Solutions · FinTech and financial services
DORA gives you four hours. The clock should already be running.
Banks, payment institutions, insurers, crypto-asset service providers and the ICT providers that serve them. DORA's major-incident clock starts at classification, and NIS2 lists banking and financial market infrastructures in Annex I.
Typical profile
- Sector
- Banking
- Employees
- 250 or more
- AI
- Uses AI tools
- Flags
- DORA financial entity
- Banking is an Annex I sector; above the medium-sized ceiling that means an essential entity.
- DORA Article 2 covers the financial entities and their critical ICT providers.
- Credit scoring and fraud models are typical AI Act deployments.
Obligations to prove
75
NIS2 essential entity on this profile.
- Regulation (EU) 2016/679 — data protection3
Applies to every organisation established in the EU that processes personal data.
- Directive (EU) 2022/2555 — cybersecurity8
You declared yourself a NIS2 essential entity.
- Commission Implementing Regulation (EU) 2024/2690 — NIS2 Art 21(2) technical requirements48
The Implementing Regulation's 47 technical requirement sections elaborate NIS2 Art 21(2).
- Regulation (EU) 2024/1689 — artificial intelligence5
You build or use AI systems — Art 4 AI literacy already applies; other tiers depend on classification.
- Regulation (EU) 2022/2554 — digital operational resilience11
You declared yourself a financial entity under DORA Art 2.
- Commission Delegated Regulation (EU) 2025/301 — DORA incident reporting RTS0
The delegated regulation sets the 4-hour major-incident clock.
First statutory clock if something goes wrong: DORA initial notification, 4 hours (DORA Art 19(4)(a); Del. Reg. (EU) 2025/301).
Computed by the platform's scope finder. A starting point, not a legal determination.
The modules that matter here
Start with these 75 obligations.
Sign up, confirm the scope in onboarding, connect your first system.
Start free →