4 Oct 2026
DORA for ICT Vendors: What Financial Institutions Need From Their Technology Providers
What DORA (EU Regulation 2022/2554) actually requires from ICT vendors selling to EU financial institutions — who is directly regulated, who is a 'critical' ICT third-party provider, and what typically flows down into contracts and due diligence.

DORA for ICT Vendors: What Financial Institutions Need From Their Technology Providers
Last reviewed: 4 October 2026. This article summarizes publicly available EU regulatory sources for general informational purposes. It is not legal advice. If you need a compliance determination for your specific business, consult qualified counsel or your customer's compliance contact.
Disclaimer: DORA is a binding EU regulation with a formal legal text, delegated acts, and regulatory technical standards. This article explains the regulation's structure and its practical effect on technology vendors in plain language. It does not replace the official text, and it does not tell you whether DORA applies to your specific business — that determination depends on facts this article cannot know.
Quick answer
The Digital Operational Resilience Act (DORA — Regulation (EU) 2022/2554) directly regulates EU financial entities (banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and other in-scope firms), not ordinary technology vendors. Most ICT and SaaS suppliers selling to EU financial institutions are not directly regulated by DORA. Instead, DORA requires their financial-entity customers to manage ICT third-party risk — which flows down to vendors as specific contract clauses, due-diligence questions, audit and access rights, and documentation requests. A separate, narrower part of DORA creates direct regulatory oversight for a small number of ICT providers formally designated "critical" by the European Supervisory Authorities (ESAs) — as of November 2025, 19 providers held that designation. If you are not on that list, DORA still affects you, but through your customer's contract and due-diligence process, not through direct supervision.
Contents
- Who DORA directly applies to
- How ICT providers are actually affected
- Why financial institutions run due diligence on ICT vendors
- What customers may need in the contract
- Ongoing monitoring implications
- Subcontractor considerations
- Critical ICT third-party providers: the direct-oversight regime
- What this can mean operationally for your business
- FAQ
- Official sources
Who DORA directly applies to
DORA is EU Regulation 2022/2554. It entered into force on 16 January 2023 and has applied since 17 January 2025.
DORA's Article 2 sets out the "financial entities" directly bound by the regulation. In broad terms, this includes: credit institutions, payment institutions and electronic money institutions, investment firms, trading venues, central counterparties and central securities depositories, insurance and reinsurance undertakings, insurance intermediaries (with proportionality for smaller firms), managers of alternative investment funds, institutions for occupational retirement provision, and crypto-asset service providers, among other categories listed in the regulation. Some smaller entities (for example certain microenterprises) receive proportionate treatment.
What this means: if your customer is a bank, insurer, investment firm, payment institution, or another entity on that list, DORA governs how they must manage risk from their technology suppliers — including you. DORA does not, by itself, directly regulate your company merely because you sell software or IT services to one of these institutions.
What DORA says vs. what your customer may operationally ask you for: DORA's legal obligations sit with the financial entity, not (in almost all cases) with you. But financial entities satisfy those obligations partly by asking their vendors for information, contract terms, and cooperation. The rest of this article separates "what the regulation requires of the financial entity" from "what that can mean the vendor gets asked to provide."
How ICT providers are actually affected
There are two distinct ways a technology vendor can be touched by DORA, and they are very different in scale:
| Ordinary ICT vendor (the vast majority) | Designated "critical" ICT third-party provider (CTPP) | |
|---|---|---|
| Directly regulated by DORA? | No | Yes |
| How DORA reaches you | Indirectly, through your financial-entity customer's contractual and due-diligence obligations | Directly, through a dedicated EU-level oversight framework with a Lead Overseer |
| Who decides | Your customer's risk and procurement process | The European Supervisory Authorities (EBA, ESMA, EIOPA), following defined criteria in Article 31 |
| Typical trigger | Selling ICT services that support a financial entity's operations, especially "critical or important functions" | Assessed as systemically important based on factors such as how many financial entities rely on you, market concentration, and substitutability |
| As of late 2025 | The large majority of ICT vendors serving the sector | 19 providers were designated in the first list published in November 2025, including major cloud infrastructure, core banking, and specialist fintech providers |
Do not assume you are directly regulated by DORA just because you sell to a bank or insurer. Direct designation as a critical ICT third-party provider is a formal, narrow status that the ESAs apply to a small number of providers assessed as systemically important — not a general label for "vendor to a financial institution."
