Skip to content

Your customer is a financial entity and asks DORA questions

Do you provide software or IT services to a bank, insurer, payment institution or investment firm? Then you will increasingly get questions that come from DORA, the EU Digital Operational Resilience Act. DORA has applied since 17 January 2025 and directly affects you as an ICT provider.

Why you receive these questions

DORA requires financial entities to manage the risk of their ICT providers. They must keep a register of all contracts with ICT providers, assess risks before they sign, and include fixed terms in the contract. Those requirements reach you as a questionnaire, a due diligence call and a contract annex.

What DORA requires in every ICT contract

Article 30 of DORA lists terms that must be in every contract with an ICT provider. Expect questions about all of them:

TopicWhat must be covered
Description of the serviceA full description of what you provide
LocationsWhere the service is provided and where data is processed
Data protectionProvisions on availability, integrity, confidentiality and personal data
Getting data backAccess to, return and recovery of data if you become insolvent or stop
Service levelsA description of your service levels
Incident assistanceAssistance with ICT incidents, at no cost or at a cost agreed in advance
Cooperation with supervisorsFull cooperation with the competent authorities
TerminationTermination rights and minimum notice periods
AwarenessTaking part in the customer's security awareness and resilience training

Extra requirements for critical or important functions

If your service supports a critical or important function of the customer, the requirements go further. Think of precise service levels with measurable targets, notice obligations for developments that may affect your service, tested contingency plans, cooperation in threat-led penetration testing, unrestricted audit and inspection rights, and an exit strategy with a transition period. Ask your customer early whether your service is considered critical or important. That decides how heavy the questionnaire gets.

What the questionnaire itself covers

How to approach it

  1. Ask which function you support. Critical or important, or not. That sets the depth.
  2. Check against your contract. Every promise in the questionnaire must be in your contract or SLA, or be able to go in.
  3. Describe your exit concretely. In what format does the customer get its data back, and how fast?
  4. Show your continuity. A report of your last recovery test says more than a plan.
  5. Be honest about gaps. An open item with a plan and a date is stronger than a promise you cannot keep.

How Holdvero helps

We complete the questionnaire based on your own documentation, with the source for every answer. What you cannot support becomes an open item instead of a “yes”. Up to 150 questions this falls under Questionnaire Rescue (€695, 3–5 working days); DORA requests through a portal or with many annexes become a complex questionnaire. Holdvero does not provide certification or legal advice; have contract wording reviewed by your own lawyer.

Frequently asked questions

Am I as a supplier in scope of DORA myself?

DORA is aimed at financial entities. You get the requirements through your customer and the contract. Only providers designated as critical by the European supervisors are supervised directly.

Do I need ISO 27001 certification?

DORA does not require suppliers to be certified. A certificate or audit report does help as evidence. Without one, you show what you have arranged with policies, procedures and test results.

What is the register of information?

A record the financial entity keeps of all its contracts with ICT providers. That is why your customer asks for details about you, your service and your subcontractors.

Do I need to change my contract?

Often yes, if your standard contract does not cover the Article 30 terms. Have a lawyer review it; Holdvero does not provide legal advice.

Need help with your customer's DORA questions?

Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.

Get a fixed price
Cover: NIS2 checklist for suppliers
Free: NIS2 checklist for suppliersThe 7 topics that keep coming back, with the evidence to have ready for each.
Download the checklist