Scan URL

DORA

DORA ICT Third-Party Service Provider Scope

Determine whether your SaaS or cloud service is classified as an ICT Third-Party Service Provider under DORA Articles 28 & 30 when selling to European financial entities.

Last updated: 15 March 2026

Do DORA ICT Third Party Vendor Scope need to comply with DORA?

Determine whether your SaaS or cloud service is classified as an ICT Third-Party Service Provider under DORA Articles 28 & 30 when selling to European financial entities. If yes: Critical ICT Third-Party Provider (Direct ESA Oversight). If not: Out of Scope of DORA. Use the inter…

  • Yes path: Critical ICT Third-Party Provider (Direct ESA Oversight)
  • No path: Out of Scope of DORA
  • Use the step-by-step decision tree below for your exact situation
Source: EUR-Lex — DORA (Regulation 2022/2554)Reviewed:
Step 1

DORA · Question 1

Do you provide software, cloud hosting, APIs, or data services to regulated EU financial entities (banks, payment institutions, insurers, investment funds)?

DORA Regulation (EU) 2022/2554 applies to financial entities, which must enforce statutory oversight over their ICT suppliers.

For informational purposes only. Consult qualified legal counsel before making compliance decisions.

Decision tree questions

  1. Do you provide software, cloud hosting, APIs, or data services to regulated EU financial entities (banks, payment institutions, insurers, investment funds)?

    DORA Regulation (EU) 2022/2554 applies to financial entities, which must enforce statutory oversight over their ICT suppliers.

    • Yes: Continue to: Does your software support a 'critical or important function' of the financial entity (e.g. core payment processing, regulatory reporting, client account access, or continuous trading)?
    • No: Out of Scope of DORA
  2. Does your software support a 'critical or important function' of the financial entity (e.g. core payment processing, regulatory reporting, client account access, or continuous trading)?

    Article 3(22) defines a critical function as one whose disruption would materially impair financial performance, business continuity, or regulatory compliance.

    • Yes: Continue to: Has your organization been officially designated as a 'Critical ICT Third-Party Provider' (CTPP) by the European Supervisory Authorities (EBA, ESMA, EIOPA)?
    • No: Standard ICT Third-Party Service Provider (Non-Critical)
  3. Has your organization been officially designated as a 'Critical ICT Third-Party Provider' (CTPP) by the European Supervisory Authorities (EBA, ESMA, EIOPA)?

    CTPP designation is reserved for systemic cloud hyperscalers (e.g. AWS, Microsoft Azure, Google Cloud) that represent systemic risk to the European financial system.

    • Yes: Critical ICT Third-Party Provider (Direct ESA Oversight)
    • No: In-Scope ICT Provider Supporting Critical Financial Functions