DORA Switzerland: When the EU Regulation Applies to Swiss Companies
Short answer: does DORA apply in Switzerland?
No, not directly. DORA, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, is EU law. It has applied directly in every EU Member State since 17 January 2025 (Art. 64 DORA), not in Switzerland. A company does not become subject to DORA because it is based in Switzerland, nor simply because it has clients in the EU.
DORA reaches Swiss companies in three different ways:
- Directly, where an entity of the group is authorised or registered in the EU as a financial entity, for example an EU subsidiary. EU branches need to be considered separately.
- By contract, where a Swiss company provides ICT services to an EU financial entity. The EU financial entity must then insist on certain contract terms (Art. 30 DORA).
- Not at all, where there is neither an EU entity nor such a service relationship. DORA then does not apply. Swiss supervisory law remains decisive, for supervised institutions in particular FINMA supervisory practice.
ICT third-party service providers that the European Supervisory Authorities have formally designated as critical are a special case. Only they are subject to direct oversight at EU level.
This article was fully revised on 30 September 2026. It reflects the cited sources as at that date and does not replace an assessment of your individual case.
Applicability at a glance: comparison table
What matters is not where the group is headquartered, but which legal entity has which role. DORA applies to 20 categories of financial entities, including credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, managers of alternative investment funds, insurance and reinsurance undertakings and insurance intermediaries (Art. 2(1)(a) to (t) DORA). ICT third-party service providers are listed as a separate category (point (u)) but are not financial entities (Art. 2(2)). Exclusions apply, among others, to insurance intermediaries that are microenterprises or small or medium-sized enterprises, and to certain small managers of alternative investment funds and small insurers (Art. 2(3)).
| Situation | Trigger | Effect of DORA | Supervision and Swiss requirements |
|---|---|---|---|
| Swiss group with a subsidiary authorised in the EU | EU authorisation of the subsidiary as a financial entity | Applies directly to the subsidiary. Does not apply directly to the Swiss parent. If the parent provides ICT services to the subsidiary, it has contractual obligations. | Authority in the subsidiary’s home Member State. FINMA remains responsible for the Swiss entities, and the Swiss requirements continue to apply unchanged. |
| Swiss institution with a branch in the EU | Authorisation of the branch in the host Member State | According to the European Commission, applicable to branches of third-country banks and insurers. Extent depends on the sector and on national law. | Host Member State authority for the branch, FINMA for the institution as a whole. |
| Swiss institution with EU clients but no EU entity | None. EU clients alone are not enough. | Does not apply directly. Whether the cross-border activity is permitted in the target country is a separate market access question. | FINMA. The Swiss requirements apply in full. |
| Purely Swiss institution with no EU link | None | None | FINMA, plus the NCSC and the FDPIC depending on the incident. |
| Swiss ICT provider serving an EU financial entity | Contract for ICT services with an EU financial entity | Contractual obligations under Art. 30(2), and additionally under Art. 30(3) for critical or important functions. No direct EU supervision. | Audit rights of the client and its authority as agreed in the contract. Swiss law depending on the provider’s own activity, for example the FADP. |
| ICT third-party service provider formally designated as critical | Designation by the European Supervisory Authorities (Art. 31) | Direct oversight at EU level. Third-country providers must establish a subsidiary in the EU within 12 months (Art. 31(12)). | EBA, ESMA or EIOPA as Lead Overseer. |
A subsidiary and a branch are not the same thing. An EU subsidiary is a separate legal entity with its own EU authorisation. It is a financial entity in its own right and is therefore directly bound. A branch has no legal personality of its own. The legal entity remains the Swiss institution.
The wording of Art. 2 DORA does not expressly mention branches of third-country undertakings. The European Commission answered the question in the joint Q&A of the European Supervisory Authorities (DORA102, question 3097): DORA applies to EU branches of third-country credit institutions and of third-country insurance and reinsurance undertakings. The Commission bases this on the Capital Requirements Directive 2013/36/EU and on the Solvency II Directive. For third-country insurance intermediaries that access a Member State directly without EU registration, DORA applies only where national law explicitly requires it.
