{"id":44069,"date":"2026-08-07T15:37:58","date_gmt":"2026-08-07T13:37:58","guid":{"rendered":"https:\/\/smartfense.com\/?p=44069"},"modified":"2026-08-07T15:38:04","modified_gmt":"2026-08-07T13:38:04","slug":"who-does-dora-apply-to","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/","title":{"rendered":"Who does DORA apply to, and why no one will notify you"},"content":{"rendered":"<p>Regulation (EU) 2022\/2554, better known as DORA, was published on 27 December 2022 and has applied since 17 January 2025. What did not arrive with it was a list of addressees.<\/p>\n<p>The Spanish securities regulator CNMV states this plainly in its <a href=\"https:\/\/www.cnmv.es\/DocPortal\/Ciberseguridad\/FAQ_DORA.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">frequently asked questions on the DORA Regulation<\/a>. Asked whether any official register exists that would let a firm look up the entities within scope, the answer is no: it is each financial entity\u2019s own responsibility to determine whether DORA applies to it and to be proactive about compliance, rather than waiting for the authority to confirm that it is covered.<\/p>\n<p>That turns a task usually treated as a preliminary formality into the first real obligation. This piece does not walk through the five pillars of the regulation or cover digital operational resilience testing. It deals with who DORA applies to, who falls outside, and why the obligation ends up reaching technology providers that are not financial entities at all.<\/p>\n<h2>Who does DORA apply to?<\/h2>\n<p>DORA is the European regulation that sets common digital operational resilience requirements for the financial sector. Article 2 lists the categories of financial entities within its scope, and the list is long.<\/p>\n<p>It takes in credit institutions, payment institutions and electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, management companies and alternative investment fund managers, insurance and reinsurance undertakings, insurance intermediaries, occupational pension funds, data reporting service providers and crowdfunding service providers.<\/p>\n<p>The geographic test is just as broad. The regulation covers financial entities offering services in the European Union, and branches remain covered as an integral part of the entity. Their systems fold into the parent\u2019s risk management framework, and their staff have to know the applicable security policies and take part in the corresponding training plans.<\/p>\n<p>Supervision, by contrast, is not centralised. It follows the existing split by entity type, so the authority that can ask you about DORA is the one that already supervises you. In Spain that means the Banco de Espa\u00f1a for credit institutions and payment and e-money institutions, the CNMV for investment firms, crypto-asset service providers, market infrastructures, management companies and data reporting or crowdfunding service providers, and the DGSFP for insurance and occupational pension funds. Third-party providers designated as critical sit under an additional European layer, the oversight framework of Articles 31 to 44.<\/p>\n<h2>Who falls outside the scope?<\/h2>\n<p>There are express exclusions, and they are worth reading closely because they are narrow.<\/p>\n<p>Article 2(3)(a) leaves out the alternative investment fund managers referred to in Article 3(2) of Directive 2011\/61\/EU, provided the portfolios they manage do not exceed EUR 100 million in total, or EUR 500 million where those portfolios consist exclusively of unleveraged funds with no redemption rights exercisable for at least five years from initial investment. Those entities can still adopt the framework voluntarily, which is a reasonable call if they expect growth that would push them past the thresholds.<\/p>\n<p>Beyond cases like that, size is not an exit. Some entities, such as small and non-interconnected investment firms and microenterprises, fall under the simplified ICT risk management framework of Article 16, and Article 4 introduces the proportionality principle. Neither of those is an exemption. Proportionality scales the intensity of the measures to the risk profile and the complexity of the operations, not the list of articles that have to be met. For a sense of scale, the regulation treats a financial entity as a microenterprise when it employs fewer than ten people and its annual turnover or annual balance sheet total does not exceed EUR 2 million.<\/p>\n<h2>Why your ICT provider is inside the perimeter too<\/h2>\n<p>This is the stretch of the perimeter that gets miscalculated most often. DORA defines ICT services deliberately broadly, as digital and data services provided through ICT systems to one or more users on an ongoing basis. Under that definition almost any platform a financial entity uses in daily operations enters the conversation, and the obligation reaches providers at three different intensities.<\/p>\n<ul>\n<li><strong>ICT third-party service provider.<\/strong> Takes on obligations indirectly, so that the financial entity does not fall out of compliance, through specific clauses flowing from Article 30(2), plus data such as the LEI or EUID code the entity needs to maintain its register of information on contractual arrangements.<\/li>\n<li><strong>Provider supporting critical or important functions.<\/strong> Faces a stricter set of contractual terms, those of Article 30(3), and has to align with the entity\u2019s outsourcing and subcontracting policy.<\/li>\n<li><strong>Critical third-party provider.<\/strong> Once the European Supervisory Authorities designate it as critical under Article 31, DORA applies directly and the provider comes under the oversight framework of Articles 31 to 44.<\/li>\n<\/ul>\n<p>Two details widen the circle further. Intragroup providers count as third-party providers, including those wholly owned by entities in the same group, with the same requirements applying. And the subcontracting chain is in scope, because the subcontractor has to grant the financial entity and the authorities the same contractual access and inspection rights as the main provider.