DORA Sector Guide

DORA for Payment & E-money Institutions

DORA for payment institutions and e-money issuers: operational resilience for transaction flows, safeguarding accounts, and SCA-protected fraud controls.

Supervised by National competent authorities under PSD2 (for example BaFin, ACPR, Banca d'Italia, DNB, CBI) supervise the DORA compliance of the payment and e-money institutions they authorise or register. The three ESAs (EBA, EIOPA, ESMA) draft the DORA technical standards jointly and run the Oversight Framework for designated critical ICT third-party providers; the EBA remains the standard-setter for the PSD2 conduct, strong customer authentication and fraud-reporting rules that continue to apply. Updated September 2026
Save up to 30% when you bundle your purchases−15% from €150 · −20% from €300 · −25% from €500 · −30% from €800: discount applied automatically at checkout (excl. VAT).
View cart →

Payment institutions (PIs) and electronic money institutions (EMIs) authorised or registered under PSD2 and the E-money Directive, including institutions benefiting from the small-institution exemptions, are explicitly in scope of DORA (Article 2(1)(b) and (d) of Regulation (EU) 2022/2554) and have been bound by its requirements since 17 January 2025. Because their entire business model runs on always-on digital transaction processing, card scheme connectivity and real-time fraud screening, ICT availability and integrity are not back-office concerns but the core of the regulated service itself.

DORA replaces the previously fragmented ICT expectations with a single, directly applicable framework covering ICT risk management, incident reporting, digital operational resilience testing, third-party risk and information sharing. The PSD2 major-incident reporting channel has been switched off for DORA entities (Article 96(7) PSD2, inserted by Directive (EU) 2022/2556), the EBA has repealed its Guidelines on major incident reporting under PSD2 and narrowed its Guidelines on ICT and security risk management (EBA/GL/2025/02, applicable since 20 May 2025), and the EBA Guidelines on outsourcing arrangements remain relevant only for non-ICT outsourcing. For PIs and EMIs the practical challenge is mapping the five DORA pillars onto distinctive operational realities: safeguarding of client funds, dependency on BIN sponsors and acquirers, networks of agents and distributors, and strong customer authentication (SCA) infrastructure.

Is your firm in scope?

Under Article 2(1)(b) and (d) of DORA, payment institutions and electronic money institutions are financial entities in their own right, and the Regulation says so expressly for institutions benefiting from the small-institution exemptions of PSD2 Article 32 and E-money Directive Article 9: they are in scope too. Account information service providers are listed separately at Article 2(1)(c). Authorisation status therefore determines which ICT risk management framework applies, not whether DORA applies. Exempted (registered) PIs and EMIs apply the simplified framework of Article 16, detailed in Delegated Regulation (EU) 2024/1774, by operation of law. Authorised PIs and EMIs, and AISPs, apply the full framework of Articles 5 to 15 whatever their size, calibrated through the proportionality principle of Article 4 and the specific reliefs the Regulation grants to microenterprises. There is no interconnectedness test and no opt-in: a small authorised PI cannot elect Article 16, and an exempted institution is not pushed into the full framework because it connects to card schemes. Passporting, EU branches and group membership change none of this.

How DORA fits your existing regime

DORA is lex specialis for ICT risk. Directive (EU) 2022/2556 amended PSD2 so that Chapter II of DORA governs ICT and security risk management for every PSD2 payment service provider that is a DORA financial entity, exempted institutions included (new subparagraph in Article 95(1)), and so that the PSD2 major incident reporting regime no longer applies to them (Article 96(7)). The EBA drew the consequences: its Guidelines on major incident reporting under PSD2 (EBA/GL/2021/03) were repealed with effect from the application of DORA, and its Guidelines on ICT and security risk management (EBA/GL/2019/04) were amended by EBA/GL/2025/02, applicable since 20 May 2025, so that for DORA entities only the requirements on the relationship with payment service users remain. PSD2 continues to govern licensing, conduct, strong customer authentication (RTS on SCA and CSC under Article 98, Delegated Regulation (EU) 2018/389) and safeguarding of funds, and PSD2 fraud reporting under EBA/GL/2018/05 stays live. PSD3 and the Payment Services Regulation, whose final texts were agreed by the co-legislators in April 2026, will replace PSD2 for licensing and conduct 18 months or more after their publication in the Official Journal, which was still awaited when this pack was revised; they defer to DORA for ICT risk, so the resilience obligations described in this pack do not change with them.

