Free tool · DORA

Does DORA apply to me?

DORA has applied since 17 January 2025 to EU financial entities, and through their contracts to the technology companies that serve them. Answer five questions and see whether DORA applies to you directly, which contract terms your financial customers must put in front of you, and when critical-provider oversight begins.

Short answer

DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 to EU financial entities: banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and more. A SaaS or cloud vendor selling to them is usually not regulated directly, but must accept the contract terms in Article 30. Only providers the EU supervisory authorities designate as critical face direct oversight.

Answer for your organisation

A function whose disruption would materially impair the customer's finances, the continuity of its services or its regulatory compliance. Your customer decides; ask them.
The ESAs designate critical providers on systemic impact, reliance by systemically important institutions and substitutability, and publish the list yearly.
Article 16 covers small and non-interconnected investment firms, exempted payment and e-money institutions, and small pension funds, among others.
Worked example: a non-EU SaaS vendor whose product supports a core function at EU banks

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Likely required: not regulated directly, but bound by Article 30(3) contracts

DORA puts the duty on your financial customers, and they must pass it to you in writing. Because your service supports a critical or important function, expect the full Article 30(3) terms: precise service levels, tested business continuity plans, participation in their threat-led penetration tests, unrestricted audit and access rights for them and their regulator, and an exit strategy with a transition period. Your subcontractors will be asked about too.

Contract terms for every ICT service: description, locations, data protection, data return, service levels, incident assistance, cooperation with authorities, termination rights, trainingArt. 30(2)
Extra terms for critical or important functions: precise service levels, business continuity testing, threat-led penetration testing participation, unrestricted audit and access rights, exit strategyArt. 30(3)
Subcontracting of services supporting critical or important functionsArt. 30(2)(a); Del. Reg. 2025/532
  • Prepare: a DORA addendum that maps your standard terms to each Article 30 point; customers' legal teams will ask for exactly this.
  • Evidence: SOC 2 or ISO 27001 reports, business continuity test results and an incident notification process answer most of the due diligence. See the SOC 2 checker.
  • Locations: be ready to state where you process and store data, and to notify customers before you change it.
01

Who DORA covers

DORA applies to 20 types of financial entity in Article 2(1): credit institutions, payment institutions, account information service providers, electronic money institutions, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, trade repositories, managers of alternative investment funds, management companies, data reporting service providers, insurance and reinsurance undertakings, insurance intermediaries, occupational pension funds, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers and securitisation repositories. It also names ICT third-party service providers, the subject of the oversight framework. It has applied since 17 January 2025 as a regulation, so it applies directly with no national transposition.

02

What it means for a SaaS vendor selling to EU banks

An ICT third-party service provider is any undertaking providing ICT services, meaning digital and data services delivered through ICT systems on an ongoing basis. That includes SaaS. Unless you are designated critical, DORA does not supervise you; it obliges your financial customers to put specific terms in your contract (Art. 30), list you in their register of information (Art. 28(3)), assess you before contracting and plan their exit from you. In practice that means a DORA addendum, longer due diligence, audit rights and incident-notification commitments.

03

The Article 30 terms a bank will send you

Article 30(1) requires the whole contract, including service levels, in one written document. Article 30(2) sets the minimum terms for every ICT service:

  1. A clear and complete description of the functions and ICT services, and whether subcontracting of a service supporting a critical or important function is permitted, and on what conditions.
  2. The regions or countries where services are provided and data is processed and stored, and a duty to notify the customer in advance before you change them.
  3. Availability, authenticity, integrity and confidentiality of data, including personal data.
  4. Access, recovery and return of the customer's data in an easily accessible format if you become insolvent, are resolved, stop trading, or the contract ends.
  5. Service level descriptions, with updates and revisions.
  6. Assistance in an ICT incident related to your service, at no extra cost or at a cost fixed in advance.
  7. Full cooperation with the customer's competent authorities and resolution authorities.
  8. Termination rights and minimum notice periods that meet the regulators' expectations.
  9. Your participation in the customer's ICT security awareness and digital operational resilience training.

Where your service supports a critical or important function, Article 30(3) adds:

  1. Full service level descriptions with precise quantitative and qualitative performance targets.
  2. Notice periods and reporting duties, including notice of anything that could materially affect your ability to deliver the service.
  3. Business contingency plans you implement and test, and security measures appropriate to the customer's regulatory framework.
  4. Participation and full cooperation in the customer's threat-led penetration testing.
  5. Unrestricted rights of access, inspection and audit for the customer, a third party it appoints and its regulator, with the right to take copies on site; alternative assurance levels can be agreed where other clients' rights are affected.
  6. An exit strategy with a mandatory transition period, during which you keep providing the service while the customer migrates to another provider or in-house.

Delegated Regulation (EU) 2025/532 adds what the customer must assess before allowing you to subcontract services that support critical or important functions.

04

Critical providers

The European Supervisory Authorities designate ICT providers as critical on their systemic impact, the reliance of systemically important institutions on them, and how hard they are to substitute, using criteria in Delegated Regulation (EU) 2024/1502. Intra-group providers, financial entities serving others, and providers serving only one member state's entities in that state are not designated. A provider can also ask to be designated. The ESAs publish the list each year.

05

DORA and NIS2

NIS2 treats DORA as sector-specific law: for financial entities, DORA's ICT risk-management and incident-reporting rules apply instead of the equivalent NIS2 duties. An ICT provider can still be covered by NIS2 in its own right, as a cloud or managed service provider. See Does NIS2 apply?.

06

Sources

Questions

The things people ask us

When did DORA come into force?

DORA entered into force in January 2023 and has applied since 17 January 2025 (Article 64). It is a regulation, so it applies directly in every member state.

Does DORA apply to SaaS providers?

Not directly, unless a SaaS provider is designated critical. But financial entities must put the Article 30 terms in their ICT contracts, so a SaaS vendor selling to EU banks or insurers has to accept those terms.

What does Article 30 of DORA require?

Written ICT contracts with minimum terms: service description, data locations, data protection and return, service levels, incident assistance, cooperation with regulators and termination rights. Services supporting critical or important functions also need precise service levels, continuity testing, audit rights and an exit strategy.

What is a critical ICT third-party service provider under DORA?

A provider the European Supervisory Authorities designate as critical for the EU financial sector, based on systemic impact, reliance and substitutability. Critical providers are overseen directly by a Lead Overseer.

What are DORA's incident reporting deadlines?

For a major ICT-related incident: an initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within one month of the latest intermediate report.

What are the penalties under DORA?

Member states set the penalties for financial entities, and DORA requires competent authorities to have the powers to impose them. For critical ICT providers, the Lead Overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover.

Does DORA apply to companies outside the EU?

DORA's financial entities are EU-authorised firms. Non-EU ICT providers are affected through their EU customers' contracts, and a non-EU provider designated critical must set up an EU subsidiary within 12 months for EU financial entities to keep using it.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.