What DORA actually regulates
DORA is a Regulation, so it applies directly across EU member states without transposition. It targets financial entities and, through them, the ICT third-party service providers they rely on. The Regulation covers five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk, and information sharing.
For a SaaS vendor, the direct legal duty sits with your customer. The practical duty flows to you through contract, evidence requests, and, for a small number of designated providers, direct oversight by European Supervisory Authorities.
Where FinTech SaaS gets pulled in
Regulated buyers must maintain a register of information covering every ICT service supporting a critical or important function. If your product supports a function the buyer cannot lose without material harm to customers, markets, or their own viability, you sit inside that register with heightened obligations.
- Core banking, payments, trading, custody, and clearing platforms are almost always in scope.
- Fraud, KYC, AML, and transaction monitoring vendors are commonly treated as critical or important.
- Data platforms, analytics, and workflow tooling can qualify depending on how the buyer uses them.
Sub-outsourcing matters. If you rely on a hyperscaler, a data processor, or a specialist model provider, the buyer expects that chain to be visible and controlled.
Contractual articles that change buyer conversations
DORA prescribes contractual content for ICT services supporting critical or important functions. Expect standard clauses covering service descriptions, locations of processing, security and availability requirements, incident cooperation, audit and access rights, sub-outsourcing conditions, and exit strategies.
Treating these as bespoke redlines costs time on every deal. Publishing a DORA-aligned addendum, an exit plan, and a subcontractor register up front moves a vendor faster through legal review and wins on operational credibility.
Operational resilience expectations
Buyers will translate their own obligations into vendor requirements. That means a documented ICT risk framework, an incident taxonomy with defined severity thresholds, tested continuity and recovery plans, and evidence of resilience testing at a cadence proportionate to your role.
Incident cooperation is a live obligation. Buyers must classify and report major ICT-related incidents within tight windows. Your incident response process needs to feed their timeline, not your own comfort. Named contacts, agreed communication channels, and a template for structured incident notifications reduce friction under stress.
Threat-led penetration testing applies to a narrow set of financial entities, but expect requests for evidence of independent security testing, red team exercises where relevant, and remediation tracking.
A 2026 readiness sequence for SaaS vendors
Quarter 1: confirm which customers treat you as supporting a critical or important function. Draft or refresh your DORA addendum. Build a subcontractor register with location, function, and criticality.
Quarter 2: align your incident taxonomy with buyer classification criteria. Define notification templates, named contacts, and cooperation commitments. Document your ICT risk management framework in a form a buyer can review.
Quarter 3: run and evidence resilience testing appropriate to your role: recovery exercises, failover tests, incident tabletops, and independent security testing. Close findings with owners and dates.
Quarter 4: package a buyer evidence pack covering scope, controls, testing, incidents, subcontractors, and exit. Track buyer requests to spot new expectations early. Refresh the register of information inputs your customers ask for.
Common questions
- Am I in scope as a FinTech SaaS vendor?
- DORA regulates financial entities directly, but ICT third-party service providers supporting their critical or important functions inherit obligations through contract. If regulated buyers rely on you for a function they must keep running, you are pulled in by their compliance perimeter.
- Do I need my own DORA programme or can I ride buyer contracts?
- Buyer contracts will set the floor. A structured internal programme (register of information, incident taxonomy, resilience testing, exit plans) reduces contract negotiation time and prevents inconsistent answers across customers. Vendors flagged as supporting critical or important functions need more than contract compliance.
- What evidence do regulated buyers ask for in 2026?
- Expect requests for your ICT risk framework summary, incident classification and reporting procedure, subcontracting register, resilience testing results, business continuity artefacts, and named accountable owners. A pre-assembled buyer evidence pack shortens procurement noticeably.
