DORA (Digital Operational Resilience Act) has applied to EU financial firms since January 2025. Many SaaS providers, IT service providers and FinTech platforms miss one point. Say a bank or other financial firm uses your service, and you count as a "critical ICT third-party provider." Then DORA duties apply to you as well. They reach you through the service contract.
When a Supplier Becomes "Critical"
DORA Art. 28 and the RTS define "critical ICT third-party providers" by four criteria:
- The function is critical or important. The financial firm needs it to deliver its service without a break.
- It is hard to replace. A switch would clearly hurt the financial customer's clients or market position.
- Concentration: Many financial customers depend on the same provider. Examples are a cloud provider, core banking or a specific SaaS workflow.
- Data sensitivity: The provider handles critical data or data that falls under the rules.
If you meet one, two or five of these criteria, expect your financial customers to ask more of you under DORA.
What DORA Passes On in Technical Terms
1. ICT Risk Management Framework, Approved by the Board
It must be written down, updated each year and signed off by management, with a record of that approval. It includes:
- an asset inventory
- a risk assessment
- a treatment plan
- reviews of how well the measures work
The multi-framework platform helps here, because the ISO 27001 base already covers 80 % of DORA's rules.
2. Incident Classification With RTS Triggers
You must rate every incident as high, medium or low, as set out in the DORA RTS. You must report "major" incidents within 4 h. This takes an initial, an interim and a final report. Integrated health monitoring + audit log gives you the data in minutes, not days.
3. Tests of Operational Resilience
Run resilience tests each year and record them. Large providers also need threat-led penetration testing in line with TIBER-EU every 3 years. Archive the results and put the lessons learned into practice.
4. Contract Rules Under DORA Art. 30
- Audit rights for the financial customer and the supervisory authority
- Service levels with penalties
- A written exit plan (return of data, help with migration)
- Clarity on subcontractors (which suppliers does the provider use?)
- Notice of incidents to the financial customer, with a deadline
- A key personnel clause
5. Concentration Risk Analysis
If your service has many financial customers, the supervisor (BaFin, EBA, SSM) will look at the combined risk. Say one SaaS incident takes down several banks at once. That counts as systemic risk, and it leads to direct oversight by the ESAs.
What Financial Customers Ask of Suppliers in 2026
These items come from real supplier audits in 2025 and 2026:
- ISO 27001 certificate (often the minimum)
- A trust center with current compliance proof (a white-label trust center makes this public)
- A list of sub-processors in a GDPR-compliant form
- A pen-test report no more than 12 months old
- Backup and restore-test logs
- Proof of EU hosting with a Schrems II assessment
- An SLA that covers incident response
- An exit plan with data migration formats
Strategic Choices
Option 1: Use DORA as a Sales Advantage
If you want to win financial customers, prove that you meet DORA before anyone asks. This opens doors that stay closed to other SaaS providers.
Option 2: Give Financial Customers Lower Priority on Purpose
Say financial customers bring in only 5 % of revenue, but DORA raises your compliance costs by 30 %. Then it can make strategic sense not to chase this segment. But in that case, state in writing that your service is "not suitable for financial services." If you don't, signing a contract can pass the duties on to you.
Option 3: Manage Subcontractors in a Planned Way
If you use cloud providers or other SaaS yourself, DORA duties reach further down the chain. Your own suppliers must also be fit for DORA. A TPRM module with DORA extension handles that.
A Realistic Estimate of the Compliance Effort
- SaaS with ISO 27001 in place: about 30 PD extra to extend it for DORA (contract templates, incident RTS, exit plan).
- SaaS without ISO 27001: about 120 PD for the ISO base plus about 30 PD for the DORA top-up.
- Ongoing effort each year: 15β25 PD for reviews, repeat tests and contract updates.
Conclusion
DORA affects you as soon as one financial firm uses your service. It affects you heavily if you become a "critical ICT third-party provider." An integrated compliance and security platform with an ISO 27001 base and a DORA top-up can get you there in 4β6 months. After that, you can pass audits from financial customers without drama. If you plan to grow with financial customers in 2026, do not put this off.