Guide
DORA for SaaS vendors serving EU financial firms
Reviewed 2026-08-07
Short answer
DORA is addressed to EU financial entities, not most of their technology suppliers. For the normal SaaS vendor, it arrives through mandatory customer contract terms and vendor-risk processes. A small number of ICT providers formally designated as critical are different: that designation creates direct EU oversight and cannot be inferred from customer size or reputation.
See the full 9-step checklist below.Why this matters
- Who should care
- ICT and technology suppliers to EU banks, insurers, funds and payment firms.
- Typical trigger
- An EU financial-sector customer's own DORA third-party risk obligations reaching your contract.
- What buyers may ask for
- prescribed contract termsincident notification commitmentsexit and continuity provisions
Where this fits
01
EU financial entity
A bank, insurer, fund or payment firm subject to DORA's ICT risk-management rules.
02
Your company
Acts as an ICT third-party provider under contract with that financial entity.
03
Contract terms
DORA requires specific clauses to flow down: incident notification, exit rights, audit access.
Who this is relevant to
This guide is for SaaS, infrastructure, fintech and regtech vendors selling into EU banks, insurers, payment institutions, investment firms, trading venues and similar regulated customers.
The relevant question is where the customer sits in the EU financial regulatory perimeter, not where your own company is headquartered.
- Vendors already on an EU financial customer's supplier panel
- Teams receiving a DORA-labelled due-diligence questionnaire
- Products supporting payments, clearing, trading, insurance or core banking workflows
- Vendors whose service or subcontractors are being recorded in a customer's ICT-risk register
How DORA reaches a vendor that is not an EU financial firm
DORA addresses financial entities directly and requires them to manage ICT risk, including the risk introduced by their suppliers.
A SaaS vendor normally encounters that obligation through the contract its EU financial customer must put in place. The customer remains accountable to its regulator for supplier risk.
A narrower route exists for providers formally designated as critical ICT third-party providers by the European Supervisory Authorities. That is a formal status, not something a vendor can infer from its customer base.
Direct application vs customer flow-down
For most vendors, DORA is a flow-down obligation rather than a direct one. The practical work is to agree workable contract terms, evidence the operational resilience behind them, and give the customer the facts it needs for its own register and risk assessment.
- Direct: a formally designated critical ICT third-party provider is subject to direct EU oversight
- Customer-driven: the normal vendor relationship carries mandatory contract clauses and evidence requests
- The financial customer classifies the service against its own operations; the vendor should not guess
What an EU financial customer will ask you to produce
The questionnaire usually arrives looking like a standard vendor security review with a handful of DORA-specific additions layered on top.
- Confirmation you accept the mandatory ICT third-party contract terms: exit rights, audit and access rights, service level detail, subcontracting notification
- A description of your service precise enough for your customer to record it correctly in their register of information
- Your position on subcontracting: who you rely on, where, and how you notify changes
- Business continuity and disaster recovery evidence, including test results, not just a plan
- Incident detection and notification timelines you can commit to contractually
- Confirmation of audit and access rights the customer's regulator expects them to hold over material suppliers
- An exit and termination plan describing how the customer's data and workloads leave your service without unacceptable disruption
- Where relevant, evidence that any subcontractor you rely on for a material part of the service accepts equivalent terms
Common misconceptions
- “DORA does not apply to us because we are not a financial institution.”
- Correct as a matter of direct legal application for almost everyone reading this. But your EU financial customer's obligation to manage you as an ICT risk is real, contractual, and enforced through the contract regardless of your own regulatory status.
- “We can decide for ourselves whether we support a critical or important function.”
- That classification is made by the financial entity, based on their own operations and regulatory exposure, not by you. If a customer has not told you the classification, the honest answer is that you do not know it. Do not guess in a security questionnaire.
- “One customer's DORA terms will do for all our EU financial customers.”
- Contract terms vary by customer and by how critical the function is judged to be. Treat each EU financial relationship as its own review, even where the paperwork looks similar.
- “Being a large or well-known vendor means we are a critical ICT third-party provider.”
- Designation is a formal EU regulatory act, not a reputational judgement. Very few providers hold it. Assume you do not unless you have been formally told otherwise.
- “Our SOC 2 report already covers this.”
- A SOC 2 report is useful evidence but does not itself satisfy the specific contractual terms DORA requires: audit rights, exit planning, subcontracting notification and register data are additional, not substitutable.
Practical checklist
- 01Identify which of your customers are EU financial entities, including EU branches or subsidiaries of Asian groups
- 02Ask directly whether your service has been classified as supporting a critical or important function. Do not assume either answer
- 03Review your standard contract for exit rights, audit and access rights, and subcontracting notification, and be ready to accept stronger versions for EU financial customers
- 04Maintain a current subcontracting map for the service you provide to each EU financial customer
- 05Test your business continuity and disaster recovery plan, and keep the test evidence, not just the document
- 06Define incident detection and notification timelines you can actually meet before you commit to them contractually
- 07Prepare a written exit and data-portability plan for the service, not just a data export feature
- 08Nominate someone who can answer a customer's register-of-information questions about your service without a lengthy internal chase
- 09Confirm your key subcontractors are willing to accept flow-down terms if a customer asks for that assurance
Questions to settle before an EU financial deal
Start with the customer relationship: identify which customers are EU financial entities, whether the service supports a critical or important function, and what service and subcontractor information the customer must record.
Then test the evidence you can actually produce: continuity and recovery test results, incident timelines, subcontractor information, audit and access rights, and a workable exit plan.
This is a readiness conversation, not a claim that a vendor is certified or that a contract review can be replaced by a checklist.
Official EU sources
Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.
Regulation (EU) 2022/2554 — Digital Operational Resilience Act · Read on EUR-Lex (CELEX 32022R2554)Verified 2026-08-17
RegulationsMethodologySee what the EU Readiness Pack includes
Mini-check: does DORA reach you?
A few questions about your financial-sector customers. Answers carry into the full assessment.