Why financial institutions conduct due diligence on ICT vendors
Article 28 of DORA requires financial entities to manage ICT third-party risk as part of their overall ICT risk management framework — not as a one-off procurement checkbox. Two obligations in Article 28 directly shape what your customer will ask you for:
- A register of information. Financial entities must maintain a register covering all their contractual arrangements for ICT services, to give supervisors visibility into their third-party dependencies. To populate and keep this register current, your customer needs accurate, current information from you: what service you provide, where it's provided from, whether it supports a critical or important function, and details about any subcontracting.
- Pre-contractual due diligence. Before signing or materially changing a contract, financial entities are expected to assess factors including the criticality of the service, concentration risk (how dependent they'd become on you, and on any subprocessors you use), and your ability to meet their security and continuity requirements.
What this typically means for a vendor: expect your customer's onboarding or renewal process to ask more specific, structured questions than a generic security questionnaire — particularly about where your service is provided from, what subprocessors you rely on, and how substitutable your service is (i.e., how hard it would be for them to switch away from you).
What customers may need in the contract
Article 30 sets out contractual content requirements on a two-tier basis: a baseline that applies to ICT service contracts generally, and an enhanced set of terms that applies specifically when the contracted service supports a critical or important function of the financial entity.
| Tier | Applies to | Typical contractual content |
|---|---|---|
| Baseline | ICT service contracts generally | Clear description of the functions/services provided; whether subcontracting is permitted and under what conditions; the locations where services are performed and data is processed/stored, with notice if that changes; data protection, availability, integrity, and confidentiality provisions; provisions for access, recovery, and return of data on termination; assistance in the event of an ICT incident; cooperation with the financial entity's competent authority |
| Enhanced (critical/important functions only) | ICT services identified by the financial entity as supporting a critical or important function | More precise service-level performance targets; notice periods for material changes; participation in the financial entity's business continuity testing; participation in threat-led penetration testing (TLPT) where relevant; audit and inspection rights for the financial entity (and, where applicable, its regulators); defined exit strategies and transition assistance; for entities subject to resolution regimes, terms preventing termination during a resolution process |
Practical takeaway: whether you see baseline or enhanced terms depends on whether your customer classifies the service you provide as supporting a "critical or important function" — a determination they make, not you. If your service touches core transaction processing, payments, custody, or similar functions, expect the enhanced set.
Ongoing monitoring implications
DORA's third-party risk obligations don't end at signature. Financial entities are expected to monitor their ICT third-party arrangements on an ongoing basis, which can mean, depending on the customer and the criticality of the service:
- Periodic re-confirmation of the information held in their register about your service (location, subcontractors, criticality classification)
- Requests to notify them of material changes on your side (a new subprocessor, a change in where data is processed, a significant incident)
- Participation in resilience testing exercises where your service supports a critical or important function
- Re-assessment of concentration risk — for example, if a customer becomes aware that many of its other suppliers also depend on the same subprocessor you use
None of this implies continuous, automated monitoring is universal — the intensity of monitoring is proportionate to the criticality of your service and the size/risk profile of the financial entity, and varies accordingly.
Subcontractor considerations
DORA explicitly extends financial entities' due-diligence and contractual concerns down the supply chain. Article 28 requires financial entities to assess subcontracting arrangements as part of their risk assessment, particularly for services supporting critical or important functions, and Article 30's baseline terms require contracts to state whether subcontracting is permitted and on what conditions. The European Supervisory Authorities have also been tasked with developing more detailed technical standards on subcontracting for critical or important functions.
What this typically means for a vendor: if you subcontract any part of a service you provide to a DORA-covered customer (cloud hosting, a specialist processing provider, outsourced support), expect to be asked to disclose that subcontractor, confirm what data or function they touch, and in some cases show that your own contract with them supports your customer's requirements (e.g., audit rights, data location commitments) flowing all the way down the chain.
Critical ICT third-party providers: the direct-oversight regime
Separately from the contractual flow-down described above, DORA (Articles 31–44) creates a direct EU-level oversight framework for ICT third-party providers formally designated as "critical" (CTPPs). This is the one part of DORA that regulates ICT vendors directly rather than through their financial-entity customers.
- Designation criteria (Article 31): the ESAs assess factors including the provider's systemic importance (e.g., how many, and how systemically important, the financial entities relying on it are), the degree of concentration and reliance in the market, and how substitutable the service is.
- First designations: the European Supervisory Authorities published their first list of designated critical ICT third-party providers on 18 November 2025, covering 19 providers, including major cloud infrastructure providers, core banking platforms, and specialist fintech firms.
- What designation means: a designated CTPP is subject to direct oversight by a "Lead Overseer" (one of the ESAs), including examination activities intended to confirm the provider maintains appropriate risk management and governance for the services it delivers to the financial sector. Designation does not remove the financial entity's own responsibility to govern the relationship — DORA is explicit that oversight of the CTPP is additive, not a substitute for the financial entity's own due diligence.
