Scope, settled
Does DORA apply to your UK firm? Work it out in 2 minutes
DORA is EU law and the UK never onshored it, so the question is not whether the UK is covered. It is whether any route into the EU catches your firm: entities, clients or contracts. Four questions, answered in order, settle it.
The decision tree
Four questions, in order
Start at question 1 and stop at the first yes. Each answer tells you what it means in practice and what to do next.
Reviewed July 2026.
-
Question 1
Do you have entities incorporated in the EU?
If yes
In scope, directly. Any EU-incorporated company in your group that meets DORA's definition of a financial entity carries the obligations itself, regardless of who owns it.
What it means
Practically, that entity needs an ICT risk framework, incident reporting arrangements, a testing programme and a register of information of its own. Because groups rarely run two standards, the EU entity's rulebook tends to become the group's rulebook.
What to do next
Scope it entity by entity. A gap analysis that starts with an applicability note tells you which companies carry which obligations before anyone builds anything.
No EU entities? Move to question 2.
-
Question 2
Do you serve clients in the EU as a financial entity?
If yes
Very likely in scope, through the authorisation that makes the business lawful. Since passporting ended, serving EU clients as a financial entity usually requires an EU authorisation or branch somewhere in the structure, and that authorised entity is a DORA financial entity in its own right.
What it means
The obligations sit with the EU-authorised entity, but its systems, suppliers and incident processes are usually shared with the UK parent, so the compliance work lands on the group either way.
What to do next
Map the legal route your EU revenue actually takes. The route determines which entity carries DORA, and how much of the group it drags in.
No EU clients served as a financial entity? Move to question 3.
-
Question 3
Are you an ICT service provider to EU financial entities?
If yes
Caught, but through their obligations rather than yours. DORA regulates EU firms' technology suppliers by contract: expect mandatory terms flowed down into your agreements, a place in each client's register of information, and, for the very largest providers, the possibility of designation and direct EU oversight.
What it means
In practice this arrives as repapering: your EU clients send revised contract terms, questionnaires and audit clauses, and renewal becomes conditional on your answers. The subcontracting rules in force since April 2025 push the same terms further down the chain.
What to do next
Prepare the evidence before the paperwork arrives. Suppliers who can answer the register of information questions quickly keep their contracts moving.
Not supplying ICT services to EU financial entities? Move to question 4.
-
Question 4
None of the above?
If this is you
You are outside DORA's direct scope. No EU entities, no EU clients served as a financial entity, no ICT contracts with EU financial entities: there is no route by which the regulation reaches you today.
What it means
Your resilience obligations are domestic ones. The FCA and PRA operational resilience rules apply if you are UK-regulated, and the UK's Critical Third Parties regime now mirrors DORA's oversight of major technology providers at home.
What to do next
Re-run this page when your structure changes. A first EU client, a new EU subsidiary or a contract with an EU financial entity changes the answer.
Landed on question 4? Your obligations live with the UK regime and the Critical Third Parties regime instead. Landed anywhere else? The DORA hub covers what the regulation actually asks of you.
Already half done
The PS21/3 overlap, mapped
If you are in scope for both regimes, the work overlaps more than the vocabulary suggests. This table shows each DORA pillar against the nearest UK requirement: a direction of travel, not an equivalence.
| DORA pillar | Nearest UK requirement |
|---|---|
| ICT risk management | PS21/3 and SS1/21: important business services mapped, impact tolerances set, and a framework the board owns. |
| ICT incident reporting | FCA and PRA notification expectations for operational incidents; the reporting triggers and timescales differ, the underlying facts do not. |
| Digital operational resilience testing | Scenario testing under the UK regime, with CBEST and STAR-FS as the threat-led equivalents of DORA's TLPT. |
| ICT third-party risk management | The UK outsourcing and third-party rules, plus the Critical Third Parties regime overseeing major providers directly. |
| Information sharing | No direct UK mirror; threat intelligence sharing in the UK runs through voluntary industry arrangements. |
Where it gets contested
The common edge cases
Most firms resolve cleanly through the four questions. These three structures are where the answer needs more care.
UK subsidiary of an EU parent
Ownership alone does not put the UK company in scope: DORA attaches to the EU entities, not to their shareholdings. But the parent's group framework will flow down through policy, and if the UK subsidiary provides ICT services to the parent, it enters the register of information as an intra-group provider, with the same contract terms as any external supplier.
EU branch of a UK firm
A branch usually exists because a local authorisation requires it, and that authorisation is what brings DORA expectations with it. Treatment varies by member state and by sector, which makes this the classic case for a written applicability note rather than an assumption either way.
Delegated portfolio management
A UK manager running money under delegation from an EU fund or manager is providing portfolio management, not an ICT service, so the delegation itself does not trigger DORA. But the EU principal is re-examining every arrangement under its own obligations, and any technology supplied alongside the mandate, reporting portals or data feeds for instance, can be classed as an ICT service and repapered accordingly.
Still unsure?
Then the honest answer is: it depends on your paperwork
If your structure did not resolve cleanly, no web page should pretend to settle it, because the answer lives in your group chart, your authorisations and your contracts. A free 45 minute scoping call will usually narrow it to a confident view, and where certainty matters, our DORA gap analysis opens with a written applicability note covering every entity in the group, so the scope question is answered once, in writing, before any compliance work is priced or planned.
The gap analysis fee is fixed and published, alongside everything else we sell, on the pricing page.
Quick answers
Applicability questions, answered
Does Brexit mean DORA never applies to UK firms?
No. Brexit means DORA is not UK law, so there is no direct obligation on a purely domestic firm. It does not stop the regulation reaching UK firms through their structures and contracts: an EU subsidiary, an EU authorisation used to serve clients, or an ICT contract with an EU financial entity each brings DORA to your door regardless of where head office sits.
Do UK subsidiaries of EU groups have to comply?
Not by virtue of ownership. The obligations sit with the EU entities in the group. In practice, though, the parent's DORA framework usually becomes group policy, and a UK subsidiary that supplies ICT services to its EU parent is treated as an intra-group ICT provider, with contract terms and register entries to match.
We only reach EU clients through intermediaries. Are we caught?
If you have no EU entity and no direct contract with an EU financial entity, you carry no direct DORA obligations. But the regulation travels down chains: the subcontracting rules in force since April 2025 mean that if your service ultimately supports an EU firm's critical or important function, contractual requirements can reach you through the intermediary. The honest answer depends on what your contracts say, which is exactly what an applicability note establishes.
Two minutes wasn't enough?
Settle your DORA scope in one call
Bring your group chart and a list of who you serve in the EU. Forty-five free minutes is usually enough to say which route catches you, or to confirm that none does.