because most CSPs route investor funds through an authorised PSP or e-money institution rather than holding them, that provider is a key ICT third-party service supporting a critical function. Map this dependency, ensure the contract carries DORA-compliant clauses (audit, sub-outsourcing, exit, incident notice), and understand what happens to in-flight investments if the PSP suffers an outage.
DORA expects ICT business continuity and response-and-recovery plans, but for a small CSP these must be proportionate and genuinely usable by a handful of people. Document who does what when the platform fails, including key-person backups, and avoid plans that assume a 24x7 operations centre you do not have. A short, tested, role-based plan beats a 60-page document nobody can execute.
CSPs hold sensitive personal and financial data on retail and sophisticated investors and on project owners. DORA Article 9 requires protection and prevention measures (access control, encryption, backups) that also reinforce GDPR obligations. A breach of investor data is both a DORA-relevant ICT incident and a personal-data breach, so align your detection and notification workflows across both regimes.
Lean CSPs typically run on cloud infrastructure and SaaS tooling rather than owned data centres, which concentrates risk in a few critical providers. DORA requires a register of information on all ICT third-party arrangements and a pre-contractual risk assessment, whatever the size of the firm. Identify which providers support critical or important functions and ensure exit and portability are realistic.
Everything tailored to your sector, ready to use on day one.
Yes. DORA applies to all crowdfunding service providers authorised under ECSPR, regardless of size and regardless of whether you hold client funds, because the regulation targets ICT risk rather than balance-sheet risk. What changes with size is the calibration, not the framework: Article 16 is not open to CSPs, so a small platform applies Articles 5 to 15 scaled through Article 4 proportionality and the microenterprise reliefs. So the answer is that DORA applies, but proportionately.
No. Article 16(1) of DORA reserves the simplified framework to a closed list: small and non-interconnected investment firms, payment and e-money institutions benefiting from the PSD2 and EMD exemptions, certain exempted credit institutions and small IORPs. Crowdfunding service providers are not on it, whatever their size. What DORA does give a small CSP is Article 4: the framework must be implemented in proportion to size, risk profile and the nature, scale and complexity of services, and several provisions expressly relieve microenterprises, for example on the independent internal-audit review of the framework and on the use of independent testers. You still need governance accountability, an ICT risk management framework, a Register of Information and DORA incident handling; advanced Threat-Led Penetration Testing applies only to entities identified by their authorities, which a small CSP will not be.
For a microenterprise CSP the main cost is staff time to document and operationalise a proportionate implementation of the framework rather than expensive tooling, because much of what DORA requires (backups, access control, a continuity plan, third-party contracts) overlaps with existing ECSPR and GDPR obligations you already meet. Budget for an initial gap assessment, updating your key cloud and PSP contracts with DORA clauses, and an annual review and incident-response test. A focused programme reusing existing controls is far cheaper than building from scratch.
Almost certainly not. TLPT under DORA Articles 26 and 27 is reserved for entities identified by authorities as significant from an ICT and systemic perspective, which excludes the typical small or micro CSP. You do still owe proportionate digital operational resilience testing under Articles 24 and 25, meaning periodic vulnerability assessments and reviews appropriate to your size, but not the full TIBER-EU style red-team exercise.
Your PSP or e-money partner is an ICT third-party provider supporting a critical function (investor payments), so it must appear in your register of information and be covered by a contract with the required DORA provisions on access, audit, incident notification, sub-outsourcing and exit. You should also assess concentration risk and understand the PSP's own resilience, because an outage on their side directly halts investor fund flows on your platform. Engage them early, as many PSPs are updating contracts sector-wide.
Your national competent authority (NCA), the same body that authorised you under ECSPR, is responsible for supervising your DORA compliance, with ESMA playing a coordinating and standard-setting role at EU level and maintaining the public ECSPR register. There is no separate DORA licence; supervision is integrated into the existing ECSPR relationship with your NCA. Expect DORA matters, including your register of information and incident reporting, to be handled through that authority.
Start free: check your DORA scope, run a gap analysis, or estimate implementation cost. Need the full risk view? See the Risk Assessment Toolkits or compare all kits. All prices exclude VAT; an EU VAT invoice is issued at checkout. Professional templates, not legal advice.
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.