What DORA means for Payment & E-money Institutions

ICT risk framework over the whole payment chain

Articles 5 to 15, detailed in Delegated Regulation (EU) 2024/1774, require a board-approved ICT risk management framework that maps the end-to-end transaction lifecycle: authorisation, clearing, settlement and reconciliation. For PIs/EMIs this means inventorying ICT assets that touch card scheme gateways, payment processors and core ledgers, and assigning protection, detection and recovery controls proportionate to the criticality of payment continuity. Exempted institutions apply the simplified framework of Article 16 to the same payment chain, with lighter governance and documentation.

Safeguarding accounts as a critical function

Client funds must be safeguarded under PSD2 Art. 10 / EMD Art. 7, and the ICT systems that calculate, reconcile and protect safeguarded balances qualify as supporting a critical or important function under DORA. Loss of integrity or availability in the safeguarding ledger is a resilience event, so it must be covered by business impact analysis, RTO/RPO targets, and the digital operational resilience testing programme.

SCA and fraud-control resilience

Strong customer authentication, 3-D Secure and transaction risk analysis engines are ICT systems whose downtime directly blocks legitimate payments and exposes the firm to fraud. DORA requires these authentication and fraud-monitoring components to be subject to the same protection, monitoring, and resilience-testing controls as core processing, while PSD2 RTS on SCA & CSC continues to dictate the authentication logic itself.

Agents, distributors and the extended attack surface

Networks of agents (PSD2 Art. 19) and e-money distributors extend the firm's ICT perimeter to endpoints and onboarding flows it does not fully control. DORA obliges the institution to manage ICT risk arising from these channels, including identity and access management, data protection at the edge, and incident detection covering agent-facing systems, even though the agents themselves are not the regulated entity.

BIN sponsors, schemes and concentration risk

Many PIs/EMIs depend on a BIN sponsor, a single acquirer, or card schemes (Visa, Mastercard) and processors that are de facto unsubstitutable. Articles 28 to 30 require these dependencies to be recorded in the Register of Information (Implementing Regulation (EU) 2024/2956 templates, collected by the competent authority on an annual cycle), assessed for concentration and exit risk, and governed by contracts meeting Article 30, with subcontracting chains handled under Delegated Regulation (EU) 2025/420 and realistic exit and stressed-scenario planning for providers that cannot be quickly replaced. The ESAs designated the first critical ICT third-party providers in November 2025; a designation changes the provider's oversight, not the institution's own obligations.

Resilience testing tailored to payment continuity

Articles 24 to 27 require a risk-based testing programme; for most PIs/EMIs this means vulnerability scans, scenario-based recovery tests of payment and safeguarding systems and penetration testing, while Threat-Led Penetration Testing (TLPT, Delegated Regulation (EU) 2025/1190, aligned with TIBER-EU) applies only to entities identified by their authorities on the basis of systemic importance and risk profile. Smaller PIs/EMIs should document why TLPT does not apply and still evidence robust functional and recovery testing.

Incident reporting

Under Article 19 DORA, Delegated Regulation (EU) 2024/1772 (classification criteria and materiality thresholds) and Delegated Regulation (EU) 2025/301 with Implementing Regulation (EU) 2025/302 (content, timelines and templates), PIs and EMIs classify ICT-related incidents on clients and counterparts affected, transactions affected, duration and service downtime, geographical spread, data losses, criticality of services and economic impact, and report major incidents to their competent authority in three steps: initial notification within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it, intermediate report within 72 hours of the initial notification, final report within one month of the intermediate report. This DORA channel replaces the former PSD2 Article 96 filing, which Article 96(7) PSD2 disapplies for DORA entities and whose EBA Guidelines (EBA/GL/2021/03) have been repealed. Firms must still preserve PSD2 fraud reporting (EBA/GL/2018/05) and recognise the overlap where a payment-fraud event is simultaneously an ICT security incident, triggering both a DORA notification and PSD2 fraud statistics. Significant cyber threats may be notified voluntarily under Article 19(2).

The Payment & E-money Institutions compliance pack

Everything tailored to your sector, ready to use on day one.

  • 30-point sector compliance checklist (Excel) across the 5 DORA pillars
  • Sector policy & contract adaptations
  • Scoping & proportionality notes + action plan
  • Sector implementation guide (PDF) with the questions and the regime mapping
€129 excl. VAT
one-off · instant download · lifetime updates
  Get the pack: €129

Train your Payment & E-money Institutions team

For payment & e-money institutions: compliance, incident reporting, third-party oversight and continuity for high-availability rails.

  • 4 role certifications curated for Payment & E-money Institutions
  • Verifiable PDF certificate per learner · lifetime access
  • Buy for one person or as a multi-seat team licence
€199 excl. VAT
€266
  Get the team track

Frequently asked questions

Are payment and e-money institutions actually in scope of DORA, or only banks?

Yes. Payment institutions and electronic money institutions are named financial entities in Article 2(1)(b) and (d) of DORA, and the text adds "including payment institutions exempted pursuant to Directive (EU) 2015/2366" and "including electronic money institutions exempted pursuant to Directive 2009/110/EC". Account information service providers are listed at Article 2(1)(c). All have been bound since 17 January 2025; passporting, EU branches and group membership change nothing. What your status changes is the framework: authorised institutions apply Articles 5 to 15, exempted ones apply Article 16.

Can a smaller PI or EMI use the simplified Article 16 regime?

Only if it is an exempted institution. Article 16(1) lists, for the payments sector, payment institutions exempted under PSD2 Article 32 and electronic money institutions exempted under E-money Directive Article 9: they apply the simplified framework by operation of law, as detailed in Delegated Regulation (EU) 2024/1774. An authorised PI or EMI cannot opt in, however small: it applies the full framework and calibrates it through Article 4 proportionality and the microenterprise reliefs. The "small and non-interconnected" criterion that is often quoted belongs to investment firms (Article 12 of the Investment Firms Regulation) and has no bearing on payment institutions.

How does DORA change our PSD2 incident reporting?

Directive (EU) 2022/2556 inserted Article 96(7) into PSD2: the major operational or security incident reporting of Article 96(1) to (5) no longer applies to payment service providers that are DORA financial entities, exempted PIs and EMIs included. The EBA repealed its Guidelines on major incident reporting under PSD2 (EBA/GL/2021/03) accordingly. You now file once, through the DORA channel, using the classification criteria of Delegated Regulation (EU) 2024/1772 and the 4-hour / 72-hour / one-month sequence and templates of Delegated Regulation (EU) 2025/301 and Implementing Regulation (EU) 2025/302. PSD2 fraud reporting under EBA/GL/2018/05 continues separately.

Do our safeguarding arrangements fall under DORA?

The legal safeguarding obligation stays under PSD2 Art. 10 / EMD Art. 7, but the ICT systems that compute, reconcile and protect safeguarded client balances support a critical or important function and are therefore squarely within DORA. You must include them in your asset inventory, business impact analysis, recovery objectives, and resilience testing, treating a loss of safeguarding-ledger integrity as a reportable resilience risk.

Will we be required to perform Threat-Led Penetration Testing (TLPT)?

TLPT under Articles 26-27 applies only to financial entities identified by competent authorities as significant for financial stability or based on their role and risk profile; the majority of PIs and EMIs will not be designated. You should still run a full risk-based testing programme (vulnerability assessments, scenario and recovery tests, and penetration testing of payment, SCA and safeguarding systems), and keep documentation explaining why TLPT does or does not apply to you.

Our card scheme and BIN sponsor are impossible to replace quickly. How does DORA treat that?

DORA Articles 28-30 require you to record these dependencies in the Register of Information, assess concentration and substitutability risk, and ensure contracts include the mandatory provisions on access, audit, sub-outsourcing, exit and incident cooperation. Where a provider is genuinely hard to substitute, you must document a realistic exit strategy and stressed continuity scenarios rather than relying on the assumption that the service will always be available.

Will PSD3 and the Payment Services Regulation change our DORA obligations?

No. The final PSD3 and PSR texts were agreed by the European Parliament and the Council in April 2026 and were awaiting publication in the Official Journal when this pack was revised; most provisions apply 18 months or more after entry into force. They reshape licensing, conduct, fraud liability and open banking, and fold e-money institutions into the payment institution regime, but they leave ICT risk, incident reporting, resilience testing and third-party risk to DORA. Plan the PSD3 transition on top of a stable DORA baseline, and re-check your DORA status if your licence category changes.

Start free: check your DORA scope, run a gap analysis, or estimate implementation cost. Need the full risk view? See the Risk Assessment Toolkits or compare all kits. All prices exclude VAT; an EU VAT invoice is issued at checkout. Professional templates, not legal advice.

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
173
certificates issued
112
certified professionals
21
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join the Webinar Waiting List