- Exemptions: certain categories are excluded from direct designation, including providers already subject to equivalent central bank oversight, intra-group service providers, providers operating in a single Member State serving only financial entities there, and providers that voluntarily opt in without meeting the systemic-importance criteria may do so under specific conditions.
If you are not on the published CTPP list, this part of DORA does not directly apply to you — but it's worth checking the ESAs' published list periodically if your company provides infrastructure-level or highly concentrated services to the financial sector, since the list is expected to be reviewed and can be updated.
What this can mean operationally for your business
If you are a typical (non-critical) ICT or SaaS vendor selling to EU financial institutions, DORA most commonly shows up as:
- More detailed due-diligence questions during onboarding, focused on service location, subcontracting, and substitutability — not just generic security posture
- Contract clauses matching the Article 30 baseline (and, if your service supports a critical/important function, the enhanced set) — expect legal review to take these seriously
- A request to disclose your subprocessors and, in some cases, evidence that your own contracts with them support your customer's requirements
- A request to notify the customer of material changes (new subprocessor, new data-processing location, material incident) — not just an annual check-in
- For services classified as supporting a critical/important function: audit/inspection rights, participation in resilience testing, and a documented exit plan
- Periodic re-confirmation of the information your customer holds about your service for their own register of information
None of this requires you to become "DORA compliant" as a company (that obligation sits with your financial-entity customer) — it requires you to be able to answer these questions accurately and keep the underlying information current, which is the same discipline needed for security questionnaires and due-diligence checklists generally. See our guides to vendor due diligence and third-party risk management from the vendor side for the broader process this fits into.
FAQ
Does DORA apply directly to my SaaS or IT company?
In almost all cases, no — unless your company has been formally designated a "critical ICT third-party provider" by the European Supervisory Authorities. DORA's direct legal obligations sit with your financial-entity customers; it reaches most vendors indirectly, through customer contracts and due diligence.
What is a "critical ICT third-party provider" (CTPP)?
A provider the ESAs have formally designated as systemically important to the EU financial sector under Article 31 criteria, subject to direct EU-level oversight. The first list of 19 designated providers was published in November 2025. It is a narrow, specific status — not a general description of "any vendor to a bank."
Will every financial-services customer ask for the same contract terms?
No. DORA sets a baseline and an enhanced tier of contractual content, and which tier applies depends on whether your customer classifies your service as supporting a "critical or important function" — a judgment they make based on their own risk assessment.
Do I need to disclose my subcontractors under DORA?
If you provide services to an EU financial entity and use subcontractors, expect this to come up — DORA's due-diligence and contractual provisions specifically address subcontracting, particularly for services supporting critical or important functions.
Is DORA the same as the EBA's third-party risk guidelines?
No. DORA is a directly applicable EU regulation focused specifically on ICT/digital operational resilience. The EBA has separately issued guidelines addressing third-party risk for services more broadly, including non-ICT services — see our guide to the EBA 2026 third-party risk guidelines for that separate framework.
What happens if my company is added to the critical ICT provider list later?
You would become subject to direct oversight by a Lead Overseer (one of the ESAs), including examination of your risk management and governance arrangements — a materially different obligation than the contractual flow-down most vendors experience.
Related reading
- Third-Party Risk Management From the Vendor Side
- EBA 2026 Third-Party Risk Guidelines: What Suppliers Should Prepare For
- Vendor Due Diligence Checklist: What Suppliers Should Prepare
- Vendor Onboarding: The Complete Guide for Suppliers
Get organized before the next DORA-driven due-diligence round
If you sell to EU financial institutions, DORA-related requests (subprocessor disclosure, service-location confirmation, contract-clause review) tend to arrive as part of a broader onboarding or renewal packet, alongside a security questionnaire and standard due diligence. MatchAudit's Vendor Assurance workspace helps you keep that underlying evidence — policies, subprocessor lists, approved answers — current and reusable across every financial-services customer relationship you manage, with a per-customer view of what's ready and what's missing.
- See your readiness across customers: start free
- Talk to us about a financial-services customer relationship: contact us
- Compare plans: pricing
Official sources
- EUR-Lex, Regulation (EU) 2022/2554 (DORA), full text: eur-lex.europa.eu
- European Securities and Markets Authority (ESMA), Digital Operational Resilience Act overview: esma.europa.eu
- European Banking Authority, press release on the designation of critical ICT third-party providers (18 November 2025): eba.europa.eu