Three limitations should be kept in mind:
- The answer is not legally binding. Only the Court of Justice of the European Union can interpret EU law authoritatively.
- It addresses banks, insurers and insurance intermediaries, not every category of financial entity.
- Practical implementation depends on the authority of the host Member State. The Luxembourg CSSF, for example, amended its circulars on 27 August 2026 and brought third-country branches into the scope of DORA.
Some older articles still repeat a 2024 answer according to which DORA did not apply to such branches. In its Q&A 2023_6876, the EBA notes that this answer was reviewed following the amendment of the Capital Requirements Directive and refers to Q&A DORA102.
EU clients alone do not trigger DORA. DORA attaches to the status of a financial entity under EU sectoral law, not to where clients live. A Swiss institution without an EU entity does not become subject to DORA because it has clients in the EU. Whether it may serve those clients without authorisation in the target country is a matter for local market access law and has to be assessed separately.
Three hypothetical examples
The following cases are invented and simplified. They show the logic of the assessment but do not replace a review of your actual structure.
Example 1 (hypothetical): Swiss group with an EU-authorised financial subsidiary
A Swiss wealth management group holds a subsidiary in an EU Member State that is authorised there as an investment firm. The Swiss parent runs the data centre, identity management and security monitoring for the whole group.
- Trigger: The EU authorisation of the subsidiary as an investment firm (Art. 2(1)(e) DORA), not the fact that it belongs to a Swiss group.
- Type of effect: Direct legal applicability for the subsidiary. The Swiss parent is not itself subject to DORA. Because it provides ICT services to the subsidiary, however, it is an ICT intra-group service provider (Art. 3(20)). The intra-group contract has to cover the content required by Art. 30, and the service belongs in the subsidiary’s register of information (Art. 28(3)). The Swiss supervisory requirements continue to apply to the Swiss entities.
- Decision and implementation: The subsidiary’s management body bears the ultimate responsibility for managing ICT risk (Art. 5(2)). The subsidiary remains fully responsible even where group functions carry out the work (Art. 28(1)(a)). The parent decides on group standards and on the intra-group contracts.
- Documents and evidence: reasoned scoping assessment, ICT risk management framework approved by the subsidiary’s management body, register of information in line with Implementing Regulation (EU) 2024/2956, intra-group service agreement, classification of critical or important functions, procedure for classifying incidents and reporting them to the authority in the home Member State, testing programme, exit strategy for services that support critical or important functions.
- What would change the conclusion: The subsidiary is a small and non-interconnected investment firm to which the simplified framework applies (Art. 16), or it holds a different authorisation and falls under an exclusion (Art. 2(3)). The EU entity is not a subsidiary but a branch. The EU entity holds no authorisation as a financial entity at all, for example as a pure distribution or service company. Or the authority identifies the subsidiary for threat-led penetration testing (Art. 26), in which case systems of the parent may also fall within the scope of the test.
Example 2 (hypothetical): purely Swiss financial institution with no EU link
A smaller Swiss bank has neither a subsidiary nor a branch in the EU. It does not provide ICT services to EU financial entities and is not a subcontractor in such a supply chain.
- Trigger: None for DORA. What counts is the Swiss licence.
- Type of effect: Swiss supervisory law, not DORA. For banks and securities firms, FINMA Circular 2023/1 sets out the requirements for operational risks and resilience, and FINMA Circular 2018/3 those for outsourcing. Cyber attacks of substantial importance must be reported to FINMA (Art. 29 para. 2 FINMASA). Companies subject to the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act must also report certain cyber attacks to the National Cyber Security Centre (NCSC) within 24 hours, unless the Federal Council has exempted them (Art. 74b to 74e ISA). A data security breach that is likely to result in a high risk to the persons concerned must in addition be reported to the FDPIC (Art. 24 FADP).
