← Legal Landscape

Already in force17/01/2025 · Regulation (EU) 2022/2554

DORA applies

What applies

DORA — the Digital Operational Resilience Act — has applied since 17 January 2025. It requires banks, insurers, payment service providers, and investment firms to manage their digital operational resilience demonstrably: ICT risk management, incident reporting, resilience testing, and a strict regime for outsourcing.

The often-missed point: DORA reaches well beyond the financial sector itself. Anyone working as an IT service provider, software vendor, or data centre for financial entities gets the requirements passed down through the contract chain — audit rights, exit strategies, and reporting channels included.

Who it affects

Financial entities of nearly every size — and their ICT service providers through the contract chain, up to “critical ICT third-party providers” under direct EU oversight.

Example (fictional): The SaaS tool at the regional bank

A software house with 35 employees supplies a portfolio tool to two regional banks. During a 2025 contract renewal, the banks suddenly demand DORA-aligned clauses: audit rights, subcontractor transparency, reporting of major ICT incidents within hours, a documented exit strategy.

The software house has none of it prepared — the framework agreement stalls for three months, and a competitor with a ready DORA file takes over one of the two accounts. The risk here wasn't the supervisor. It was the customer.

The risks, plainly stated

Lost contracts rather than fines

Financial entities simply aren't allowed to keep working with non-aligned service providers — the sanction shows up as a termination or a lost tender.

Supervisory measures and periodic penalty payments

For critical ICT third-party providers, DORA provides for periodic penalty payments of up to 1% of average daily worldwide turnover — per day, for up to six months (Art. 35 DORA).

Liability in an incident

Anyone who fails to deliver contractually promised resilience is civilly liable when something goes wrong — and loses credibility in a regulated market.

Your next steps

  1. 01Check whether financial entities are among your customers, directly or through intermediaries
  2. 02Document ICT risk management and the incident process — every DORA questionnaire asks for it
  3. 03Prepare contract clauses (audit, exit, subcontractors) before the customer asks

In Compliverse

The compass turns exactly these steps into measures in your plan automatically — with deadlines, owners, and evidence.

Plain-language product content, not legal advice · Case studies are fictional · Fine amounts as stated in the legal act (“up to”)