SEO

DORA Compliance for Non-Financial SaaS: Why It Affects You Anyway

Technical SEO – speed and site structure concept



The bank problem that becomes your problem

DORA compliance for SaaS is not optional if a single EU bank, insurer, payment institution, or investment firm uses your product. The Digital Operational Resilience Act (Regulation EU 2022/2554) targets EU financial institutions directly, but its Chapter V forces those institutions to push binding security, audit, and incident-response obligations into every ICT vendor contract they hold. If your product sits inside a regulated entity's operational stack, DORA reaches you through that contract, regardless of where your company is incorporated.

Key takeaways

  • DORA applied on January 17, 2025, with no grace period. Financial clients were expected to have compliant vendor contracts in place from day one.

  • Twenty categories of EU financial entities must push DORA obligations into every ICT vendor contract, including SaaS providers of any size.

  • Formally designated critical ICT third-party providers face direct EU oversight and fines of up to 1% of average daily worldwide turnover per day.

  • Monthly SaaS breaches rose 300% year over year in the period leading to DORA, which is why vendor security became a regulated concern rather than a procurement footnote.



What is DORA and who is it written for?

DORA is an EU regulation requiring banks, insurers, investment firms, payment institutions, and sixteen other financial entity categories to maintain digital operational resilience. It became applicable on January 17, 2025. There was no transition window and no soft launch.

The regulation was drafted to fix a specific gap. EU financial markets had grown deeply dependent on third-party technology, and no standardized resilience requirements existed across the bloc. The European legislator treated vendor security as a systemic issue rather than a private IT matter, citing a sharp rise in SaaS-targeted incidents in the years before adoption (Obsidian Security).

DORA does not distinguish between on-premises deployments and cloud-delivered software. If you provide an ICT service used by a covered entity, you are inside the regulation's reach. Crypto-asset service providers and crowdfunding platforms are named explicitly in DORA's scope article, which surprises most SaaS founders who assumed "financial services" meant retail banks.



Why does DORA compliance for SaaS apply if you are not a bank?

The mechanism is contractual. DORA's Chapter V requires every regulated financial entity to include mandatory clauses in all ICT vendor agreements, covering audit rights, incident-support timelines, data-security standards, sub-processor disclosure, and exit planning. The contract between your SaaS product and a regulated bank is itself a DORA compliance instrument, whether or not you drafted it that way.

Article 30 (formerly numbered Article 28 in earlier drafts, and still referenced that way in most vendor documentation) sets the minimum contractual provisions: service levels, security requirements, audit and inspection rights, termination triggers, and data-location commitments. Financial entities must also maintain a full register of ICT dependencies, updated continuously, and submit that register to their competent authority on request. Every vendor you contract through, and every sub-processor you rely on, is inventoried somewhere in Frankfurt, Paris, or Dublin.

The obligation flows downward. A SaaS vendor that relies on another cloud service for core functionality must contractually bind that sub-processor to equivalent standards, or the primary vendor cannot honestly sign the client's addendum. NIS2 covers overlapping ground for a broader set of essential services. If you have already worked through that framework, several DORA requirements will look familiar (see the NIS2 practical compliance checklist).



What is a critical ICT third-party provider?

The European Supervisory Authorities (EBA, EIOPA, and ESMA) can formally designate ICT vendors as critical ICT third-party providers, known as CTPPs. Once designated, a company faces direct EU regulatory oversight: on-site inspections, binding remediation timelines, and fines of up to 1% of average daily worldwide turnover for each day of continued non-compliance.

Designation is not a checklist. Criteria include the vendor's systemic importance to EU financial stability, how substitutable the service is, and how concentrated the financial-client base is on that vendor. Hyperscalers (AWS, Microsoft Azure, Google Cloud) and large SaaS platforms with heavy penetration into EU financial services are the primary candidates. The Joint Oversight Network administers the CTPP program, and the first formal designation decisions began landing in 2025.

Most SaaS vendors will never receive a CTPP designation. That does not exempt you. The contractual obligations pushed down through every regulated client contract still apply, and being small is not a defence when a compliance officer sends over a 40-page addendum with a signature deadline.



What will your financial services clients require from your SaaS?

Financial entities under DORA must pass specific obligations through to their ICT vendors via contract. SaaS companies selling into EU financial services now face security questionnaires, audit clauses, incident-response SLAs, and formal exit documentation that were not part of standard commercial software agreements before 2025.

