Insurtech companies — startups and scale-ups using technology to provide insurance products or services — fall under DORA if they hold EU insurance or reinsurance authorisation, or if they provide ICT services to regulated insurers. The compliance picture depends on your business model: are you the regulated entity, or the technology provider, or both?
Which Insurtechs Are DORA Entities
DORA applies to:
Insurance and reinsurance undertakings — companies holding EIOPA-supervised authorisation under Solvency II. If you are the authorised insurer (not just the technology), DORA applies directly to you.
Insurance intermediaries above threshold — insurance brokers, agents, and intermediaries above the size threshold (more than 250 employees for most categories — microenterprises are exempt from most DORA requirements).
Occupational pension funds — IORPs (Institutions for Occupational Retirement Provision) above the member state's defined threshold.
The technology-only insurtech: If you provide technology infrastructure, underwriting algorithms, or operational systems to a regulated insurer but are not yourself authorised as an insurer, you are an ICT third-party service provider. DORA's third-party requirements reach you through your regulated customer's obligations.
Insurtechs as DORA Entities: The Authorised Path
If your insurtech holds insurance or reinsurance authorisation (e.g., Lloyd's market participants, EU-licensed P&C insurers, digital-first health insurers), DORA applies to you as a financial entity.
Proportionality: DORA applies proportionality principles. Microenterprises (under 10 employees, under €2 million annual balance sheet) have simplified requirements. Small insurers may qualify for lighter-touch obligations. The national supervisor determines what "proportionate" means for your entity type.
Solvency II intersection: Solvency II already imposes operational risk and IT risk requirements on insurers. Many DORA requirements overlap with Solvency II's existing IT governance expectations. Companies compliant with Solvency II are well-positioned for DORA — the primary additions are the detailed third-party risk management requirements and the structured incident reporting framework.
What DORA Adds for Authorised Insurtechs
Beyond Solvency II operational risk requirements, DORA specifically adds:
Register of Information: A formal register of all ICT third-party arrangements — including cloud infrastructure, claims processing platforms, distribution technology, and telematics providers.
DORA-specific incident classification and reporting: The 4-hour initial notification obligation. Solvency II has incident reporting, but DORA's timeframes are stricter.
Resilience testing programme: Systematic testing beyond what Solvency II's Own Risk and Solvency Assessment (ORSA) typically requires.
Article 30 contract provisions: Ensuring all critical ICT provider contracts include DORA-specified minimum provisions.
Insurtechs as ICT Third-Party Providers
For insurtechs providing technology to regulated insurers (without holding insurance authorisation):
Your regulated insurance customers will treat you as an ICT third-party provider under DORA. Expect:
Risk assessment: Your insurance customers will assess whether your service is critical to their operations.
Security questionnaires: Aligned to DORA Article 21 requirements (or ISO 27001 equivalent).
Contract amendments: Demanding DORA Article 30 minimum provisions:
- Data location disclosure
- Audit rights
- Incident notification within their 4-hour notification window
- BCP provisions
- Exit assistance
Special focus for insurtech services: Claims processing platforms, underwriting AI systems, fraud detection, and reinsurance analytics are likely to be classified as critical by major insurers. These services get the highest level of due diligence.
Technology Considerations for DORA Compliance in Insurtech
Claims processing resilience: Claims platforms are critical functions. RTOs of a few hours are standard expectations. Architecture should support multi-region failover.
Underwriting algorithm availability: Underwriting systems that are unavailable prevent policy issuance. Business continuity plans must address algorithm unavailability.
Telematics and IoT data: Insurtech companies relying on IoT/telematics data have additional supply chain considerations — the telematics hardware manufacturers and data aggregators are part of the ICT third-party risk picture.
AI model risk: Underwriting and pricing AI models present a specific DORA risk — if the model produces incorrect outputs due to data quality issues or adversarial inputs, the operational and financial consequences can be material. Document model risk alongside ICT operational risk.
EIOPA Oversight
For DORA in insurance, EIOPA is the European Supervisory Authority. EIOPA published implementing technical standards (ITS) for the Register of Information and other DORA reporting requirements. Use EIOPA-specific templates for insurance entities rather than EBA templates (which are for banking).
National insurance supervisors (BaFin for insurance in Germany, FCA for UK insurers, etc.) implement DORA at entity level.