Skip to main content
DORA Auditor

DORA for Payment & E-Money Institutions

Last updated: 2 authoritative sourcesDORA Auditor Editorial Team

Payment institutions and electronic money institutionsare within DORA's scope under Article 2. Given how ICT-dependent payments are, DORA's incident-reporting and resilience-testing pillars are especially material. DORA has applied since 17 January 2025.

Payments are ICT-critical by nature

For payment and e-money firms, availability and integrity of ICT systemsis the service. That makes the incident-reporting and resilience-testing pillars the sharpest edges of DORA compliance.

Interaction with PSD2 reporting

DORA harmonises major-ICT-incident reporting that previously overlapped with PSD2 operational and security incident reporting, reducing duplicate channels for in-scope events.

Third-party concentration

Payment firms often depend heavily on a few processors and cloud providers, so the register of information and concentration-risk analysis deserve early attention.

Fintechs and payment firms specifically

Many payment and e-money institutions are also fintechs still building out a compliance function. See our incident-reporting guide for fintechs for a practical readiness checklist tailored to how these firms typically operate.

Smaller payment and e-money firms: check the Article 16 exemption

Not every payment or e-money institution has to build the full Article 5-15 regime. Article 16's simplified ICT risk management framework applies to payment institutions exempted under Article 32(1) of PSD2 and electronic money institutions exempted under Article 9(1) of the E-Money Directive, typically the smallest firms operating under national waiver regimes. The simplified framework still requires a documented ICT risk approach, monitoring of systems, a business-continuity plan, and a record of third-party dependencies; it scales down the depth of testing and review frequency rather than removing the obligation. Firms that are unsure whether their national waiver status carries over to the DORA exemption should confirm with their competent authority before assuming the simplified track applies.

Frequently asked questions

Are e-money institutions covered by DORA?
How does DORA affect PSD2 incident reporting?
What should a payment institution prioritise?
Do all payment institutions have to meet the full DORA framework?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  2. European Banking Authority, DORA