The table below maps what DORA demands of the financial entity, and what that entity will contractually push down to you as their vendor.

DORA area

Financial entity obligation

What they will push to your SaaS

Incident reporting

Notify competent authority within 4 hours of major incident classification

Vendor notification window, often 2 hours or less

Threat-led penetration testing

Conduct TLPT at least every 3 years

Inclusion of vendor infrastructure in client-driven test scope

Audit rights

Document and verify all ICT dependencies

On-site or remote audit rights for the client or its approved third party

Exit strategy

Maintain documented exit plans for critical vendors

Data export, migration support, and a defined transition period

Sub-outsourcing

Track all sub-processors

Disclose sub-processors and bind them to equivalent standards

Atlassian documented its DORA posture publicly during 2024 and 2025 because Jira and Confluence sit inside operations teams across EU financial institutions (Atlassian Trust Center). That kind of transparency is now a sales asset. If your first pentest is coming and you have not seen one from the vendor side, the mechanics carry over to what a financial client will demand of you (how to survive your first pentest).



How do you assess whether your SaaS is in scope?

Three questions determine your exposure. First, do any paying customers fall under DORA's twenty financial entity categories? Second, are you providing operational ICT services or peripheral tooling? Third, how many financial clients depend on your product for regulated activities?

If the first answer is yes, the analysis does not stop there. Payment institutions and e-money institutions are frequently missed in customer-list reviews because they do not carry "bank" in their name. Map your customer base against DORA's scope directly, not against your internal industry taxonomy. Then classify your service function. Data storage, transaction processing, communication infrastructure, and security tooling attract higher scrutiny than scheduling or HR tools.

In the SaaS security reviews Gravidy has run this year, the pattern is consistent: founders assume a CRM or analytics tool is out of scope, then discover their contract with a Nordic bank already includes DORA clauses they never read. Operational dependency, not vendor size, determines the practical obligation level. If you already hold ISO 27001 or SOC 2, you have a starting position, but neither is a substitute (compare in ISO 27001 vs SOC 2).

If your financial clients sent contract addenda in late 2024, you are already inside the scope conversation whether you signed them or not.



Frequently Asked Questions



Does DORA apply to SaaS companies?

Yes, if your SaaS provides ICT services to EU-regulated financial entities. DORA does not require you to be a financial firm. It requires your financial clients to hold their technology vendors to specific resilience, security, and reporting standards, which they enforce through contract. If a bank, insurer, or payment institution uses your product, DORA applies to that relationship.



When did DORA take effect?

DORA became applicable on January 17, 2025, with no grace period. Financial entities were expected to have compliant ICT vendor contracts in place from day one, which means their vendors were expected to be ready too.



What is a critical ICT third-party provider under DORA?

A critical ICT third-party provider (CTPP) is an ICT vendor formally designated by the European Supervisory Authorities as systemically important to EU financial stability. CTPPs face direct regulatory oversight including on-site inspections and potential fines. Most SaaS vendors will not receive a CTPP designation, but they still face contractual compliance requirements through every EU financial client they serve.



What are DORA's reporting requirements for ICT incidents?

Financial entities must submit an initial major-incident notification to their competent authority within 4 hours of classification, an intermediate report within 72 hours, and a final root-cause report within one month. SaaS vendors do not report directly to regulators in most scenarios, but they must contractually support these timelines, which means vendor incident-response processes need to align with client reporting deadlines.



The compliance signal that shapes how buyers find you

DORA is not a bank problem that occasionally touches vendors. It is a vendor-compliance framework administered through financial institutions. Any SaaS company with EU financial services customers is operating inside DORA's scope, whether or not the current paperwork reflects that. The vendors that lose deals in 2026 will be the ones who cannot answer a compliance questionnaire from a procurement team in under two weeks.

Compliance readiness also shapes how buyers find you. A documented security posture, public compliance pages, and structured data around certifications all feed into how financial services teams discover and evaluate vendors before the first call.

Most B2B SaaS sites Gravidy audits have three to five compliance and trust signals sitting unsurfaced from both Google and AI-generated vendor comparisons. If you want to know which fixes are draining your traffic before a procurement team notices the gaps, book a Free SEO Audit Call. Thirty minutes, specific findings, no slide decks.

Further reading