DORA and an ICT supplier
DORA is the EU regulation on digital operational resilience for financial entities. From 17 January 2025 it directly places duties on banks, insurers, investment firms, and other financial entities for ICT risk, incidents, testing, and contractual management of ICT third-party services. A supplier is not automatically the direct addressee of every DORA duty. Its financial customer must, however, be able to show that it selected, contracted, and manages the service in a risk-proportionate way.
What a customer may request
For a critical or important function, a customer may request through due diligence and contract an architecture description, security measures, subcontractors, data-processing locations, service recovery, incident notification, audit cooperation, and exit terms. The scope depends on the service and risk. ISO 27001 can be useful evidence, but it is not a blanket statutory DORA requirement.
Testing and incidents
A financial entity must plan and perform risk-proportionate digital-resilience testing. TLPT is a specific supervisory regime for selected entities, not a routine obligation for every supplier. A supplier should have a contractual process for promptly giving the customer information needed for its incident response and reporting.
Practical checks
- identify the service, data, dependencies, and the customer owner
- record subcontractors, change notification, recovery evidence, audit cooperation, and exit handover
- agree the supplier incident contact, the information needed, and the contractual notification route
Run two useful exercises. Restore a representative record from backup and record the actual recovery time. Then simulate an incident notification. Confirm that the customer receives impact, affected service, containment, and next-update information in the agreed period. These exercises support a customer assessment. They do not replace legal advice or a regulator’s decision.
Read the primary text in DORA on EUR-Lex. For a delivery brief, see custom software and technology consulting.
If you are preparing a service for a regulated customer, contact us. We can turn customer requirements into clear technical and contractual material.