DORA's Simplified ICT Risk Framework: A Guide for Small and Non-Interconnected Investment Firms
DORA's Article 16 lets small and non-interconnected investment firms, certain exempted payment, e-money and credit institutions, and small occupational pension schemes swap the full ICT risk management chapter (Articles 5 to 15) for a simplified framework. It is not a DORA exemption. Firms still need a documented ICT risk framework built to the detailed controls of RTS 2024/1774, still report major incidents, and, as the ESAs confirmed, still maintain the register of information in full. This guide works through the most common misconceptions.
First, a scope note for UK readers
DORA (Regulation (EU) 2022/2554) applies from 17 January 2025 to financial entities in the EU. It is not UK law. What follows is relevant to EU-authorised firms, for instance a small investment firm a UK wealth manager or broker operates in an EU Member State. The DORA knowledge base holds EU texts and ESAs material only, so it cannot tell you what applies to your UK-regulated business, and this article does not try to.
Misconception 1: "Small firms are out of DORA"
Not so. DORA has two distinct small-firm concepts, and neither takes a firm out of scope:
- Article 16(1) entities (the subject of this guide): small and non-interconnected investment firms meeting Article 12(1) of Regulation (EU) 2019/2033; payment institutions exempted under Directive (EU) 2015/2366; institutions exempted under Directive 2013/36/EU where the Member State has not excluded them under DORA Article 2(4); exempted e-money institutions; and small IORPs, meaning fewer than 100 scheme members in total.
- Microenterprises (Article 3(60)): financial entities, other than trading venues, CCPs, trade repositories and CSDs, with fewer than 10 staff and annual turnover and/or balance sheet not exceeding EUR 2 million. They keep the full framework but benefit from specific lighter rules, for example on testing in Articles 24 and 25.
Only a narrow set of entities is wholly outside DORA under Article 2(3), such as IORPs operating schemes with no more than 15 members in total. Note that the conditions for being "small and non-interconnected" are in Regulation (EU) 2019/2033, which is not in this base: check them at source.
Misconception 2: "Simplified means informal"
The second subparagraph of Article 16(1) requires a sound and documented ICT risk management framework, continuous monitoring of all ICT systems, prompt detection of anomalies, identification of key dependencies on ICT providers, business continuity plans with at least back-up and restoration measures, regular testing, and lessons-learned and training. Article 16(2) requires periodic review, review after major incidents, and a review report to the competent authority on request.
RTS 2024/1774 then specifies all of this in Title III (Articles 28 to 41). The level of detail surprises many small firms:
Selected simplified-framework requirements (RTS 2024/1774)
| Article | What it requires |
|---|---|
| 28 (Governance) | Management body owns the framework, sets roles and information security objectives, approves asset classification and continuity plans, and reviews the resilience budget at least once a year; independent internal audit of the framework |
| 30 (Classification) | Identify and document all critical or important functions, the information and ICT assets supporting them, their interdependencies, and those supported by ICT third-party providers |
| 31 (Risk management) | Risk tolerance, documented periodic risk assessment, mitigation strategies, continuous threat and vulnerability monitoring, alert thresholds for incident response |
| 33 (Access control) | Least privilege; logged privileged access; strong authentication for remote access, privileged access and publicly available assets supporting critical or important functions |
| 34 (Operations security) | Asset lifecycle, automated vulnerability scanning and patching, legacy assets, logging, anomaly detection |
| 35 (Data and network security) | Data in use, in transit and at rest; secure deletion and disposal; teleworking and private devices |
| 39-40 (Business continuity) | Management-approved plans, including a cyber-attack scenario; back-up and restore testing at least once every year or on every major plan change |
| 41 (Review report) | Searchable electronic format; findings, self-assessment of weaknesses, remediation measures and dates |
Misconception 3: "We don't need a register of information"
This is the point the ESAs have settled explicitly. In Q&A 2025_7388, published on 8 August 2025, a submitter argued that because Article 28 refers to the ICT risk management framework, Article 16 firms might be exempt from it. The joint answer was clear: Article 28(3) "establishes the obligation to maintain and update a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers with no exception", and all financial entities subject to DORA must keep one.