<\/p>\n<p>In practice, a technology company that is not a financial entity can meet DORA requirements across a negotiating table rather than in an official journal. It is the same shift towards the supply chain we looked at when analysing <a href=\"https:\/\/smartfense.com\/en\/blog\/nis2-security-awareness-compliance-deep-dive\/\">the awareness requirements of the NIS2 Directive<\/a>.<\/p>\n<h2>What DORA asks of people once it applies to you<\/h2>\n<p>With scope settled, the obligation on staff shows up by name. Article 13(6) requires financial entities to develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes.<\/p>\n<p>Three details in that paragraph change how a programme is designed. It applies to all employees and to senior management. It has to carry a level of complexity commensurate to the remit of each function, which rules out a single course for the whole workforce. And where appropriate, entities also include ICT third-party service providers in their relevant training schemes, so the training crosses the same boundary drawn above.<\/p>\n<p>Senior management is not exempt either. The management body holds ultimate responsibility for the ICT risk management framework and needs sufficient knowledge, skills and experience in technology risk and digital resilience, along with keeping that knowledge current. In financial services this direction is already visible under other frameworks, as I noted when reviewing <a href=\"https:\/\/smartfense.com\/en\/blog\/ai-financial-sector-human-factor-bafin\/\">the human factor in financial supervisors\u2019 expectations<\/a>. How a programme like this is structured by audience is set out on the <a href=\"https:\/\/smartfense.com\/en\/compliance\/dora\/\">DORA compliance page<\/a>.<\/p>\n<h2>How do you prove it to the competent authority?<\/h2>\n<p>You prove it with records, and with records that speak in terms of functions. One point that surprises people arriving from another framework is that certification does not settle the matter: an ISO 27001 certification, or an equivalent one, attests to a set of standard cybersecurity practices that are not tailored to DORA obligations, and supervisors expect a gap analysis to establish how well the entity actually measures up. The same applies to providers, whose certification can form part of due diligence without replacing it. The difference between evidencing training and evidencing behaviour is something I covered when breaking down <a href=\"https:\/\/smartfense.com\/en\/blog\/iso-27001-2022-control-6-3-awareness\/\">control 6.3 of ISO 27001:2022<\/a>.<\/p>\n<p>On the people layer, the evidence that underpins compliance usually rests on these elements:<\/p>\n<ul>\n<li>A record of who received awareness and training, when, and on what, covering the whole workforce and the branches.<\/li>\n<li>Content differentiated by function, at a level of complexity you can justify against the remit of each role.<\/li>\n<li>Documented, sustained training for the management body, not a one-off session.<\/li>\n<li>Coverage of the ICT third-party service providers included in training schemes where appropriate.<\/li>\n<li>Enough traceability to feed the report on the review of the risk management framework that a competent authority may request.<\/li>\n<\/ul>\n<p>On top of that comes a reporting obligation worth putting on the calendar. Entities maintain a register of information on all contractual arrangements for the use of ICT services, one that separates those supporting critical or important functions from those that do not. Authorities require it annually so it can be forwarded to the European Supervisory Authorities for the designation of critical providers. The problem that shows up in any audit reappears here, and it was worked through in <a href=\"https:\/\/smartfense.com\/en\/blog\/audit-questions-your-spreadsheet-cant-answer\/\">the audit questions a spreadsheet cannot answer<\/a>.<\/p>\n<p>SMARTFENSE, as a security awareness platform operating across Europe and Latin America, is built so that trail exists without anyone rebuilding it by hand. Every awareness action, every assessment and every simulation is recorded and segmented by group and by function, which is the unit DORA frames the requirement in. The rest of the regulatory map we cover sits on the <a href=\"https:\/\/smartfense.com\/en\/compliance\/\">compliance page<\/a>.<\/p>\n<p>Determining scope is the first decision the entity makes about DORA on its own responsibility, and the one it will later have to justify. That calculation rarely stops at your own org chart, because it runs on through the chain of providers holding up each critical function. When the supervisor\u2019s question arrives, what will count is what you can prove inside the line you drew.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.<\/p>\n","protected":false},"author":31,"featured_media":44066,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[1362,456,2063,448],"class_list":["post-44069","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-cumplimiento-normativo-en","tag-cyber-security","tag-riesgo-humano","tag-security-awareness"],"acf":[],"yoast_head":" \n<title>Who does DORA apply to? Scope and ICT providers<\/title>\n<meta name=\"description\" content=\"DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Who does DORA apply to? Scope and ICT providers\" \/>\n<meta property=\"og:description\" content=\"DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-07T13:37:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-07T13:38:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-27.