Essential and important entities
Also known as: Systemically important financial institutions (SIFIs), Critical ICT entities, DORA-classified entities
These are financial institutions classified under the Digital Operational Resilience Act (DORA) based on their systemic importance to the European Union's financial stability. Essential entities face the highest level of regulatory oversight due to their critical role in infrastructure, while important entities have a significant impact but may be subject to different reporting requirements. This classification determines the rigor and frequency of ICT risk management audits and supervisory reviews.
In practice
An auditor verifies the entity's formal classification to determine which specific DORA compliance mandates apply, such as the requirement for advanced threat-led penetration testing (TLPT). The practitioner will check if the controls implemented align with the heightened oversight expectations mandated for that specific tier of importance.