Does DORA apply to me?
DORA has applied since 17 January 2025 to EU financial entities, and through their contracts to the technology companies that serve them. Answer five questions and see whether DORA applies to you directly, which contract terms your financial customers must put in front of you, and when critical-provider oversight begins.
DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 to EU financial entities: banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and more. A SaaS or cloud vendor selling to them is usually not regulated directly, but must accept the contract terms in Article 30. Only providers the EU supervisory authorities designate as critical face direct oversight.
Result
DORA puts the duty on your financial customers, and they must pass it to you in writing. Because your service supports a critical or important function, expect the full Article 30(3) terms: precise service levels, tested business continuity plans, participation in their threat-led penetration tests, unrestricted audit and access rights for them and their regulator, and an exit strategy with a transition period. Your subcontractors will be asked about too.
- Prepare: a DORA addendum that maps your standard terms to each Article 30 point; customers' legal teams will ask for exactly this.
- Evidence: SOC 2 or ISO 27001 reports, business continuity test results and an incident notification process answer most of the due diligence. See the SOC 2 checker.
- Locations: be ready to state where you process and store data, and to notify customers before you change it.
Who DORA covers
DORA applies to 20 types of financial entity in Article 2(1): credit institutions, payment institutions, account information service providers, electronic money institutions, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, trade repositories, managers of alternative investment funds, management companies, data reporting service providers, insurance and reinsurance undertakings, insurance intermediaries, occupational pension funds, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers and securitisation repositories. It also names ICT third-party service providers, the subject of the oversight framework. It has applied since 17 January 2025 as a regulation, so it applies directly with no national transposition.
What it means for a SaaS vendor selling to EU banks
An ICT third-party service provider is any undertaking providing ICT services, meaning digital and data services delivered through ICT systems on an ongoing basis. That includes SaaS. Unless you are designated critical, DORA does not supervise you; it obliges your financial customers to put specific terms in your contract (Art. 30), list you in their register of information (Art. 28(3)), assess you before contracting and plan their exit from you. In practice that means a DORA addendum, longer due diligence, audit rights and incident-notification commitments.
The Article 30 terms a bank will send you
Article 30(1) requires the whole contract, including service levels, in one written document. Article 30(2) sets the minimum terms for every ICT service:
- A clear and complete description of the functions and ICT services, and whether subcontracting of a service supporting a critical or important function is permitted, and on what conditions.
- The regions or countries where services are provided and data is processed and stored, and a duty to notify the customer in advance before you change them.
- Availability, authenticity, integrity and confidentiality of data, including personal data.
- Access, recovery and return of the customer's data in an easily accessible format if you become insolvent, are resolved, stop trading, or the contract ends.
- Service level descriptions, with updates and revisions.
- Assistance in an ICT incident related to your service, at no extra cost or at a cost fixed in advance.
- Full cooperation with the customer's competent authorities and resolution authorities.
- Termination rights and minimum notice periods that meet the regulators' expectations.
- Your participation in the customer's ICT security awareness and digital operational resilience training.
Where your service supports a critical or important function, Article 30(3) adds:
- Full service level descriptions with precise quantitative and qualitative performance targets.
- Notice periods and reporting duties, including notice of anything that could materially affect your ability to deliver the service.
- Business contingency plans you implement and test, and security measures appropriate to the customer's regulatory framework.
- Participation and full cooperation in the customer's threat-led penetration testing.
- Unrestricted rights of access, inspection and audit for the customer, a third party it appoints and its regulator, with the right to take copies on site; alternative assurance levels can be agreed where other clients' rights are affected.
- An exit strategy with a mandatory transition period, during which you keep providing the service while the customer migrates to another provider or in-house.
Delegated Regulation (EU) 2025/532 adds what the customer must assess before allowing you to subcontract services that support critical or important functions.
Critical providers
The European Supervisory Authorities designate ICT providers as critical on their systemic impact, the reliance of systemically important institutions on them, and how hard they are to substitute, using criteria in Delegated Regulation (EU) 2024/1502. Intra-group providers, financial entities serving others, and providers serving only one member state's entities in that state are not designated. A provider can also ask to be designated. The ESAs publish the list each year.
DORA and NIS2
NIS2 treats DORA as sector-specific law: for financial entities, DORA's ICT risk-management and incident-reporting rules apply instead of the equivalent NIS2 duties. An ICT provider can still be covered by NIS2 in its own right, as a cloud or managed service provider. See Does NIS2 apply?.
Sources
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act), EUR-Lex
- Commission Delegated Regulation (EU) 2025/301 (incident reporting content and time limits), EUR-Lex
- Commission Delegated Regulation (EU) 2024/1502 (criteria for critical ICT third-party providers), EUR-Lex
- Commission Delegated Regulation (EU) 2025/532 (subcontracting of critical or important functions), EUR-Lex
- European Commission: DORA implementing and delegated acts
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
When did DORA come into force?
DORA entered into force in January 2023 and has applied since 17 January 2025 (Article 64). It is a regulation, so it applies directly in every member state.
Does DORA apply to SaaS providers?
Not directly, unless a SaaS provider is designated critical. But financial entities must put the Article 30 terms in their ICT contracts, so a SaaS vendor selling to EU banks or insurers has to accept those terms.
What does Article 30 of DORA require?
Written ICT contracts with minimum terms: service description, data locations, data protection and return, service levels, incident assistance, cooperation with regulators and termination rights. Services supporting critical or important functions also need precise service levels, continuity testing, audit rights and an exit strategy.
What is a critical ICT third-party service provider under DORA?
A provider the European Supervisory Authorities designate as critical for the EU financial sector, based on systemic impact, reliance and substitutability. Critical providers are overseen directly by a Lead Overseer.
What are DORA's incident reporting deadlines?
For a major ICT-related incident: an initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within one month of the latest intermediate report.
What are the penalties under DORA?
Member states set the penalties for financial entities, and DORA requires competent authorities to have the powers to impose them. For critical ICT providers, the Lead Overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover.
Does DORA apply to companies outside the EU?
DORA's financial entities are EU-authorised firms. Non-EU ICT providers are affected through their EU customers' contracts, and a non-EU provider designated critical must set up an EU subsidiary within 12 months for EU financial entities to keep using it.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.