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Andrea Sona\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Andrea Sona\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/\"},\"author\":{\"name\":\"Andrea Sona\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/3d5d7dc2e569f5c1af2daef92f35de00\"},\"headline\":\"Who does DORA apply to, and why no one will notify you\",\"datePublished\":\"2026-08-07T13:37:58+00:00\",\"dateModified\":\"2026-08-07T13:38:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/\"},\"wordCount\":1485,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-27.jpg\",\"keywords\":[\"Cumplimiento Normativo\",\"cyber security\",\"riesgo humano\",\"security awareness\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/\",\"name\":\"Who does DORA apply to? Scope and ICT providers\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-27.jpg\",\"datePublished\":\"2026-08-07T13:37:58+00:00\",\"dateModified\":\"2026-08-07T13:38:04+00:00\",\"description\":\"DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-27.jpg\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-27.jpg\",\"width\":1376,\"height\":768,\"caption\":\"Vista a\u00e9rea de una plaza empresarial donde una franja pintada en el pavimento delimita un recinto que encierra la torre principal y tambi\u00e9n varias construcciones peque\u00f1as de los alrededores que parec\u00edan quedar afuera\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/who-does-dora-apply-to\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Who does DORA apply to, and why no one will notify you\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/3d5d7dc2e569f5c1af2daef92f35de00\",\"name\":\"Andrea Sona\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/andrea-sona-avatar-150x150.png\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/andrea-sona-avatar-150x150.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/andrea-sona-avatar-150x150.png\",\"caption\":\"Andrea Sona\"},\"description\":\"Da anni nel settore informatico, Analista Informatica di professione, negli ultimi anni specializzata in cybersecurity awareness e formazione digitale, attualmente collaborando in SMARTFENSE. Con esperienza nel supportare aziende e organizzazioni nella diffusione della cultura della sicurezza informatica. Appassionata di innovazione e comunicazione tecnologica, contribuisce attivamente al dibattito sulla sicurezza digitale attraverso contenuti divulgativi.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/andrea-sona-58238b83\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/andrea-sona\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"Who does DORA apply to? Scope and ICT providers","description":"DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/","og_locale":"en_US","og_type":"article","og_title":"Who does DORA apply to? Scope and ICT providers","og_description":"DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.","og_url":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/","og_site_name":"SMARTFENSE","article_published_time":"2026-08-07T13:37:58+00:00","article_modified_time":"2026-08-07T13:38:04+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-27.jpg","type":"image\/jpeg"}],"author":"Andrea Sona","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Andrea Sona","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/"},"author":{"name":"Andrea Sona","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/3d5d7dc2e569f5c1af2daef92f35de00"},"headline":"Who does DORA apply to, and why no one will notify you","datePublished":"2026-08-07T13:37:58+00:00","dateModified":"2026-08-07T13:38:04+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/"},"wordCount":1485,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-27.jpg","keywords":["Cumplimiento Normativo","cyber security","riesgo humano","security awareness"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/","url":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/","name":"Who does DORA apply to? Scope and ICT providers","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-27.jpg","datePublished":"2026-08-07T13:37:58+00:00","dateModified":"2026-08-07T13:38:04+00:00","description":"DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-27.jpg","contentUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-27.jpg","width":1376,"height":768,"caption":"Vista a\u00e9rea de una plaza empresarial donde una franja pintada en el pavimento delimita un recinto que encierra la torre principal y tambi\u00e9n varias construcciones peque\u00f1as de los alrededores que parec\u00edan quedar afuera"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/who-does-dora-apply-to\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"Who does DORA apply to, and why no one will notify you"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/3d5d7dc2e569f5c1af2daef92f35de00","name":"Andrea Sona","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/file\/2026\/05\/andrea-sona-avatar-150x150.png","url":"https:\/\/smartfense.com\/file\/2026\/05\/andrea-sona-avatar-150x150.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/05\/andrea-sona-avatar-150x150.png","caption":"Andrea Sona"},"description":"Da anni nel settore informatico, Analista Informatica di professione, negli ultimi anni specializzata in cybersecurity awareness e formazione digitale, attualmente collaborando in SMARTFENSE. Con esperienza nel supportare aziende e organizzazioni nella diffusione della cultura della sicurezza informatica. Appassionata di innovazione e comunicazione tecnologica, contribuisce attivamente al dibattito sulla sicurezza digitale attraverso contenuti divulgativi.","sameAs":["https:\/\/www.linkedin.com\/in\/andrea-sona-58238b83\/"],"url":"https:\/\/smartfense.com\/en\/author\/andrea-sona\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/44069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=44069"}],"version-history":[{"count":2,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/44069\/revisions"}],"predecessor-version":[{"id":44095,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/44069\/revisions\/44095"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/44066"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=44069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=44069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=44069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}