DORA applies to insurance and reinsurance undertakings, to insurance, reinsurance and ancillary insurance intermediaries, and to institutions for occupational retirement provision, under points (n), (o) and (p) of Article 2(1) of Regulation (EU) 2022/2554. It has applied since 17 January 2025. Two exclusions decide who actually carries it. Small insurers that fall outside Solvency II under its Article 4 are outside DORA too, and every intermediary that is a micro, small or medium-sized enterprise is excluded, so only large intermediaries are caught. Insurers get no simplified framework: Article 16 does not list them, so an in-scope insurer runs the full ICT risk management framework in Articles 5 to 15, scaled by the Article 4 proportionality principle.
The second change is inside Solvency II itself. Directive (EU) 2022/2556 rewrote Article 41(4) of Solvency II so that insurers must set up and manage network and information systems in accordance with DORA, and it removed ICT risk management from the governance delegated acts under Article 50(1). For ICT, the Solvency II system of governance now points to DORA. This guide takes each piece in turn: scope, governance, incidents, testing and third parties. The general picture is in our guide to DORA requirements.
| Entity | In DORA scope? | Where it says so |
|---|---|---|
| Insurance and reinsurance undertakings | Yes, unless excluded from Solvency II by its Article 4. | Art. 2(1)(n), Art. 2(3)(b) |
| Insurance, reinsurance and ancillary intermediaries | Only if not a micro, small or medium-sized enterprise. | Art. 2(1)(o), Art. 2(3)(e) |
| Institutions for occupational retirement provision | Yes, unless the schemes together have no more than 15 members. | Art. 2(1)(p), Art. 2(3)(c) |
| Small IORPs | In scope, on the simplified framework. | Art. 16(1) |
| Insurers and reinsurers | No simplified framework; proportionality applies. | Art. 4, Art. 16(1) |
Which insurers are outside DORA?
Article 2(3)(b) excludes insurance and reinsurance undertakings as referred to in Article 4 of Directive 2009/138/EC. That is the Solvency II size exclusion, and it is narrow. An insurance undertaking qualifies only if it meets all of the Article 4(1) conditions at once: annual gross written premium income not above EUR 5 million, technical provisions not above EUR 25 million, group technical provisions not above EUR 25 million where it belongs to a group, no liability, credit or suretyship business unless it is an ancillary risk, and reinsurance operations within set limits. Under Article 4(2), exceeding any of those amounts for three consecutive years brings Solvency II into application from the fourth year.
The thresholds are about to move. Directive (EU) 2025/2, the Solvency II review, replaces points (a) to (c) of Article 4(1) with EUR 15 million of gross written premium and EUR 50 million of technical provisions, and Member States apply the new rules from 30 January 2027. DORA refers to Article 4 rather than repeating its figures, so the boundary of DORA's insurance scope follows that article. If your undertaking sits between the old and new thresholds, confirm with your supervisor how and when the change reaches your status under national law before you plan around it.
Are insurance brokers and agents covered?
Article 2(1)(o) brings insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries into scope, and Article 2(3)(e) takes out every one of them that is a microenterprise or a small or medium-sized enterprise. Recital 39 gives the reason: the Regulation acknowledges the specificities of the insurance intermediation market structure. The size categories are DORA's own, set in Article 3. A medium-sized enterprise is one that is not small and employs fewer than 250 persons, with an annual turnover not above EUR 50 million and/or an annual balance sheet not above EUR 43 million. An intermediary is therefore in scope only above that line, which leaves the large brokers and the large distribution arms of banks and retailers.
Excluded does not mean untouched. An insurer that relies on a broker's systems for a critical or important function still has to manage that dependency as ICT third-party risk under its own Article 28 obligations, whatever the broker's own status.
What did DORA change in Solvency II?
Directive (EU) 2022/2556 was adopted alongside DORA to align the sectoral directives, and Member States had to apply it from 17 January 2025. Its Article 2 makes two changes to Solvency II. Article 41(4) now reads that insurance and reinsurance undertakings shall take reasonable steps to ensure continuity and regularity in the performance of their activities, including the development of contingency plans, and shall in particular set up and manage network and information systems in accordance with Regulation (EU) 2022/2554. And Article 50(1)(a) and (b), which empower the Commission to specify the system of governance and the key functions, now exclude the elements concerning ICT risk management.
The practical effect is that the Solvency II governance file and the DORA file meet at the management body. DORA Article 5(2) makes the management body responsible for the ICT risk management framework, the digital operational resilience strategy, the ICT business continuity policy and the budget for resilience, and Article 6(4) asks for ICT risk oversight by a control function with appropriate independence and segregation along three lines of defence or an equivalent model. Those sit next to the risk management, compliance, internal audit and actuarial functions an insurer already runs under Solvency II. Our guide to Solvency II governance requirements covers the Pillar 2 side.

How fast must an insurer report a major ICT incident?
The same clocks apply to insurers as to every other financial entity. Article 19 requires major ICT-related incidents to be reported to the competent authority, which for insurers and reinsurers is the authority designated under Article 30 of Solvency II and for intermediaries the authority designated under Article 12 of the Insurance Distribution Directive, per Article 46(k) and (l). Article 5 of Delegated Regulation (EU) 2025/301 sets the time limits: the initial notification as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from becoming aware of it; the intermediate report within 72 hours of the initial notification; and the final report no later than one month after the latest intermediate report.
One detail differs for many insurers. Article 5(4) lets an entity submit by noon of the next working day where a deadline falls on a weekend day or a bank holiday. Article 5(5) withholds that relief, for the initial notification and the intermediate report, from credit institutions, central counterparties, operators of trading venues and entities identified as essential or important under NIS2. Insurance is not a sector in either annex of the NIS2 Directive, so an insurer is not caught by that exclusion as such. Article 5(6) lets a competent authority withdraw the relief anyway from an entity it considers significant or systemic, by a decision notified to it. Check whether you have received one. The classification thresholds are in our guide to DORA major incident classification.
Which insurers must run threat-led penetration testing?
Article 26(1) requires the financial entities identified by their competent authority to carry out threat-led penetration testing at least every three years, on live production systems supporting several or all critical or important functions. Delegated Regulation (EU) 2025/1190 sets how the TLPT authority identifies them, and Article 2(2)(g) is written for insurers. It works in two stages.
First, the authority identifies a subset of insurance and reinsurance undertakings that meet all of three criteria: gross written premium above EUR 1.5 billion, technical provisions above EUR 10 billion, and, for undertakings pursuing life activities or both life and non-life, total assets above 3.5% of the total assets of the insurers and reinsurers established in the Member State. Second, an undertaking in that subset must perform TLPT where it also meets any one of: gross written premium above EUR 3 billion, technical provisions above EUR 30 billion, or total assets above 10% of that national total. The requirement falls away where the authority's assessment of impact, financial stability and ICT risk profile under Article 2(1) does not justify a test, and Article 2(1) also lets the authority identify an insurer outside those thresholds on the same assessment.
Below those lines, the Article 24 testing programme still applies to every in-scope insurer other than a microenterprise: at least yearly, appropriate tests of all ICT systems and applications supporting critical or important functions. How the three-year cycle runs is in our guide to DORA threat-led penetration testing.
What does DORA ask about ICT providers, brokers and outsourced claims?
Article 28(3) requires a register of information on all contractual arrangements for ICT services, kept at entity level and at sub-consolidated and consolidated levels, which for an insurance group means the solo undertakings and the group. Article 28(8) requires exit strategies for ICT services supporting critical or important functions, and Article 30 sets the minimum contract terms. For an insurer, the arrangements that take the longest to capture are rarely the cloud contracts. They are the policy administration platforms run by a software house, the claims handling and document services, and the ICT services embedded in managing general agent and bancassurance arrangements, where the question of who provides the ICT service is buried in a distribution contract. The filing format is in our guide to the DORA register of information.

What the other results get wrong
The page one results for this query are good on the five pillars, and three points are easy to miss. The first is who is excluded. One guide updated in September 2026 says insurers have full DORA scope unless they qualify as a microenterprise, and that only microenterprises and small ancillary distributors among intermediaries are excluded. The text is different on both counts. The insurer exclusion is the Solvency II Article 4 test, not the microenterprise definition, and Article 2(3)(e) excludes every intermediary that is micro, small or medium-sized, of any kind.
The second is the simplified framework. The same guide describes a simplified ICT risk framework for small insurers and intermediaries under Article 4. Article 4 is the proportionality principle. The simplified framework is Article 16, and its list does not include insurers, reinsurers or intermediaries; the only insurance-adjacent entities on it are small IORPs.
The third is TLPT. That guide puts designation at roughly EUR 20 billion of gross written premium. Delegated Regulation (EU) 2025/1190 uses EUR 1.5 billion and EUR 3 billion of premium, with the technical provisions and total assets tests alongside, so a large national insurer well below EUR 20 billion can still be in scope.
Where does your undertaking stand?
Fill this in per legal entity, not per group. A blank cell is the next piece of work.
| Question | Your answer | Why it matters |
|---|---|---|
| Does any entity in the group meet every Solvency II Article 4(1) condition? | Only those are outside DORA under Art. 2(3)(b). | |
| Which intermediaries in the group exceed DORA's medium-sized ceilings? | Only those are in scope under Art. 2(3)(e). | |
| When did the management body last approve the ICT risk tolerance and resilience strategy? | DORA Art. 5(2), now referenced by Solvency II Art. 41(4). | |
| Who classifies an incident as major out of hours, and has your authority removed weekend relief? | Delegated Regulation 2025/301, Art. 5(4) to (6). | |
| Is every policy administration, claims and distribution ICT service in the register? | Art. 28(3), at entity and consolidated level. | |
| Where are your gross written premium and technical provisions against EUR 1.5 and 10 billion? | The first TLPT filter in 2025/1190, Art. 2(2)(g). |
If most of the column is empty, start with scope and then the register. Our guide to what DORA compliance costs puts a budget line against each item, the free compliance check gives you a baseline, and the DORA framework page shows how the register, incident clocks and testing are tracked alongside the Solvency II system of governance.
Frequently asked questions
Does DORA apply to insurance companies?
Yes. Insurance and reinsurance undertakings are financial entities under Article 2(1)(n), and DORA has applied to them since 17 January 2025. Only undertakings excluded from Solvency II by its Article 4 are outside.
Does DORA apply to insurance brokers?
Only large ones. Article 2(3)(e) excludes insurance, reinsurance and ancillary insurance intermediaries that are micro, small or medium-sized enterprises as defined in DORA Article 3.
Does NIS2 apply to insurers?
Insurance is not listed in Annex I or Annex II of the NIS2 Directive. For financial entities that are identified under NIS2, DORA Article 1(2) makes DORA the sector-specific act. Our guide to DORA versus NIS2 sets out the split.
Is there a simplified DORA regime for small insurers?
No. Article 16 lists small and non-interconnected investment firms, certain exempted payment, e-money and credit institutions, and small IORPs. Insurers apply Articles 5 to 15 in full, scaled by the proportionality principle in Article 4.
Who supervises an insurer's DORA compliance?
The competent authority designated under Article 30 of Solvency II, per DORA Article 46(k). For intermediaries, it is the authority designated under Article 12 of the Insurance Distribution Directive, per Article 46(l).
Primary sources
Scope, exclusions and duties are taken from Articles 1 to 5, 16, 19, 24, 26, 28, 30, 46 and 64 and recital 39 of Regulation (EU) 2022/2554; the Solvency II amendments from Article 2 of Directive (EU) 2022/2556; the size exclusion from Article 4 of Directive 2009/138/EC and its amendment by Directive (EU) 2025/2; the reporting time limits from Article 5 of Delegated Regulation (EU) 2025/301; the TLPT criteria from Article 2 of Delegated Regulation (EU) 2025/1190; and the NIS2 sector lists from Annexes I and II of Directive (EU) 2022/2555. National transposition of the Solvency II review may differ in timing. Confirm the current text before relying on a specific provision.




