Klavius
DORA · Free tool

Am I in DORA scope?

Five questions, one orientation: whether DORA applies to your entity, whether the simplified framework covers you, and which parts of the Regulation you carry. Built on Articles 2, 3, 4 and 16, and it runs entirely in your browser.

Answer for the entity you are assessing. Nothing you enter leaves this page.

01Which of these is your entity?Art. 2
03Are you a microenterprise: fewer than 10 persons and a turnover or balance sheet of EUR 2 million or less?Art. 3(60)
04Do you use any ICT third-party providers: cloud, software, hosting, data feeds, outsourced IT?Art. 28
05Does any ICT service support a critical or important function?Art. 3(22)

Orientation, not legal advice. The result follows from your answers and the text of DORA; scope is ultimately a question of your authorisation and your facts. Private by design: it runs entirely in your browser, and nothing you enter is sent anywhere.

How this checker works

You say what your entity is, whether it is a microenterprise, whether it uses ICT third-party providers, and whether any of those services supports a critical or important function. The tool reads that against four provisions of DORA: the list of financial entities and the exclusions in Article 2, the definitions in Article 3, the proportionality principle in Article 4 and the simplified framework in Article 16. It returns an orientation, the article that drives it, and the parts of the Regulation that apply to you, with a printable summary.

It is deliberately not a determination. Scope turns on your authorisation and your facts, and the CSSF's and your advisers' reading prevails. What the checker does is stop the two most common mistakes: assuming a registered manager is in, and assuming a small management company gets the simplified framework.

Who DORA applies to

Article 2(1) lists the financial entities DORA applies to, twenty types in all, from credit institutions to crowdfunding providers. Two of them are the entities this site is written for: managers of alternative investment funds, point (k), and management companies of UCITS, point (l). A third, point (u), is not a financial entity but is in the list all the same: ICT third-party service providers, who are reached through their clients' contracts and, if designated critical, through the ESAs' oversight framework. The CSSF, in opening its DORA page, described the Regulation as applicable to no less than twenty types of financial entities from 17 January 2025, investment fund managers among them.

Who is excluded

Article 2(3) takes six categories out. The one that matters to a fund manager is point (a): managers of alternative investment funds as referred to in Article 3(2) of the AIFM Directive, in other words registered managers below the thresholds that have not opted in to full authorisation. The others are small insurance undertakings outside Solvency II, pension institutions with fifteen members or fewer, persons exempted from MiFID II, insurance intermediaries that are microenterprises or SMEs, and post office giro institutions. Article 2(4) lets a Member State also exclude certain institutions listed in the Capital Requirements Directive.

Being excluded from DORA does not switch off the CSSF's own expectations. A registered manager remains subject to the circulars that apply to its status, and it comes into DORA the day it opts in or breaches a threshold.

The simplified framework does not cover fund managers

Article 16 lets a closed list of entities apply a simplified ICT risk management framework: small and non-interconnected investment firms, payment institutions and electronic money institutions exempted under their own directives, certain institutions exempted under the Capital Requirements Directive, and small pension institutions. Managers of alternative investment funds and UCITS management companies are not in that list. A management company with five people is under the full framework, in the same chapters as a bank. What changes with size is the depth of the application, not the set of obligations.

Proportionality and microenterprises

Article 4 is the lever that changes with size. Financial entities implement the ICT risk management rules of Chapter II in accordance with the principle of proportionality, taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations. The application of the incident, testing and third-party chapters is proportionate in the same way, and the competent authority takes that into account when it reviews the framework.

A microenterprise, defined in Article 3(60) as a financial entity with fewer than ten persons and an annual turnover or balance sheet total of EUR 2 million or less, is relieved of a few specific obligations while staying in scope: it need not subject its ICT risk management framework to a regular internal audit, it is not subject to threat-led penetration testing, and its testing programme is lighter. Both conditions have to be met; a small firm with fewer than ten staff and a EUR 3 million balance sheet is not a microenterprise.

What it means in Luxembourg

The CSSF is the competent authority for investment fund managers, and its working definition of that term covers UCITS management companies, other management companies, Luxembourg branches of managers, self-managed investment companies, authorised AIFMs and internally managed AIFs, while registered AIFMs sit outside it. That is the sense in which a self-managed SICAV carries the framework for its own operations. Major ICT incidents are notified to the CSSF through eDesk under the circulars the CSSF published for DORA entities in May 2025, and the register of information is collected each year on a 31 December reference date, with the entity's LEI communicated beforehand.

Frequently asked questions

Is this checker legal advice?

No. It is an orientation built from your answers and the text of DORA Articles 2, 3, 4 and 16. It does not replace a reading of the Regulation, the CSSF's guidance or your advisers' view.

I am a registered, sub-threshold AIFM. Am I really outside DORA?

Article 2(3), point (a), excludes managers referred to in Article 3(2) of the AIFM Directive, that is registered managers below the thresholds that have not opted in. Opting in or breaching the thresholds brings you into scope, and any other authorisation you hold is assessed separately.

My management company is small. Do I get the simplified framework?

No. Article 16 lists the entities that may apply the simplified ICT risk management framework, and AIFMs and UCITS management companies are not among them. The full framework applies, scaled to your size and risk profile under Article 4; a microenterprise is relieved of a few specific obligations.

What is a critical or important function?

Under Article 3(22), a function whose disruption would materially impair the financial performance of the entity, or the soundness or continuity of its services and activities. The assessment is yours to make, and it drives the contract clauses, the exit strategy and the testing scope.

Where do my answers go?

Nowhere. The checker runs entirely in your browser and makes no network call; no analytics event carries your answers.

Sources

Where Klavius fits

Once the answer is yes, the work is the framework itself: the ICT risk record, the incident clock, the third-party register and its contract clauses, the exit strategies. Klavius starts from the register of information you already filed and populates those sections as one connected record, with officers reviewing and signing off. See how Klavius handles DORA, check a contract with the clause checker, and a provider's code with the LEI checker.

See how Klavius handles DORA → ← All tools