Proportionality is in the register, not around it
The ESAs add that smaller firms typically use fewer ICT services, so their register is naturally smaller. A small EU firm that relies on its UK parent for IT should record that parent company as an intra-group ICT service provider.
Misconception 4: "Incident reporting is for the big players"
The Article 16 exemption covers Articles 5 to 15 only. The incident chapter (Articles 17 to 19) is untouched, so a simplified-framework firm must still classify ICT-related incidents and report major ones within the deadlines of RTS 2025/301. Two genuine reliefs exist:
- the recurring-incident rule in Article 8(2) of RTS 2024/1772 (repeated incidents with the same root cause treated as one major incident) does not apply to Article 16(1) entities;
- Article 26(1) DORA excludes them from threat-led penetration testing (TLPT).
Misconception 5: "Third-party rules don't reach us"
Article 28(2) does exempt Article 16(1) firms (and microenterprises) from adopting a formal strategy on ICT third-party risk, and the ESAs cite Recital 43 as relieving them of a dedicated role to monitor ICT provider arrangements. But the contractual requirements of Article 30 contain no such carve-out, and Article 16(1)(e) itself requires firms to identify key dependencies on ICT providers. RTS 2024/1774, Article 30(2), adds that they must identify all critical or important functions supported by ICT third-party providers.
One useful flexibility: under Article 28(3) of the RTS, the firm may outsource the verification of compliance with ICT risk management requirements to an intra-group or third-party ICT provider, in line with Union and national sectoral law, while remaining fully responsible for it.
The review report: what supervisors can ask for
Article 16(2) DORA requires a report on the review of the framework to be submitted to the competent authority on request. Article 41 of RTS 2024/1774 fixes its format (searchable electronic) and its content, which in practice doubles as a self-assessment template:
- an introduction describing the firm's services, organisation, critical functions, dependence on in-house and outsourced ICT, and an executive summary of current and near-term ICT risk and security posture;
- where applicable, the date the management body approved the report;
- the reasons for the review, including evidence of supervisory instructions or, after incidents, the list of ICT-related incidents with their root-cause analysis;
- the review period, and the person responsible for the review;
- findings with a self-assessment of the severity of weaknesses and gaps, remedial measures with expected dates (including follow-up of earlier findings), and overall conclusions.
A short compliance checklist
- Record why the firm falls within Article 16(1).
- Approve, at management-body level, the asset classification and business continuity plans.
- Document the information security policy and the Article 33 to 35 controls.
- Maintain the register of information, including group ICT providers.
- Test back-up and restore at least annually and report deficiencies to the management body.
- Keep a review report ready in searchable electronic format.
- Rehearse classifying and reporting a major incident.
For a quick check of any of these points, ask the DORA knowledge base: for example, "We use the simplified ICT risk management framework under Article 16. Do we still have to keep a register of our ICT third-party contracts?"
Sourced answers on DORA's simplified framework
Search DORA, RTS 2024/1774 and the ESAs' Q&A in plain English. Every answer cites the article it relies on.
This guide explains the rules; it is not legal advice. Official sources: DORA on EUR-Lex and RTS 2024/1774 on EUR-Lex.
Frequently asked questions
What is the DORA simplified ICT risk management framework?
It is the regime in Article 16 of DORA for certain smaller entities, which replaces Articles 5 to 15 with lighter requirements set out in Article 16(1), second subparagraph, and detailed in Title III of RTS 2024/1774.
Who qualifies under DORA Article 16(1)?
Small and non-interconnected investment firms, payment institutions exempted under Directive (EU) 2015/2366, institutions exempted under Directive 2013/36/EU (where not excluded under Article 2(4)), exempted e-money institutions, and small IORPs.
Is a microenterprise the same as an Article 16 entity?
No. A microenterprise (Article 3(60)) has fewer than 10 staff and turnover and/or balance sheet not exceeding EUR 2 million; it keeps the full framework with specific lighter rules. Article 16 entities are a separate list.
Does the register of information apply to Article 16 firms?
Yes. ESAs Q&A 2025_7388 says Article 28(3) applies with no exception.
Does DORA apply to UK investment firms?
DORA is EU law and not part of UK law. It applies to financial entities within its Article 2(1), such as EU-authorised investment firms, including those owned by UK groups.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.