This article provides general informational guidance. See Legal Disclaimer .
DORA became applicable to EU financial entities on 17 January 2025. If you run a covered entity, the obligations apply now, not at some future deadline. The regulation reaches most regulated financial entities, including small payment institutions, e-money institutions, investment firms, and crypto-asset service providers. Since November 2025 it also covers a growing list of "critical" ICT third-party providers under direct EU supervision. Microenterprises get a lighter regime under DORA's proportionality rules. They don't get an exemption.
Key Takeaways
- DORA is already in force. It became applicable on 17 January 2025. If you run a fintech SME in scope, you're already inside the compliance window.
- Scope is broad, and it reaches many fintech SMEs directly. Article 2(1) names small payment institutions, e-money institutions, investment firms, crowdfunding platforms, and crypto-asset service providers. Size alone doesn't remove you from scope.
- Proportionality simplifies the regime. It doesn't remove it. Microenterprises and certain smaller entities get a streamlined ICT risk-management framework: fewer formal requirements, not zero requirements.
- ICT providers to financial entities are now under the same spotlight. In November 2025, EU supervisors designated the first "critical" ICT third-party providers for direct oversight. The third-party-risk pillar of DORA is enforced now, not theoretical.
Who is actually in scope
DORA's Article 2(1) list runs long. The fintech-relevant core includes credit institutions, payment institutions (including those exempted under PSD2/PSD3), electronic money institutions, investment firms, crypto-asset service providers (CASPs), crowdfunding service providers, and management companies, among others. A few categories fall outside it: some alternative investment fund managers, and persons exempted under MiFID II.
If you run a fintech SME and any part of your business is licensed or registered under one of the categories above, DORA applies to you directly, regardless of headcount. Founders often assume DORA is "for banks." In practice it reaches deep into the smaller regulated-fintech layer. For a broader overview of the framework and key thresholds, consult our dedicated DORA regulation guide .
The proportionality question: are you exempt if you're small?
No. You may qualify for a lighter regime instead. According to the Themio Digital Compliance Barometer , more than 51% of mid-sized financial entities have not yet formalized their third-party ICT registry or tested their 24-hour early warning response. DORA builds in proportionality: microenterprises and certain smaller or non-interconnected financial entities can apply a simplified ICT risk-management framework rather than the full requirement set built for large, systemic institutions. In practice:
- You still need an ICT risk-management framework. It can be simpler and scaled to your size and risk profile, but it can't be absent.
- You still need to classify and report major ICT incidents on the same timelines as larger entities (see below). Proportionality reduces the framework's complexity, not the incident-reporting obligation.
- You still need a register of your ICT third-party providers and contractual safeguards with them.
Confirm your specific proportionality treatment with your national competent authority (such as the AMF or ACPR in France, BaFin in Germany, or the CSSF in Luxembourg). The simplified regime's exact boundaries sit in regulatory technical standards (RTS), and getting this wrong in either direction wastes budget or creates exposure.
The five pillars, in practice for a fintech SME
| Pillar | What it requires | Fintech SME reality check |
|---|---|---|
| ICT risk management | Governance, risk identification, security policy, business continuity, annual testing | Usually your biggest lift if you don't already have a formal ICT risk framework |
| Incident classification & reporting | Major ICT incidents: initial report within 24h, interim report within 72h, final report within 1 month | The timelines are tight and non-negotiable. This is where an untested process fails first. |
| Digital operational resilience testing | Vulnerability assessments, penetration testing, crisis simulations; advanced threat-led testing (TLPT) every 3 years for systemic entities | Most fintech SMEs fall under basic testing, not the advanced threat-led regime. Confirm which bucket you're in. |
| Third-party ICT risk management | Register of Information on all ICT providers, contractual safeguards, oversight of critical providers | Relevant if you rely on cloud, core banking, or payment infrastructure vendors. Check whether any of your vendors sit on the EU's critical-provider list. |
| Information sharing | Voluntary threat-intelligence sharing arrangements with trusted financial peers | The lowest-friction pillar. Optional, but increasingly expected in practice by supervisors. |
Why the November 2025 critical-provider designation matters to you
On 18 November 2025, the European Supervisory Authorities (ESAs — EBA, ESMA, and EIOPA) designated the first batch of "critical" ICT third-party providers under DORA: entities that provide core infrastructure, cloud, and data services to financial entities of every type and size across the EU. These providers now sit under direct EU oversight.
This matters to a fintech SME even if you're not one of the designated providers yourself. If any of your ICT vendors made that list, your own third-party risk register and contractual safeguards with them now operate in a live-supervised environment, not a theoretical one. Check your vendor register against the published designation list and ensure your contracts include the mandatory Article 30 audit and termination provisions.
Frequently Asked Questions
This article provides general information on EU regulatory developments. It does not constitute legal advice. Themio does not replace a lawyer, ICT risk specialist, or your national competent authority: confirm your specific DORA scope and proportionality treatment with qualified advisers. Sources: AMF France — DORA regulation overview; European Banking Authority — ESAs designate critical ICT third-party providers, 18 November 2025 (cross-checked 24 August 2026). Primary source: Regulation (EU) 2022/2554 (DORA) . Last updated: September 16, 2026.