Your customer is a financial entity and asks DORA questions
Do you provide software or IT services to a bank, insurer, payment institution or investment firm? Then you will increasingly get questions that come from DORA, the EU Digital Operational Resilience Act. DORA has applied since 17 January 2025 and directly affects you as an ICT provider.
Why you receive these questions
DORA requires financial entities to manage the risk of their ICT providers. They must keep a register of all contracts with ICT providers, assess risks before they sign, and include fixed terms in the contract. Those requirements reach you as a questionnaire, a due diligence call and a contract annex.
What DORA requires in every ICT contract
Article 30 of DORA lists terms that must be in every contract with an ICT provider. Expect questions about all of them:
| Topic | What must be covered |
|---|---|
| Description of the service | A full description of what you provide |
| Locations | Where the service is provided and where data is processed |
| Data protection | Provisions on availability, integrity, confidentiality and personal data |
| Getting data back | Access to, return and recovery of data if you become insolvent or stop |
| Service levels | A description of your service levels |
| Incident assistance | Assistance with ICT incidents, at no cost or at a cost agreed in advance |
| Cooperation with supervisors | Full cooperation with the competent authorities |
| Termination | Termination rights and minimum notice periods |
| Awareness | Taking part in the customer's security awareness and resilience training |
Extra requirements for critical or important functions
If your service supports a critical or important function of the customer, the requirements go further. Think of precise service levels with measurable targets, notice obligations for developments that may affect your service, tested contingency plans, cooperation in threat-led penetration testing, unrestricted audit and inspection rights, and an exit strategy with a transition period. Ask your customer early whether your service is considered critical or important. That decides how heavy the questionnaire gets.
What the questionnaire itself covers
- information security policy, certifications and audit reports
- where your data is and which sub-processors and subcontractors you use
- business continuity: how fast you recover and when you last tested it
- incident management and how quickly you inform the customer
- exit: how the customer gets its data back and how a switch works
- your own financial and organisational stability
How to approach it
- Ask which function you support. Critical or important, or not. That sets the depth.
- Check against your contract. Every promise in the questionnaire must be in your contract or SLA, or be able to go in.
- Describe your exit concretely. In what format does the customer get its data back, and how fast?
- Show your continuity. A report of your last recovery test says more than a plan.
- Be honest about gaps. An open item with a plan and a date is stronger than a promise you cannot keep.
How Holdvero helps
We complete the questionnaire based on your own documentation, with the source for every answer. What you cannot support becomes an open item instead of a “yes”. Up to 150 questions this falls under Questionnaire Rescue (€695, 3–5 working days); DORA requests through a portal or with many annexes become a complex questionnaire. Holdvero does not provide certification or legal advice; have contract wording reviewed by your own lawyer.
Frequently asked questions
Am I as a supplier in scope of DORA myself?
DORA is aimed at financial entities. You get the requirements through your customer and the contract. Only providers designated as critical by the European supervisors are supervised directly.
Do I need ISO 27001 certification?
DORA does not require suppliers to be certified. A certificate or audit report does help as evidence. Without one, you show what you have arranged with policies, procedures and test results.
What is the register of information?
A record the financial entity keeps of all its contracts with ICT providers. That is why your customer asks for details about you, your service and your subcontractors.
Do I need to change my contract?
Often yes, if your standard contract does not cover the Article 30 terms. Have a lawyer review it; Holdvero does not provide legal advice.
Need help with your customer's DORA questions?
Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.
Get a fixed price