Skip to content
OUT OF SCOPE

Out of DORA's scope

An entity not listed in Article 2 of the regulation, or subject to another sectoral cyber regulation.

Download this sheet to share or keep it.

Download as PDF

Your obligations

  • 1

    No direct obligation under DORA.

    None of DORA's governance, incident notification or resilience testing requirements apply directly to your organisation.

  • 2

    Check whether another regulation applies (NIS2, GDPR...).

    Depending on your sector of activity, you may still be subject to NIS2 or other cybersecurity or data protection obligations.

  • 3

    You may be indirectly bound by contractual clauses if you are a provider to an entity subject to DORA.

    A financial client subject to DORA may contractually impose certain requirements on you (audit, incident notification) even if you are not directly targeted by the regulation.