- Decision and implementation: The board of directors approves the critical functions and their tolerances for disruption, and the executive board implements them (FINMA Circular 2023/1, chapter V). The circular provides relief for banks and securities firms in supervisory categories 4 and 5 (chapter III).
- Documents and evidence: critical functions with tolerances for disruption, documentation of ICT and cyber risk management, inventory of outsourced functions and contracts with inspection and audit rights (FINMA Circular 2018/3, margin nos. 14 and 26 ff.), reporting process for cyber attacks with the 24-hour and 72-hour deadlines, results of the scenario-based cyber exercises (FINMA Circular 2023/1, margin no. 70) and a short file note explaining why DORA does not apply.
- What would change the conclusion: setting up or acquiring an EU subsidiary, opening an EU branch, applying for an EU authorisation, or providing ICT services to an EU financial entity, for example operating a platform for an EU institution. The type of licence also matters: Circular 2023/1 is addressed to banks, securities firms, financial groups and financial conglomerates, not to insurers or portfolio managers. Other rules apply to them.
Example 3 (hypothetical): Swiss ICT provider with an EU financial client
A Swiss software company operates a SaaS solution for client onboarding. One of its clients is a bank authorised in the EU. The company has no establishment in the EU and has not been designated as a critical ICT third-party service provider.
- Trigger: The contract for ICT services with an EU financial entity. ICT services are digital and data services provided through ICT systems on an ongoing basis (Art. 3(21)). Being established in a third country does not change this (Art. 3(24)).
- Type of effect: Contractual. The legal obligation lies with the EU bank: its contracts for ICT services must contain the minimum content set out in Art. 30. For the Swiss provider, the obligations arise from the contract, not from supervision by EU authorities. It has no DORA reporting obligation of its own towards EU authorities. It must, however, assist the client with ICT incidents in such a way that the client can meet its deadlines (Art. 30(2)(f)).
- Decision and implementation: Whether the service supports a critical or important function is assessed by the client (Art. 28(4)(a)), not by the provider. The provider’s management decides which clauses it accepts and on what terms. Legal, information security and operations implement them.
- Documents and evidence: contract addendum that maps Art. 30(2) and, where needed, Art. 30(3), service description with service levels, the countries in which services are provided and data is processed, list of subcontractors with a change procedure, process for assistance with ICT incidents including contact route and response times, contingency plans and test results, audit reports or certificates on information security, arrangements for access, inspection and audit rights, exit and handover plan, and the information the client needs for its register of information.
- What would change the conclusion: The client classifies the function as critical or important, in which case the additional content of Art. 30(3) applies. The European Supervisory Authorities formally designate the provider as critical. The provider is only a subcontractor, in which case the requirements reach it through the contract with the main provider. The client is excluded from DORA (Art. 2(3)), or the service is not an ICT service within the meaning of the Regulation.
One point needs separate clarification for Swiss providers. Contracts for critical or important functions provide for on-site inspections, including by the competent EU authority. Carrying out official acts on Swiss territory on behalf of a foreign state without authorisation is a criminal offence (Art. 271 Swiss Criminal Code). How such inspection rights can be exercised in Switzerland should therefore be reviewed legally before the contract is signed.
ICT providers: ordinary or formally designated as critical?
DORA distinguishes two things that are often confused in practice: how important a function is for the client, and the formal designation of a provider as a critical ICT third-party service provider.
Ordinary ICT third-party service providers are not supervised by the EU. They feel DORA through the contracts of their clients. The minimum content of Art. 30(2) applies to all contracts for ICT services. Where the service supports a critical or important function of the financial entity, the content of Art. 30(3) applies in addition. A function is critical or important if its disruption would materially impair the financial performance of the financial entity, the continuity of its services and activities, or its continuing compliance with the conditions of its authorisation (Art. 3(22)).
| Topic | All ICT contracts (Art. 30(2)) | Additionally for critical or important functions (Art. 30(3)) |
|---|---|---|
| Service | Clear and complete description of the functions and services, including whether and on what conditions subcontracting is permitted for services that support critical or important functions | Full service level descriptions with precise quantitative and qualitative performance targets |
| Locations and data | Countries or regions where services are provided and data is processed, with prior notification of changes, provisions on availability, authenticity, integrity and confidentiality, access to the data and its return in the event of insolvency or termination | No additional content |
| Incidents and reporting | Assistance with ICT incidents at no additional cost or at a cost determined in advance | Notice periods and reporting obligations of the provider, including notification of developments that might have a material impact on its ability to deliver |
| Authorities and audit | Full cooperation with the authorities competent for the financial entity | Unrestricted rights of access, inspection and audit for the financial entity, an appointed third party and the competent authority |
| Continuity and testing | No express requirement | Implement and test contingency plans, adequate ICT security measures, participation in the financial entity’s threat-led penetration testing |
| Termination | Termination rights and minimum notice periods | Exit strategy with a mandatory, adequate transition period |
| Training | Conditions for participating in the financial entity’s security awareness and training programmes | No additional content |
Where the provider subcontracts parts of such a service, Delegated Regulation (EU) 2025/532 specifies what the financial entity must assess and secure by contract when subcontracting is used.
Critical ICT third-party service providers are only those providers that the European Supervisory Authorities EBA, ESMA and EIOPA (together the ESAs) formally designate (Art. 31). The yardstick is the systemic impact of a failure, the importance of the financial entities that rely on the provider, their reliance on it for critical or important functions, and how easily it can be substituted. Delegated Regulation (EU) 2024/1502 specifies these criteria. Supporting a critical function for individual clients does not make a provider a critical ICT third-party service provider.
The ESAs published the first list on 18 November 2025. It comprises 19 providers, mainly internationally active cloud, infrastructure, data and IT services groups. No company headquartered in Switzerland is on it. The list is updated yearly (Art. 31(9)). ICT intra-group service providers are excluded from designation (Art. 31(8)).
A separate oversight framework applies to designated providers:
- One of the three ESAs oversees the provider as Lead Overseer. It can request information, conduct investigations and inspections and issue recommendations (Art. 35(1)). The provider pays oversight fees (Art. 43).
- A critical provider established in a third country must establish a subsidiary in the EU within 12 months of designation. Otherwise financial entities may no longer use its services (Art. 31(12)).
- Inspections in a third country require, among other things, that the provider consents and that the authority of the third country has been informed and has not objected (Art. 36).
- If the provider does not comply with the measures, a periodic penalty payment of up to 1 per cent of its average daily worldwide turnover can be imposed, on a daily basis and for no more than six months (Art. 35(6) to (8)). This is a means of enforcing compliance, not a fine.
DORA obligations and Swiss requirements compared
For entities that are directly subject to DORA, the Regulation groups the obligations into five areas. The table sets them against the most important Swiss rules. It is meant as orientation and says nothing about equivalence: meeting FINMA’s requirements does not automatically mean meeting DORA, and vice versa.
