DORA for Insurance Intermediaries, 18 Months On: Why Almost No Agent or Broker Is Really Obliged
Insurance e finance Consulting

DORA for Insurance Intermediaries, 18 Months On: Why Almost No Agent or Broker Is Really Obliged

Eighteen months after it became applicable, the European regulation on digital resilience excludes micro and small enterprises: of the more than 30,000 agents and brokers listed on the RUI, only a few dozen are subject to it. Who has to comply, and why it concerns you anyway.

A126 Team 6 min read

The rule everyone is talking about that almost no intermediary has to apply

For eighteen months now, precisely since 17 January 2025, DORA — the Digital Operational Resilience Act, the European regulation governing the digital operational resilience of the financial sector — has been fully applicable. It is much discussed, often in alarmed tones, and many agents and brokers have received the message that this is the "new cyber obligation" that concerns them directly. The reality, checked against the text of the regulation and IVASS guidance, is more nuanced and in some respects surprising: for the vast majority of Italian insurance intermediaries, DORA does not apply at all.

This is not a loophole or a convenient interpretation: it is written into the regulation. And understanding why that is the case — and what it nonetheless entails, indirectly, for those formally excluded — is more useful than any generic summary of the rule. Because the right question for an intermediary is not "what do I have to do for DORA," but "does DORA concern me or not, and in what way."

What DORA requires, in brief

DORA was created for a concrete reason: the financial sector is now critically dependent on technology and IT providers, and an incident affecting a supplier can paralyse a bank or an insurer. The regulation therefore requires the entities subject to it to oversee four areas. ICT risk governance, with clear responsibilities resting with senior management. Incident management and reporting, with tight deadlines for notifying the authorities. Resilience testing, up to advanced penetration tests for the largest entities. And above all third-party risk management: contracts, registers, control of the ICT supply chain. These are solid principles and, for the most part, simple organisational common sense elevated to a legal obligation.

The point is who these obligations are addressed to. And it is here that the framework, for intermediaries, changes radically.

Who is really obliged: the question of the threshold

The regulation explicitly names intermediaries: Article 2 includes "insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries." If one stopped there, the conclusion would be that DORA applies to everyone. But the same article, a little further on, introduces a decisive exclusion: the regulation does not apply to intermediaries that are microenterprises or small and medium-sized enterprises. The recital accompanying the rule justifies this by explicitly referring to "the specific features of the structure of the insurance intermediation market."

Translated into numbers, an intermediary falls within DORA's obligations only if it simultaneously exceeds the thresholds of a medium-sized enterprise: at least 250 employees and an annual turnover above 50 million euros (or a balance sheet above 43 million). This is the official reading given by IVASS, which on its page dedicated to DORA specifies that the intermediaries subject to the regulation are those "that are not microenterprises or small or medium-sized enterprises." And there is no simplified regime for small players: they are simply outside the scope.

One need only look at the snapshot of the market to grasp the reach of this exclusion. According to the IVASS Annual Report, as at 31 December 2025 the Single Register of Intermediaries counted 228,925 registrants, of which 25,121 agents (section A) and 5,821 brokers (section B). The vast majority are individuals or small companies, a very long way from the 250-employee threshold. The entities actually obliged number in the order of a few dozen: the large corporate brokers of international scale. For the small-town agent and the provincial broker, DORA is a rule that speaks about someone else.

What has happened in eighteen months, for those who are obliged

For the insurers and the large intermediaries that are subject to it, however, these eighteen months have been ones of concrete work, and observing them helps to understand what compliance really entails. The first heavy task was the register of information on ICT providers: a complete mapping of technology contracts, which IVASS required to be submitted for the first time by 11 April 2025 and then updated by 31 March 2026. It is no trivial exercise: in the dry-run conducted at European level in 2024, out of more than a thousand entities, only 6.5% passed all the quality checks foreseen on the register. A figure that shows how difficult it is, even for structured organisations, to have their own chain of suppliers under control.

Then there is incident reporting, with strict timing: initial notification within 24 hours, intermediate report within 72 hours, final report within one month. The first aggregate data describe a real but still contained phenomenon on the cyber front: at European level the authorities recorded around 3,383 major incidents in 2025, of which, however, only a tenth were strictly cyber in nature; in the Italian insurance segment IVASS received around ten reports, most of them originating from third-party providers. It is practical confirmation of the reason why DORA insists so much on the supply chain: risk, increasingly often, comes in through the suppliers' door.

On the supervisory front, in November 2025 the European authorities designated the first nineteen critical ICT providers — the big names in cloud and IT services, from Amazon Web Services to Microsoft, from Google to IBM — which come under direct oversight. IVASS, for its part, has launched its first checks on the large intermediaries and a survey of the insurance market. As for penalties, the point deserves clarity because a good deal of confusion circulates on this: eighteen months after application, no DORA penalty appears to have been imposed, either on intermediaries or on other financial entities, in Italy or in Europe. The penalty framework exists and is severe — the Italian transposing legislation provides for fines of up to 10% of turnover for legal persons — but so far it is supervision that has moved, not the sanctioning hand. Anyone reporting that "the first fines have already arrived" is anticipating something that, to date, has not yet happened.

Why DORA concerns even the small players anyway

It would be a mistake, however, for the small intermediary to file DORA away as someone else's problem. Formal exclusion from the obligations does not mean immunity from the effects, for two very concrete reasons.

The first is the contractual chain. The mandating insurers and the large players subject to DORA have to oversee their own ICT providers and partners, and this requirement propagates downstream: whoever interfaces digitally with an insurer — exchanging data, connecting to its systems, managing customer information on its behalf — may find themselves contractually required to meet standards of security, continuity and incident management that stem precisely from DORA. In practice, the obligation that does not come from the law can come from the contract with the mandating insurer.

The second is that exclusion from DORA does not cancel out the other obligations. An intermediary, even a small one, handles particularly sensitive personal data and remains fully subject to the GDPR and to the organisational safeguards required by sector-specific rules. As we saw when discussing the NIS 2 Directive and insurance intermediaries, the financial sector has in DORA its special rule on digital resilience; the point we add here is the decisive one, and often overlooked: that special rule, for intermediaries, applies only above a precise size threshold. Below that threshold there is no security vacuum — there are other rules and, above all, a cyber risk that does not look at the number of employees before striking.

The practical point, then, is not "I have to comply with DORA," but "is my level of IT security equal to the data I handle and to what my mandating insurers will ask of me?" And it is a question that applies to the three-person agency exactly as it does to the three-hundred-person broker.

In summary

DORA is an important and well-constructed rule, but its application to insurance intermediaries is far narrower than it is portrayed: the vast majority of Italian agents and brokers, as micro and small enterprises, are excluded by the regulation's explicit provision. Those obliged are a few dozen large corporate intermediaries, which over eighteen months have worked on supplier registers, incident reporting and controls, while penalties so far remain on paper. For everyone else, DORA is not a direct obligation but a signal: digital security will arrive anyway, contractually through the mandating insurers and by way of the concrete risk to customer data.

At A126 we help insurance intermediaries understand where they stand in relation to these obligations and secure their digital tools in a way that is proportionate to their real size, without alarmism and without underestimation. If you want to gain clarity on your agency's position with respect to DORA and data security, get in touch for a free consultation.

A126 Corporate Advisors — technology and security tailored to those who work in insurance intermediation.

Share this article