Assess your DORA exposure
How to tell if your product falls under DORA's critical ICT scope
Under DORA Article 31, the three European Supervisory Authorities — EBA, ESMA, and EIOPA — jointly assess ICT providers and designate which ones are “critical.” That designation triggers a formal oversight regime.
But that doesn’t mean you should wait passively. If your product serves financial institutions in the EU, understanding the criteria now lets you prepare — or restructure — before a designation lands.