Skip to content

Guide

DORA for SaaS vendors serving EU financial firms

Reviewed 2026-08-07

Short answer

DORA is addressed to EU financial entities, not most of their technology suppliers. For the normal SaaS vendor, it arrives through mandatory customer contract terms and vendor-risk processes. A small number of ICT providers formally designated as critical are different: that designation creates direct EU oversight and cannot be inferred from customer size or reputation.

See the full 9-step checklist below.

Why this matters

Who should care
ICT and technology suppliers to EU banks, insurers, funds and payment firms.
Typical trigger
An EU financial-sector customer's own DORA third-party risk obligations reaching your contract.
What buyers may ask for
prescribed contract termsincident notification commitmentsexit and continuity provisions

Where this fits

  1. 01

    EU financial entity

    A bank, insurer, fund or payment firm subject to DORA's ICT risk-management rules.

  2. 02

    Your company

    Acts as an ICT third-party provider under contract with that financial entity.

  3. 03

    Contract terms

    DORA requires specific clauses to flow down: incident notification, exit rights, audit access.

Who this is relevant to

This guide is for SaaS, infrastructure, fintech and regtech vendors selling into EU banks, insurers, payment institutions, investment firms, trading venues and similar regulated customers.

The relevant question is where the customer sits in the EU financial regulatory perimeter, not where your own company is headquartered.

  • Vendors already on an EU financial customer's supplier panel
  • Teams receiving a DORA-labelled due-diligence questionnaire
  • Products supporting payments, clearing, trading, insurance or core banking workflows
  • Vendors whose service or subcontractors are being recorded in a customer's ICT-risk register

How DORA reaches a vendor that is not an EU financial firm

DORA addresses financial entities directly and requires them to manage ICT risk, including the risk introduced by their suppliers.

A SaaS vendor normally encounters that obligation through the contract its EU financial customer must put in place. The customer remains accountable to its regulator for supplier risk.

A narrower route exists for providers formally designated as critical ICT third-party providers by the European Supervisory Authorities. That is a formal status, not something a vendor can infer from its customer base.

Direct application vs customer flow-down

For most vendors, DORA is a flow-down obligation rather than a direct one. The practical work is to agree workable contract terms, evidence the operational resilience behind them, and give the customer the facts it needs for its own register and risk assessment.

  • Direct: a formally designated critical ICT third-party provider is subject to direct EU oversight
  • Customer-driven: the normal vendor relationship carries mandatory contract clauses and evidence requests
  • The financial customer classifies the service against its own operations; the vendor should not guess

What an EU financial customer will ask you to produce

The questionnaire usually arrives looking like a standard vendor security review with a handful of DORA-specific additions layered on top.

  • Confirmation you accept the mandatory ICT third-party contract terms: exit rights, audit and access rights, service level detail, subcontracting notification
  • A description of your service precise enough for your customer to record it correctly in their register of information
  • Your position on subcontracting: who you rely on, where, and how you notify changes
  • Business continuity and disaster recovery evidence, including test results, not just a plan
  • Incident detection and notification timelines you can commit to contractually
  • Confirmation of audit and access rights the customer's regulator expects them to hold over material suppliers
  • An exit and termination plan describing how the customer's data and workloads leave your service without unacceptable disruption
  • Where relevant, evidence that any subcontractor you rely on for a material part of the service accepts equivalent terms

Common misconceptions

“DORA does not apply to us because we are not a financial institution.”
Correct as a matter of direct legal application for almost everyone reading this. But your EU financial customer's obligation to manage you as an ICT risk is real, contractual, and enforced through the contract regardless of your own regulatory status.
“We can decide for ourselves whether we support a critical or important function.”
That classification is made by the financial entity, based on their own operations and regulatory exposure, not by you. If a customer has not told you the classification, the honest answer is that you do not know it. Do not guess in a security questionnaire.
“One customer's DORA terms will do for all our EU financial customers.”
Contract terms vary by customer and by how critical the function is judged to be. Treat each EU financial relationship as its own review, even where the paperwork looks similar.
“Being a large or well-known vendor means we are a critical ICT third-party provider.”
Designation is a formal EU regulatory act, not a reputational judgement. Very few providers hold it. Assume you do not unless you have been formally told otherwise.
“Our SOC 2 report already covers this.”
A SOC 2 report is useful evidence but does not itself satisfy the specific contractual terms DORA requires: audit rights, exit planning, subcontracting notification and register data are additional, not substitutable.

Practical checklist

  1. 01Identify which of your customers are EU financial entities, including EU branches or subsidiaries of Asian groups
  2. 02Ask directly whether your service has been classified as supporting a critical or important function. Do not assume either answer
  3. 03Review your standard contract for exit rights, audit and access rights, and subcontracting notification, and be ready to accept stronger versions for EU financial customers
  4. 04Maintain a current subcontracting map for the service you provide to each EU financial customer
  5. 05Test your business continuity and disaster recovery plan, and keep the test evidence, not just the document
  6. 06Define incident detection and notification timelines you can actually meet before you commit to them contractually
  7. 07Prepare a written exit and data-portability plan for the service, not just a data export feature
  8. 08Nominate someone who can answer a customer's register-of-information questions about your service without a lengthy internal chase
  9. 09Confirm your key subcontractors are willing to accept flow-down terms if a customer asks for that assurance

Questions to settle before an EU financial deal

Start with the customer relationship: identify which customers are EU financial entities, whether the service supports a critical or important function, and what service and subcontractor information the customer must record.

Then test the evidence you can actually produce: continuity and recovery test results, incident timelines, subcontractor information, audit and access rights, and a workable exit plan.

This is a readiness conversation, not a claim that a vendor is certified or that a contract review can be replaced by a checklist.

Official EU sources

Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.

RegulationsMethodologySee what the EU Readiness Pack includes

Mini-check: does DORA reach you?

A few questions about your financial-sector customers. Answers carry into the full assessment.

Do you provide ICT services to an EU financial institution?

This includes an EU branch or subsidiary of a wider group.

Has that customer told you whether your service supports a critical or important function?

This classification comes from the customer, not from you.

Start the full assessment instead

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.