DORA for Payment & E-Money Institutions
Payment institutions and electronic money institutionsare within DORA's scope under Article 2. Given how ICT-dependent payments are, DORA's incident-reporting and resilience-testing pillars are especially material. DORA has applied since 17 January 2025.
Payments are ICT-critical by nature
For payment and e-money firms, availability and integrity of ICT systemsis the service. That makes the incident-reporting and resilience-testing pillars the sharpest edges of DORA compliance.
Interaction with PSD2 reporting
DORA harmonises major-ICT-incident reporting that previously overlapped with PSD2 operational and security incident reporting, reducing duplicate channels for in-scope events.
Third-party concentration
Payment firms often depend heavily on a few processors and cloud providers, so the register of information and concentration-risk analysis deserve early attention.
Fintechs and payment firms specifically
Many payment and e-money institutions are also fintechs still building out a compliance function. See our incident-reporting guide for fintechs for a practical readiness checklist tailored to how these firms typically operate.
Smaller payment and e-money firms: check the Article 16 exemption
Not every payment or e-money institution has to build the full Article 5-15 regime. Article 16's simplified ICT risk management framework applies to payment institutions exempted under Article 32(1) of PSD2 and electronic money institutions exempted under Article 9(1) of the E-Money Directive, typically the smallest firms operating under national waiver regimes. The simplified framework still requires a documented ICT risk approach, monitoring of systems, a business-continuity plan, and a record of third-party dependencies; it scales down the depth of testing and review frequency rather than removing the obligation. Firms that are unsure whether their national waiver status carries over to the DORA exemption should confirm with their competent authority before assuming the simplified track applies.
Frequently asked questions
Are e-money institutions covered by DORA?
Yes. Both payment institutions and electronic money institutions are listed financial entities under Article 2.
How does DORA affect PSD2 incident reporting?
DORA provides a harmonised major-ICT-incident reporting regime that streamlines the overlap with PSD2 operational and security incident reporting.
What should a payment institution prioritise?
Incident detection and classification, a tested continuity plan, and a complete register of ICT third-party arrangements.
Do all payment institutions have to meet the full DORA framework?
No. Payment institutions exempted under Article 32(1) of PSD2 and electronic money institutions exempted under Article 9(1) of the E-Money Directive qualify for DORA's Article 16 simplified ICT risk management framework instead of the full Article 5-15 regime.