DORA simplified regime for minor financial entities

DORA regime semplificato per entità finanziarie minori

The Digital Operational Resilience Act introduces a simplified DORA framework for ICT risk management, aimed at financial entities that are smaller in size or have limited interconnection. This regime aims to ensure a high level of digital operational resilience without imposing excessive administrative burdens.

Who can fall under Art. 16

The applicability of the simplified regime is limited to an exhaustive list of categories defined by Art. 16 of DORA. These categories include:

  • Small and non-interconnected investment firms
  • Payment institutions exempted under Directive (EU) 2015/2366
  • Electronic money institutions exempted under Directive 2009/110/EC
  • Small institutions for occupational retirement provision (IORPs)

Entities falling into these categories are generally characterized by a reduced scale of operations and, at times, a limited number of employees.

What really changes in terms of testing and governance

DORA proportionality translates into a less granular framework compared to the general one, as outlined in Title III of Delegated Regulation 2024/1774. The main differences include:

  • Governance and Organization: The ESAs’ mandate for the simplified framework is broader, as it includes the definition of the entire framework and not just additional elements. The requirements, however, are adapted to the entity’s complexity. The management body retains final responsibility, but decision-making processes are leaner.
  • Business Continuity: Operational continuity requirements remain but with a lower level of detail. Specific “Response and Recovery” plans or the extremely complex test scenarios provided for in the ordinary regime are not required.
  • Security Testing: Entities must adopt a risk-based testing plan, including vulnerability scans and assessments to identify weaknesses. The frequency and depth of tests are calibrated to the risk profile.

Minimum controls not to be overlooked

Although the framework is simplified, there are mandatory obligations for DORA small financial entities:

  • Identification and Classification: Obligation to identify, classify, and document all critical or important functions, related ICT assets, and interdependencies.
  • ICT Operations Security: Monitoring of assets supporting critical functions, management of obsolete assets, event logging, and implementation of measures to detect threats and vulnerabilities.
  • Access Control: Definition and implementation of rigorous procedures for logical and physical access control.

How to avoid under-compliance in the name of proportionality

Proportionality must be interpreted as a commensurate application of requirements, not as a waiver. Entities must be able to demonstrate to authorities that the adopted framework, while simplified, is adequate for managing specific ICT risks. In cases of particular complexity, it may be necessary to strengthen controls in certain areas.

Examples of a minimum effective plan

  • ICT asset inventory updated regularly, with a clear mapping of third-party dependencies
  • Vulnerability management procedure that uses automated scans to identify vulnerabilities in critical systems
  • Business continuity test plan tested at least annually to verify the ability to restore essential functions
  • Periodic review of the ICT risk management framework, documented in a report to be presented to the authority upon request

FAQ

  • Does “simplified” mean less responsibility?
  • No. The management body of the financial entity retains full responsibility for managing ICT risks and for compliance with legal requirements.
  • Is a vulnerability assessment still required?
  • Yes. Entities must conduct evaluations and DORA vulnerability assessments (scans) to identify and address risks promptly, in line with their risk profile.
  • Is it still necessary to classify assets and critical functions?
  • Yes, this is a fundamental prerequisite. The identification and classification of critical or important functions and the ICT assets that support them is mandatory even in the simplified regime.

Ensure your resilience: request an eligibility check and a personalized scoping of your simplified framework today to be ready by January 17, 2025.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!