| Area | DORA (EU financial entities) | Switzerland |
|---|---|---|
| Legal nature and addressees | Directly applicable EU regulation with detailed technical standards. 20 categories of financial entities. | FINMA circulars set out supervisory practice in a principles-based way. Circular 2023/1 is addressed to banks, securities firms, financial groups and financial conglomerates. Circular 2018/3 applies to banks, securities firms, insurers, managers of collective assets, fund management companies and self-managed SICAVs. |
| ICT risk management and governance | Art. 5 to 16. The management body bears the ultimate responsibility. Simplified framework for certain small financial entities (Art. 16). | Circular 2023/1: management of ICT and cyber risks, critical data risks and business continuity management. The board of directors approves the critical functions and tolerances for disruption. |
| Incident reporting | Major ICT-related incidents to the competent authority. Initial notification within 4 hours of classification as major and no later than 24 hours after becoming aware. Intermediate report no later than 72 hours after the initial notification. Final report no later than one month after the latest intermediate report (Delegated Regulation (EU) 2025/301, Art. 5). Classification follows Delegated Regulation (EU) 2024/1772. | Cyber attacks of substantial importance to FINMA. Initial report within 24 hours of discovery, full report within 72 hours via the survey and application platform (EHP). The deadlines count on bank working days, except for the severity level “severe” (Guidance 05/2020 and Guidance 03/2024). In addition, a report to the NCSC within 24 hours for companies subject to the reporting obligation (Art. 74e ISA) and, where applicable, to the FDPIC (Art. 24 FADP). |
| Testing | Testing programme for all financial entities other than microenterprises (Art. 24). Threat-led penetration testing (TLPT) at least every three years, but only for financial entities identified by the competent authority (Art. 26, Delegated Regulation (EU) 2025/1190). | Regular vulnerability assessments and penetration tests, and risk-based, scenario-based cyber exercises (Circular 2023/1). FINMA regards red teaming exercises as necessary for systemically important institutions, and at least one tabletop exercise a year for the others (Guidance 03/2024). |
| ICT third parties and outsourcing | Register of information covering all ICT contracts (Art. 28(3)), minimum contract content (Art. 30), exit strategies for critical or important functions (Art. 28(8)). | Inventory of outsourced significant functions, written contract, inspection and audit rights for the institution, its audit firm and FINMA, specific conditions for outsourcing abroad (Circular 2018/3). |
| Information sharing | Voluntary exchange of cyber threat information between financial entities (Art. 45). | No corresponding requirement in the circulars mentioned. Voluntary exchange is possible. |
Three differences matter in practice:
- The DORA deadlines attach to the classification of the incident and to awareness of it. The FINMA deadline starts when the cyber attack is discovered, and for outsourced functions as soon as the third-party provider discovers it.
- DORA also covers major ICT-related incidents where there is no attack, for example a system outage. FINMA’s guidance specifies the reporting duty for cyber attacks. Other events of substantial importance must likewise be reported to FINMA immediately under Art. 29 para. 2 FINMASA.
- Institutions subject to the reporting obligation under the ISA can submit the 24-hour report via the NCSC reporting form and have it forwarded to FINMA. The full 72-hour report is still submitted via the EHP.
Legal obligation or recommended practice? A five-step approach
Not everything that is recommended in connection with DORA is mandatory for every company. The following sequence helps to keep the two apart. Duration and effort depend on the structure, the starting point and the number of contracts and cannot be quantified in general terms.
- Clarify the scope for each legal entity. Record the registered office, authorisation and role of every entity: financial entity in the EU, ICT intra-group service provider, external ICT provider, or none of these.
- Allocate the obligations. Separate statutory obligations, contractual commitments and voluntary standards. Document the result briefly and with reasons.
- Measure gaps against the right benchmark. An EU subsidiary is measured against DORA, a Swiss institution against the Swiss requirements, an ICT provider against its contracts.
- Clean up contracts and registers. Start with the services that support critical or important functions, including intra-group contracts.
- Rehearse reporting lines and tests. Define who classifies an incident, who reports to which authority and how the service provider is involved. Practise the process.
