Free scope check

Am I in DORA scope?

Answer 7 quick questions for an indicative read on whether the Digital Operational Resilience Act applies to your entity, which pillars apply, and what to do next.

~3 minutes No signup Instant result

Question 1 of 7

What type of organisation are you?

DORA Article 2 lists the financial entities in scope.

Question 2 of 7

Are you established or authorised in the EU (or providing regulated services into the EU)?

Question 3 of 7

Is your entity a microenterprise?

Fewer than 10 staff and annual turnover or balance sheet ≤ €2m.

Question 4 of 7

Do any of these Article 2(3) exemptions apply to you?

DORA explicitly excludes a few categories.

Question 5 of 7

Are you a "small and non-interconnected" investment firm, or an exempt/small payment, e-money or AISP entity?

These qualify for the simplified ICT risk management framework (Article 16).

Question 6 of 7

Do you rely on ICT systems to deliver critical or important functions?

Functions whose disruption would materially impair your services, soundness or continuity.

Question 7 of 7

Are you a significant / systemically important entity?

e.g. a significant credit institution (SSM), CCP, CSD — relevant to Threat-Led Penetration Testing (TLPT) obligations.

Please answer every question for an accurate read.

Pillars likely to apply

P1 · ICT Risk
P2 · Incidents
P3 · Testing
P4 · Third-Party
P5 · Info Sharing

Indicative only. This tool is an educational aid, not legal advice or a formal regulatory determination. DORA scope depends on the precise legal classification of your entity (Article 2) and any applicable exemptions. For a definitive answer, get a written Scope Determination or consult a legal partner.

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar