NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
DORA for Payment Institutions: Scope and TLPT
Learn

DORA for Payment Institutions: Scope and TLPT

·Alexander Sverdlov

DORA applies to payment institutions, including those exempted under the second Payment Services Directive, to account information service providers, and to electronic money institutions, including exempted ones, under points (b), (c) and (d) of Article 2(1) of Regulation (EU) 2022/2554. It has applied since 17 January 2025. None of the Article 2(3) exclusions touches payment firms, so there is no size floor: a small authorised payment institution is in scope. What size changes is the version of the rules. Exempted payment institutions and exempted e-money institutions get the simplified ICT risk management framework in Article 16. Authorised ones run the full framework in Articles 5 to 15, scaled by the Article 4 proportionality principle, with lighter treatment on specific duties only if they are microenterprises.

The second change is in PSD2 itself. Directive (EU) 2022/2556 switched off the PSD2 major incident reporting paragraphs for these firms, and DORA Article 23 extends its incident reporting chapter to operational or security payment-related incidents, whether ICT-related or not. For a payment institution, every major incident now runs on the DORA clock. This guide takes each piece in turn: scope, the lighter regimes, PSD2, incidents, testing and third parties. The general picture is in our guide to DORA requirements.

EntityIn DORA scope?Which frameworkWhere it says so
Authorised payment institutionsYesFull, Articles 5 to 15, proportionateArt. 2(1)(b), Art. 4
Payment institutions exempted under PSD2 Article 32(1)YesSimplifiedArt. 2(1)(b), Art. 16(1)
Account information service providersYesFull, Articles 5 to 15, proportionateArt. 2(1)(c)
Authorised electronic money institutionsYesFull, Articles 5 to 15, proportionateArt. 2(1)(d)
E-money institutions with an Article 9(1) EMD2 waiverYesSimplifiedArt. 2(1)(d), Art. 16(1)
Who DORA reaches in payments: Article 2(1)(b) payment institutions, 2(1)(c) account information service providers, 2(1)(d) e-money institutions, the Article 16(1) simplified framework for exempted firms, Article 23 payment-related incidents and the PSD2 competent authority under Article 46(b)

Which payment firms does DORA cover?

Article 2(1) lists twenty types of financial entity. Point (b) is payment institutions, including payment institutions exempted pursuant to Directive (EU) 2015/2366; point (c) is account information service providers; point (d) is electronic money institutions, including those exempted pursuant to Directive 2009/110/EC. The definitions in Article 3 point back to the payments directives: a payment institution as defined in Article 4(4) of PSD2, an exempted payment institution under Article 32(1) of PSD2, an account information service provider under Article 33(1) of PSD2, and an exempted electronic money institution under Article 9(1) of the second E-Money Directive.

Article 2(3) then excludes six groups: certain alternative investment fund managers, the small insurers outside Solvency II, occupational pension schemes with no more than 15 members, persons exempted under MiFID II, insurance intermediaries that are micro, small or medium-sized enterprises, and post office giro institutions. None of them is a payment firm. Article 46(b) names the supervisor: for payment institutions, electronic money institutions and account information service providers, including the exempted ones, it is the competent authority designated under Article 22 of PSD2.

Do small and exempted payment institutions get a lighter regime?

Two kinds of relief exist, and they are easy to confuse. The first is Article 16. Its first paragraph disapplies Articles 5 to 15 for small and non-interconnected investment firms, payment institutions exempted pursuant to PSD2, certain exempted credit institutions, electronic money institutions exempted pursuant to the E-Money Directive, and small occupational pension schemes. Those firms run a simplified ICT risk management framework instead. An authorised payment or e-money institution is not on that list, however small, and neither is an account information service provider.

The second is the microenterprise carve-out. Article 3(60) defines a microenterprise as a financial entity that employs fewer than 10 persons and has an annual turnover and/or annual balance sheet total that does not exceed EUR 2 million. A number of duties are written for financial entities other than microenterprises. For example, Article 6(5) lets a microenterprise review its ICT risk management framework periodically rather than yearly, Article 25(3) lets it combine a risk-based approach with strategic planning of its testing, Article 26(1) keeps it out of threat-led penetration testing, and Article 28(2) does not ask it, or an Article 16 entity, for a strategy on ICT third-party risk. The rest of Articles 5 to 15 still applies. Reading the Regulation without either carve-out overstates the work for a small firm; reading it as if every small firm were on Article 16 understates it.

What did DORA change in PSD2?

Directive (EU) 2022/2556 was adopted alongside DORA to align the sectoral directives, and Member States had to apply it from 17 January 2025. Its Article 7 amends PSD2 in four places that matter to a payment firm. The authorisation file under Article 5(1) now refers to DORA for the arrangements on the use of ICT services, the incident monitoring and handling procedure, and ICT business continuity. Article 19(6) now names ICT systems among the important operational functions whose outsourcing must not materially impair internal control. Article 95(1), the operational and security risk duty, now applies without prejudice to Chapter II of DORA. And a new Article 96(7) requires Member States to ensure that paragraphs 1 to 5 of Article 96, the PSD2 major incident reporting rules, do not apply to credit institutions, e-money institutions, payment institutions, account information service providers, exempted payment institutions and waived e-money institutions.

DORA fills the gap from the other side. Article 3(9) defines an operational or security payment-related incident as one, whether ICT-related or not, that has an adverse impact on the availability, authenticity, integrity or confidentiality of payment-related data, or on the payment-related services provided, and Article 23 applies the whole incident reporting chapter to those incidents and to major ones where they concern credit institutions, payment institutions, account information service providers and electronic money institutions. Recital 33 of Directive 2022/2556 gives the intent: a single, fully harmonised incident reporting mechanism, irrespective of whether the incidents are ICT-related. There is no longer a separate PSD2 track for a payment firm to run.

Venvera incident record for a data centre cooling failure with discovery details, impact and scope fields, response metrics and a classification engine that shows which frameworks, including DORA and NIS2, the incident triggers

How fast must a payment institution report a major incident?

Article 19 requires major incidents to be reported to the competent authority, and Article 5 of Delegated Regulation (EU) 2025/301 sets the time limits: the initial notification within four hours of classifying the incident as major and no later than 24 hours from becoming aware of it; the intermediate report within 72 hours of the initial notification; and the final report no later than one month after the latest intermediate report. Where an incident is classified as major after the first 24 hours, Article 5(2) asks for the initial notification within four hours of classification.

Article 5(4) lets an entity submit by noon of the next working day where a deadline falls on a weekend day or a bank holiday. Article 5(5) withholds that relief, for the initial notification and the intermediate report, from credit institutions, central counterparties, operators of trading venues and entities identified as essential or important under NIS2. Payment institutions and e-money institutions are not named, and payment services are not a sector in either annex of the NIS2 Directive. Article 5(6) lets a competent authority withdraw the relief anyway from an entity it considers significant or systemic. Check whether yours has. The classification thresholds are in our guide to DORA major incident classification.

The DORA major incident clock for payment institutions under Delegated Regulation 2025/301: become aware, classify as major, initial notification within 4 hours of classification and no later than 24 hours from awareness, intermediate report within 72 hours, final report within one month

Which payment firms must run threat-led penetration testing?

Article 26(1) requires financial entities identified by their competent authority to carry out threat-led penetration testing at least every three years. It excludes the Article 16(1) entities and microenterprises from the start, so an exempted payment institution never falls under it. Delegated Regulation (EU) 2025/1190 sets how the TLPT authority identifies the rest, and Article 2(2) contains a default for payment firms.

A payment institution is required to perform TLPT where it exceeded EUR 150 billion of total value of payment transactions, as defined in Article 4(5) of PSD2, in each of the two calendar years preceding the assessment. An electronic money institution is required to where, in each of those two years, it exceeded either EUR 150 billion of total value of payment transactions or EUR 40 billion of outstanding electronic money. The requirement falls away where the authority's assessment of impact, financial stability and ICT risk profile under Article 2(1) does not justify a test, and the same assessment lets the authority identify a firm below the thresholds.

When a payment firm must run DORA threat-led penetration testing under Delegated Regulation 2025/1190: above EUR 150 billion of payment transactions, or for e-money institutions above EUR 40 billion of outstanding e-money, in both preceding calendar years, with at least one test every three years

Below those lines, the Article 24 testing programme still applies to every in-scope firm other than a microenterprise: at least yearly, appropriate tests of all ICT systems and applications supporting critical or important functions. How the three-year cycle runs is in our guide to DORA threat-led penetration testing.

What does DORA ask about processors, cloud and other ICT providers?

Article 28(3) requires a register of information on all contractual arrangements for ICT services, kept at entity level and at sub-consolidated and consolidated levels. Article 28(8) requires exit strategies for ICT services supporting critical or important functions, and Article 30 sets the minimum contract terms. Payment firms tend to be built on other people's technology, so the register is rarely short: the payment platform run as a service, cloud hosting, fraud screening and identity verification, card issuing and processing services, and the ICT services embedded in agent and distributor arrangements. Deciding which of those support a critical or important function is the judgement a supervisor will look at first. The filing format is in our guide to the DORA register of information.

Venvera DORA register of information under Article 28(3) showing ICT providers, contractual arrangements, business functions and risk assessments, pre-export validation warnings and xBRL-CSV export

What the other results get wrong

Page one for this query is mostly general DORA explainers from vendors and consultancies, and three points are easy to get wrong. The first is the dates. One guide says DORA came into force on 27 December 2022; another says 17 January 2023. It was published in the Official Journal on 27 December 2022, entered into force on the twentieth day after, 16 January 2023, and has applied since 17 January 2025.

The second is the fine. One guide aimed at banks and fintechs warns of fines of up to 1% of daily turnover for every day of non-compliance. That is Article 35(8), the periodic penalty payment the Lead Overseer can impose on a critical ICT third-party service provider, calculated on the provider's average daily worldwide turnover. It does not apply to a payment institution. For financial entities, Article 50 leaves administrative penalties and remedial measures to Member States.

The third is what is missing. The payment-specific DORA guide we found covers TLPT without the EUR 150 billion and EUR 40 billion defaults in Delegated Regulation 2025/1190, which are the first thing a growing payment or e-money institution needs to check itself against.

An illustrative DORA readiness view for a payment firm: ICT contracts in the register, payment incidents routed to the DORA reporting path, critical systems tested this year, and exit plans for critical providers

Where does your firm stand?

Fill this in per legal entity. A blank cell is the next piece of work.

QuestionYour answerWhy it matters
Is the entity authorised, exempted under PSD2 Article 32(1), or waived under EMD2 Article 9(1)?Decides between Articles 5 to 15 and Article 16.
Does it employ fewer than 10 persons with turnover or balance sheet up to EUR 2 million?The Art. 3(60) microenterprise carve-outs.
When did the management body last approve the ICT risk management framework?Art. 5(2) and Art. 6(5).
Does the incident procedure route non-ICT payment incidents to the DORA path?Art. 3(9) and Art. 23; PSD2 Art. 96(7).
Who classifies an incident as major out of hours, and has your authority removed weekend relief?Delegated Regulation 2025/301, Art. 5(4) to (6).
Is every platform, processing and screening service in the register?Art. 28(3), at entity and consolidated level.
What were your payment transactions and outstanding e-money in each of the last two years?The TLPT defaults in 2025/1190, Art. 2(2).

If most of the column is empty, start with scope and then the incident procedure. Our guide to what DORA compliance costs puts a budget line against each item, the free compliance check gives you a baseline, and the DORA framework page shows how the register, the incident clocks and testing are tracked as controls with owners and evidence.

The bottom line on DORA for payment institutions: every major incident now runs on the DORA clock, ICT or not

Frequently asked questions

Does DORA apply to payment institutions?

Yes. Payment institutions, including those exempted under PSD2, are financial entities under Article 2(1)(b), and DORA has applied to them since 17 January 2025. No Article 2(3) exclusion reaches them.

Does DORA apply to e-money institutions and account information service providers?

Yes. E-money institutions, including exempted ones, are covered by Article 2(1)(d), and account information service providers by Article 2(1)(c).

Do payment institutions still report major incidents under PSD2?

No. Article 96(7) of PSD2, inserted by Directive (EU) 2022/2556, disapplies the PSD2 major incident reporting paragraphs for them, and DORA Article 23 covers operational or security payment-related incidents whether ICT-related or not.

Is there a simplified DORA regime for small payment institutions?

Only for exempted ones. Article 16(1) covers payment institutions exempted under PSD2 and e-money institutions exempted under the E-Money Directive. An authorised firm runs Articles 5 to 15, with specific carve-outs if it is a microenterprise under Article 3(60).

Does NIS2 apply to payment institutions?

Payment services are not listed in Annex I or Annex II of the NIS2 Directive. For financial entities that are identified under NIS2, DORA is the sector-specific act. Our guide to DORA versus NIS2 sets out the split.

Primary sources

Scope, definitions and duties are taken from Articles 2 to 6, 16, 19, 23 to 26, 28, 30, 35, 46, 50 and 64 of Regulation (EU) 2022/2554; the PSD2 amendments from Article 7 and recital 33 of Directive (EU) 2022/2556 and the amended text of Directive (EU) 2015/2366; the reporting time limits from Article 5 of Delegated Regulation (EU) 2025/301; the TLPT criteria from Article 2 of Delegated Regulation (EU) 2025/1190; and the NIS2 sector lists from Annexes I and II of Directive (EU) 2022/2555. Confirm the current text before relying on a specific provision.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING