Why DORA reaches you
DORA applies to around twenty types of financial entity: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and reinsurers, pension funds and more. You are an ICT third-party service provider: any undertaking that provides digital and data services to them, from SaaS and hosting to managed IT.
Article 28(1)(a) is the key sentence for you: a financial entity that outsources ICT "shall, at all times, remain fully responsible" for compliance. It cannot hand the responsibility to you, so it secures the rights it needs by contract. Before signing, it must assess whether your service supports a critical or important function, run due diligence, and check concentration risk (Article 28(4)). It may only contract with providers that "comply with appropriate information security standards" (Article 28(5)).
"Critical or important" is the customer's call. The same CRM can be non-critical for one insurer and critical for a payment institution whose onboarding runs on it. Ask early how they classify your service, because it decides whether Article 30(3) applies.
The register of information
Article 28(3) obliges every financial entity to keep a register of all its ICT contracts, and the competent authorities collect these registers each year. The format is fixed by Commission Implementing Regulation (EU) 2024/2956 (templates for the register of information). For you this means:
- You will be identified by a Legal Entity Identifier (LEI) or a European Unique Identifier (EUID), and where available both (Article 3(5) of the ITS). If you do not have an LEI, getting one is cheap and avoids friction.
- Where your service supports a critical or important function, the customer must also record the subcontractors that "effectively underpin" it, with their LEI or EUID (Article 3(6)). Expect a request for your relevant sub-processors and where they operate from.
- They will ask for the service type, data locations, governing law, substitutability and exit details for each contract.
The ESAs used these registers to identify which providers are critical for the sector as a whole (see the CTPP section below).
Article 30: the clauses that will appear in your contract
Article 30(1) requires the whole contract, including SLAs, to be in one written document in a durable, accessible format. The minimum content splits into two tiers.
| Article | Required element | What it means for a SaaS vendor |
|---|---|---|
| 30(2): every ICT contract | ||
| 30(2)(a) | Clear description of all functions and services; whether subcontracting of critical parts is allowed, and on what conditions | A service description that matches reality, including sub-processors |
| 30(2)(b) | Locations (regions or countries) of service delivery and data processing and storage; advance notice of changes | Name your hosting regions; commit to notify before moving them |
| 30(2)(c) | Availability, authenticity, integrity and confidentiality of data, including personal data | Security annex; ties in with your GDPR DPA |
| 30(2)(d) | Access, recovery and return of data in an easily accessible format on insolvency, resolution, discontinuation or termination | Documented export formats; escrow or similar for insolvency scenarios |
| 30(2)(e) | Service level descriptions, including updates | SLA in the contract, not only on a website |
| 30(2)(f) | Assistance in ICT incidents related to the service, at no additional cost or at a cost determined in advance | Price incident support up front |
| 30(2)(g) | Full cooperation with the customer's competent and resolution authorities | Accept that supervisors may contact you |
| 30(2)(h) | Termination rights and minimum notice periods | Plus the termination triggers in Article 28(7), such as a significant breach or evidenced security weaknesses |
| 30(2)(i) | Participation in the customer's ICT security awareness and resilience training | Join their training where agreed |
| 30(3): additionally, for critical or important functions | ||
| 30(3)(a) | Full SLAs with precise quantitative and qualitative performance targets | Measurable uptime, RTO/RPO and response times, with reporting |
| 30(3)(b) | Notice periods and reporting obligations, including any development that may materially affect service delivery | Proactive notice of financial, ownership or capacity issues |
| 30(3)(c) | Business contingency plans implemented and tested; appropriate ICT security measures, tools and policies | Tested BCP/DR with evidence |
| 30(3)(d) | Participation and full cooperation in the customer's TLPT | See the TLPT section |
| 30(3)(e) | Unrestricted access, inspection and audit rights for the customer, its appointee and the competent authority; alternative assurance if other clients are affected; cooperation in onsite inspections | The clause SaaS vendors negotiate hardest; see below |
| 30(3)(f) | Exit strategy with a mandatory adequate transition period | You keep serving them while they migrate |
Article 30(4) asks both sides to consider standard contractual clauses developed by public authorities. Financial entities must also maintain a written policy on these contracts, detailed in Commission Delegated Regulation (EU) 2024/1773. That is why bank addenda look so similar to each other.
Subcontracting: Delegated Regulation 2025/532
The regulatory technical standards on subcontracting ICT services that support critical or important functions were adopted on 24 March 2025 and published on 2 July 2025. Before agreeing that you may subcontract, the customer must be satisfied that you can select and monitor subcontractors, identify all of them in the chain, and pass down the same access and audit rights (Article 3). The contract must specify, among other things (Article 4):
- that you remain responsible for services provided by your subcontractors and monitor them;
- your reporting duties about subcontractors, and the location of data they process;
- that your subcontracts include business contingency plans, security standards, and the same audit and access rights for the financial entity and its authorities;
- continuity of service across the chain if a subcontractor fails.
For material changes to your subcontracting (Article 5), you must inform the customer "well in time", give a reasonable notice period, and only implement the change once the customer has approved it or not objected by the end of that period. The customer may terminate if you go ahead despite an objection, before the notice period ends, or subcontract something the contract does not allow (Article 6). If you swap sub-processors casually today, this is the process to change first.
Audit, access and pooled audits
Article 30(3)(e) speaks of "unrestricted rights of access, inspection and audit". For a multi-tenant SaaS, unrestricted physical access to shared infrastructure is rarely workable, and the law recognises that with "the right to agree on alternative assurance levels if other clients' rights are affected". Delegated Regulation 2024/1773 (Article 8) lists the methods a financial entity may use: its own or third-party audits, pooled audits organised with other customers, third-party certifications, and audit reports made available by you. But it may not rely on certifications or reports alone over time, and it keeps the contractual right to perform individual and pooled audits.
Practical approach: offer ISO 27001 certification and/or a SOC 2 Type II report as the first line, a structured evidence pack, and a clear procedure for on-site or remote audits (notice, scope, confidentiality, frequency, cost). Pooled audits among your financial customers keep the burden manageable. A microenterprise financial entity may agree that its audit rights are delegated to an independent third party appointed by you (Article 30(3), last subparagraph).
Incident support and the bank's reporting clock
Your customer must report major ICT-related incidents to its supervisor. Under Delegated Regulation (EU) 2025/301, the initial notification is due within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it. The intermediate report follows within 72 hours and the final report within one month. If your outage or breach is the incident, they can only meet that clock if you tell them quickly. Expect clauses that require notification within a few hours, named contacts available around the clock, and cooperation with root-cause analysis. Article 30(2)(f) requires incident assistance at no extra cost or at a price agreed in advance.
Threat-led penetration testing (TLPT)
Significant financial entities must run threat-led penetration tests on live production systems at least every three years (Articles 26 and 27, detailed in Delegated Regulation (EU) 2025/1190, based on TIBER-EU). Where your service supports a critical or important function in scope, you must "participate and fully cooperate" (Article 30(3)(d)). Where your participation could harm the quality or security of services to clients outside DORA, or the confidentiality of their data, you and the customer can agree in writing that you contract an external tester directly for a pooled TLPT covering several financial entities, directed by one of them (Article 26(4)). Agree in advance on rules of engagement, safe windows, data protection and who carries what cost. Most SME vendors will never be in a TLPT, but the clause will still be in the contract.
Exit strategies
Financial entities must have tested exit plans for every service that supports critical or important functions (Article 28(8)). They must be able to leave without disruption to their business, to regulatory compliance or to their clients. Your contract will therefore include a transition period during which you continue the service while they migrate (Article 30(3)(f)), plus data return in an accessible format (30(2)(d)). Have a documented export (format, completeness, timing), an off-boarding runbook and a transition price ready. "We delete everything 30 days after termination" will not pass.
CTPP oversight, and why you are probably not one
DORA also creates direct EU oversight of critical ICT third-party service providers (CTPPs). The ESAs designate them on the basis of systemic impact, how many systemically important institutions rely on them, reliance for critical functions, and substitutability (Article 31(2)). For the systemic-impact criterion, Delegated Regulation (EU) 2024/1502 starts with a quantitative test: the provider supports critical or important functions of at least 10% of a category of financial entities, both by number and by total assets.
On 18 November 2025 the ESAs published the first list of 19 CTPPs, including Amazon Web Services, Microsoft, Google Cloud, Oracle, SAP, IBM, Accenture, Capgemini, Bloomberg, Equinix and Deutsche Telekom. Some providers are excluded by law, including those serving financial entities in only one Member State (Article 31(8)). Providers can also apply to be designated voluntarily (Article 31(11)).
For a typical SME vendor this means: you are not a CTPP and are not directly overseen by a Lead Overseer. Your obligations come from your contracts. But if you host on a designated CTPP, that dependency will appear in your customers' registers as part of your subcontracting chain.
Contract clause checklist
- Service description and sub-processor list that match reality (30(2)(a))
- Hosting and processing regions named, with advance notice of changes (30(2)(b))
- Security annex covering availability, integrity, authenticity and confidentiality (30(2)(c))
- Data return and export format, including on insolvency (30(2)(d))
- SLA in the contract, with quantitative targets if the service is critical (30(2)(e), 30(3)(a))
- Incident notification window you can actually meet, and incident assistance pricing (30(2)(f))
- Cooperation with supervisors and resolution authorities (30(2)(g))
- Termination triggers and notice periods aligned with Article 28(7) (30(2)(h))
- Training participation terms (30(2)(i))
- Material-development notice obligations (30(3)(b))
- Tested BCP/DR and evidence on request (30(3)(c))
- TLPT cooperation, including pooled testing and cost allocation (30(3)(d))
- Audit clause: methods, pooled audits, notice, frequency, confidentiality, alternative assurance (30(3)(e))
- Exit transition period and transition support (30(3)(f))
- Subcontracting conditions, material-change notice period and objection right (RTS 2025/532)
- LEI or EUID provided for you and for subcontractors underpinning critical services (ITS 2024/2956)
What your bank customer will ask you
- Your LEI or EUID, legal entity, group structure and ownership.
- Which functions your service supports, and your view on criticality.
- Where data is processed and stored, per region, including backups and support access.
- Your full subcontractor chain for the service, with locations and LEIs, plus your process for changing it.
- Certifications and reports: ISO 27001 certificate and Statement of Applicability, SOC 2 Type II, penetration test summaries.
- Your incident response plan, notification times and a named 24/7 contact.
- BCP/DR: RTO and RPO, last test date and results.
- Vulnerability and patch management timelines.
- Access control and MFA for your staff, background checks, and privileged access management.
- Exit: export formats, transition support, retention after termination.
- Financial soundness and insurance, especially for critical services.
- Willingness to accept audit and inspection, including by their supervisor.
Keep the evidence your financial customers ask for in one place
Dazr Compliance gives SaaS vendors the DORA and ISO 27001 frameworks side by side, a vendor register for your sub-processors and their locations, an incident register with timestamps you can share, BCP test evidence with expiry alerts, and read-only auditor access for pooled audits.
FAQ
Does DORA apply directly to my SaaS company?
Not unless you are a financial entity yourself or are designated as a critical ICT third-party service provider. DORA's obligations for ordinary ICT providers reach you through the contracts that financial entities must sign under Articles 28 and 30.
Can I refuse unrestricted audit rights?
For services that support critical or important functions, the customer is legally required to have them. You can negotiate how they are exercised: pooled audits, certifications and reports as a first line, notice periods and confidentiality. Article 30(3)(e)(ii) allows alternative assurance levels where other clients' rights are affected.
Do I need an LEI?
Financial entities must identify ICT providers that are legal persons by LEI or EUID in their register of information (Implementing Regulation (EU) 2024/2956). An LEI is often the simplest way to make that easy for them.
How quickly must I report an incident to a bank customer?
DORA does not set a number for you, but your customer must notify its supervisor within 4 hours of classifying an incident as major and within 24 hours of becoming aware of it. Contracts therefore typically ask for notification within a few hours.
Related
Sources (as of 1 October 2026)
- Regulation (EU) 2022/2554 (DORA), Articles 26 to 31.
- Commission Implementing Regulation (EU) 2024/2956: register of information templates.
- Commission Delegated Regulation (EU) 2025/532: subcontracting of ICT services supporting critical or important functions.
- Commission Delegated Regulation (EU) 2024/1773: contractual arrangements policy.
- Commission Delegated Regulation (EU) 2025/301: major incident reporting time limits.
- Commission Delegated Regulation (EU) 2025/1190: threat-led penetration testing.
- Commission Delegated Regulation (EU) 2024/1502: CTPP designation criteria.
- ESAs: designation of critical ICT third-party providers, 18 November 2025.
This guide explains DORA as of 1 October 2026 for ICT providers and is not legal advice. Contract terms depend on your customer's classification and supervisor.