DORA explained: impact on Software procurement in the financial sector
DORA comes into effect on 17 January 2025 and fundamentally changes how financial organisations procure and contract Software. Here is what you need to know about the five pillars, the contractual requirements and the impact on managing Software manufacturers.
- 9 September 2025
- 5 min
- DORA – Digital Operational Resilience Act
DORA, the Digital Operational Resilience Act, has applied across the EU since 17 January 2025. For financial organisations, digital resilience is no longer just an internal IT issue but a legal obligation under supervision.
What is DORA?
DORA is an EU Regulation and therefore directly applicable without transposition into national law. The Regulation applies to a broad range of financial entities, from banks and insurers to investment firms, payment institutions and crypto service providers.
The five pillars
ICT risk management: a framework to identify, classify and control ICT risks.
Incident reporting: major ICT incidents must be reported within strict timeframes.
Testing digital resilience: periodic testing of critical systems.
Management of ICT third-party risks: contractual requirements, a register and concentration risk analysis.
Information sharing: sharing threat intelligence within the sector.
What does DORA mean for Software procurement?
The fourth pillar directly affects Software procurement:
Contractual minimum requirements: ICT contracts must include provisions regarding, among other things, service provision, incident notification, audit rights, exit, data location and continuity.
Register of Information: an up-to-date and complete register of all contractual agreements with ICT service providers.
Concentration risk: excessive dependency on one party must be assessed.
Subcontractors: the parties your Software manufacturers rely on must also be accounted for.
Read in DORA in practice what supervisors are currently focusing on.
How SoftVaro helps
SoftVaro maps your Software landscape, including the long tail often missing from the register. With every renewal, we include the contract provisions required by DORA. This article is not legal advice; please coordinate application with your compliance or legal department.
Frequently Asked Questions
The most commonly asked questions on this topic.
Who does DORA apply to?
DORA applies to a broad range of financial entities in the EU, such as banks, insurers, investment firms, payment institutions and crypto service providers. ICT service providers encounter DORA requirements through their contracts with these clients.
Does DORA also apply to my Software vendor?
Indirectly, yes. Your organisation must contractually embed DORA requirements with the Software manufacturers you use. Providers designated as critical are furthermore subject to direct European supervision.
What are the penalties for non-compliance with DORA?
Penalties for financial entities are determined by national regulators. For critical ICT service providers, the European regulator has its own enforcement measures.
Ready to save on software?
SoftVaro negotiates the best deal for you with over 4,000 suppliers. Independent, transparent, within 24 hours.