Previous Article Back to Blog
September 16, 2026 Majda Skrijelj (Consultant & Chief Regulation Untangler) 6 min read DORA

DORA Compliance for Fintech SMEs: What Actually Applies to You (2026)

Executive Summary

DORA became applicable to EU financial entities on 17 January 2025. If you run a covered entity, the obligations apply now, not at some future deadline. The regulation reaches most regulated financial entities, including small payment institutions, e-money institutions, investment firms, and crypto-asset service providers. Since November 2025 it also covers a growing list of "critical" ICT third-party providers under direct EU supervision. Microenterprises get a lighter regime under DORA's proportionality rules. They don't get an exemption.

17 Jan
In Force Since 2025

DORA has been legally binding across all EU member states with zero grace period for covered entities.

Nov 2025
Critical ICT Oversight

first designation batch of critical third-party ICT service providers under direct EU supervisory oversight.

Key Takeaways

  • DORA is already in force. It became applicable on 17 January 2025. If you run a fintech SME in scope, you're already inside the compliance window.
  • Scope is broad, and it reaches many fintech SMEs directly. Article 2(1) names small payment institutions, e-money institutions, investment firms, crowdfunding platforms, and crypto-asset service providers. Size alone doesn't remove you from scope.
  • Proportionality simplifies the regime. It doesn't remove it. Microenterprises and certain smaller entities get a streamlined ICT risk-management framework: fewer formal requirements, not zero requirements.
  • ICT providers to financial entities are now under the same spotlight. In November 2025, EU supervisors designated the first "critical" ICT third-party providers for direct oversight. The third-party-risk pillar of DORA is enforced now, not theoretical.

Who is actually in scope

DORA's Article 2(1) list runs long. The fintech-relevant core includes credit institutions, payment institutions (including those exempted under PSD2/PSD3), electronic money institutions, investment firms, crypto-asset service providers (CASPs), crowdfunding service providers, and management companies, among others. A few categories fall outside it: some alternative investment fund managers, and persons exempted under MiFID II.

If you run a fintech SME and any part of your business is licensed or registered under one of the categories above, DORA applies to you directly, regardless of headcount. Founders often assume DORA is "for banks." In practice it reaches deep into the smaller regulated-fintech layer. For a broader overview of the framework and key thresholds, consult our dedicated DORA regulation guide .

The proportionality question: are you exempt if you're small?

No. You may qualify for a lighter regime instead. According to the Themio Digital Compliance Barometer , more than 51% of mid-sized financial entities have not yet formalized their third-party ICT registry or tested their 24-hour early warning response. DORA builds in proportionality: microenterprises and certain smaller or non-interconnected financial entities can apply a simplified ICT risk-management framework rather than the full requirement set built for large, systemic institutions. In practice:

  • You still need an ICT risk-management framework. It can be simpler and scaled to your size and risk profile, but it can't be absent.
  • You still need to classify and report major ICT incidents on the same timelines as larger entities (see below). Proportionality reduces the framework's complexity, not the incident-reporting obligation.
  • You still need a register of your ICT third-party providers and contractual safeguards with them.

Confirm your specific proportionality treatment with your national competent authority (such as the AMF or ACPR in France, BaFin in Germany, or the CSSF in Luxembourg). The simplified regime's exact boundaries sit in regulatory technical standards (RTS), and getting this wrong in either direction wastes budget or creates exposure.

The five pillars, in practice for a fintech SME

Pillar What it requires Fintech SME reality check
ICT risk management Governance, risk identification, security policy, business continuity, annual testing Usually your biggest lift if you don't already have a formal ICT risk framework
Incident classification & reporting Major ICT incidents: initial report within 24h, interim report within 72h, final report within 1 month The timelines are tight and non-negotiable. This is where an untested process fails first.
Digital operational resilience testing Vulnerability assessments, penetration testing, crisis simulations; advanced threat-led testing (TLPT) every 3 years for systemic entities Most fintech SMEs fall under basic testing, not the advanced threat-led regime. Confirm which bucket you're in.
Third-party ICT risk management Register of Information on all ICT providers, contractual safeguards, oversight of critical providers Relevant if you rely on cloud, core banking, or payment infrastructure vendors. Check whether any of your vendors sit on the EU's critical-provider list.
Information sharing Voluntary threat-intelligence sharing arrangements with trusted financial peers The lowest-friction pillar. Optional, but increasingly expected in practice by supervisors.

Why the November 2025 critical-provider designation matters to you

On 18 November 2025, the European Supervisory Authorities (ESAs — EBA, ESMA, and EIOPA) designated the first batch of "critical" ICT third-party providers under DORA: entities that provide core infrastructure, cloud, and data services to financial entities of every type and size across the EU. These providers now sit under direct EU oversight.

This matters to a fintech SME even if you're not one of the designated providers yourself. If any of your ICT vendors made that list, your own third-party risk register and contractual safeguards with them now operate in a live-supervised environment, not a theoretical one. Check your vendor register against the published designation list and ensure your contracts include the mandatory Article 30 audit and termination provisions.

What Themio does for you

Themio's DORA module launches in early 2027. Once it's live, the audit will run your organisation against the Article 2(1) scope test, flag whether you qualify for the simplified proportionality regime, and surface gaps in your ICT risk-management, incident-reporting, and third-party-register documentation against the five pillars above.

Join the DORA early-access waitlist →

Frequently Asked Questions

Is DORA still a future requirement I can plan for later?
No. DORA has applied since 17 January 2025. If you run a covered entity, you are expected to be compliant now, not at some future transposition deadline.
I run a 12-person payment institution. Am I really in scope?
Likely yes, directly, regardless of headcount. DORA's scope depends on regulatory status: are you a licensed or registered payment institution, e-money institution, investment firm, and so on. Size decides your proportionality tier, not whether DORA applies at all.
What's the difference between "simplified regime" and "exempt"?
A simplified regime is a lighter version of the same obligations. You still need an ICT risk framework, incident reporting, and a third-party register, scaled to your size and risk profile. Being small does not exempt a covered entity type.
We're not a financial entity. We just sell software to banks. Does DORA affect us?
Potentially, through the third-party risk pillar. Your bank or fintech customers may need to apply DORA-driven contractual safeguards to their agreements with you. If your services reach sufficient scale, you could eventually be considered for critical provider designation and direct EU oversight.
What happens if we miss an incident-reporting deadline?
Confirm this with your national competent authority or legal counsel. Consequences vary by member state and by the specifics of the incident, so penalties cannot be generalized to a single statutory figure.
Majda Skrijelj

Senior Compliance Officer currently at an international financial institution, Majda has over 20 years of experience at the intersection of governance, anti-corruption, and European regulatory risk (GDPR, AI Act, DORA).