| Situation | Legal obligation | Recommended practice |
|---|---|---|
| EU subsidiary as a financial entity | DORA and the related technical standards, applied in accordance with the proportionality principle (Art. 4) | One methodology across the group, so that subsidiary and parent do not document twice |
| Swiss parent as ICT intra-group service provider | Performance of the intra-group contract, alongside Swiss supervisory law | Align group standards with the subsidiary’s requirements at an early stage |
| Purely Swiss institution | Swiss requirements depending on the licence, plus the ISA and the FADP | DORA can serve as a voluntary reference. There is no obligation to use it. Weigh benefit against effort. |
| Swiss ICT provider | The obligations assumed by contract, plus its own applicable law, for example the FADP | Prepare a contract addendum and an evidence pack once, instead of answering every client request individually |
Limits of this article: It covers the EU Regulation and the Swiss rules at federal level. National specifics of individual EU Member States, the legal position in EEA states such as Liechtenstein and market access law for cross-border services are not covered. Technical standards and supervisory practice are adjusted on an ongoing basis. ISO/IEC 27001 certification or an audit report can provide evidence, but on its own it demonstrates neither compliance with DORA nor compliance with FINMA’s requirements.
Sources and status
All sources were accessed on 30 September 2026. The current official version is authoritative in each case.
European Union
- Regulation (EU) 2022/2554 (DORA), EUR-Lex
- Delegated Regulation (EU) 2024/1772 on the classification of ICT-related incidents, EUR-Lex
- Delegated Regulation (EU) 2025/301 on the content and time limits of incident reports, EUR-Lex
- Implementing Regulation (EU) 2024/2956 on the templates for the register of information, EUR-Lex
- Delegated Regulation (EU) 2025/532 on subcontracting, EUR-Lex
- Delegated Regulation (EU) 2025/1190 on threat-led penetration testing, EUR-Lex
- Delegated Regulation (EU) 2024/1502 on the criteria for designation as critical, EUR-Lex
- ESA announcement of 18 November 2025 with the list of critical ICT third-party service providers, EBA
- Q&A DORA102, question 3097 on third-country branches, answer by the European Commission, EIOPA
- Q&A 2023_6876 with a reference to Q&A DORA102, EBA
- CSSF communiqué of 27 August 2026 on the application of DORA to third-country branches
Switzerland
- FINMA Circular 2023/1 on operational risks and resilience at banks
- FINMA Circular 2018/3 on outsourcing
- FINMA Guidance 05/2020 on the duty to report cyber attacks
- FINMA Guidance 03/2024 with clarifications on the reporting duty and on cyber exercises
- Financial Market Supervision Act (FINMASA, SR 956.1), Fedlex
- Information Security Act (ISA, SR 128), Fedlex, available in German, French and Italian
- Federal Act on Data Protection (FADP, SR 235.1), Fedlex
- Swiss Criminal Code (SCC, SR 311.0), Fedlex
- Information on the reporting obligation, NCSC
- Reporting portal for data security breaches, FDPIC
Which situation applies to your company?
Go through the questions in order. More than one answer can apply at the same time.
- Does an entity of your group hold an EU authorisation or EU registration as a financial entity? Then DORA applies directly to that entity (example 1).
- Does your Swiss institution operate a branch in the EU? Then applicability has to be clarified by sector and host Member State. Do not treat the branch as if it were a subsidiary.
- Do you provide ICT services to an EU financial entity, including within a group or as a subcontractor? Then you face contractual requirements under Art. 30 (example 3).
- Does your client classify the supported function as critical or important? Then the content of Art. 30(3) applies in addition.
- Have the European Supervisory Authorities informed you of a designation as critical? Then the oversight framework under Art. 31 ff. applies.
- Do you only have clients in the EU, but no EU entity and no such services? Then DORA does not apply directly. Assess market access separately.
- None of the above? Then the Swiss requirements apply, depending on your licence (example 2).
SIDD supports Swiss financial institutions and ICT providers with this assessment. In the FINMA/DORA applicability and gap assessment we clarify the scope for each entity and measure the gaps against the relevant benchmark. For ongoing governance we can take on the mandate as external CISO or information security officer. We carry out penetration tests ourselves. We coordinate threat-led penetration testing (TLPT) and advanced red teaming with specialised partners.
Arrange an initial call via the contact form or request a fixed-price quote for the assessment.
