Skip to content
Compliance guide

DORA explained: impact on Software procurement in the financial sector

DORA comes into effect on 17 January 2025 and fundamentally changes how financial organisations procure and contract Software. Here is what you need to know about the five pillars, the contractual requirements and the impact on managing Software manufacturers.

  • 9 September 2025
  • 5 min
  • DORA – Digital Operational Resilience Act

DORA, the Digital Operational Resilience Act, has applied across the EU since 17 January 2025. For financial organisations, digital resilience is no longer just an internal IT issue but a legal obligation under supervision.

What is DORA?

DORA is an EU Regulation and therefore directly applicable without transposition into national law. The Regulation applies to a broad range of financial entities, from banks and insurers to investment firms, payment institutions and crypto service providers.

The five pillars

  • ICT risk management: a framework to identify, classify and control ICT risks.

  • Incident reporting: major ICT incidents must be reported within strict timeframes.

  • Testing digital resilience: periodic testing of critical systems.

  • Management of ICT third-party risks: contractual requirements, a register and concentration risk analysis.

  • Information sharing: sharing threat intelligence within the sector.

What does DORA mean for Software procurement?

The fourth pillar directly affects Software procurement:

  • Contractual minimum requirements: ICT contracts must include provisions regarding, among other things, service provision, incident notification, audit rights, exit, data location and continuity.

  • Register of Information: an up-to-date and complete register of all contractual agreements with ICT service providers.

  • Concentration risk: excessive dependency on one party must be assessed.

  • Subcontractors: the parties your Software manufacturers rely on must also be accounted for.

Read in DORA in practice what supervisors are currently focusing on.

How SoftVaro helps

SoftVaro maps your Software landscape, including the long tail often missing from the register. With every renewal, we include the contract provisions required by DORA. This article is not legal advice; please coordinate application with your compliance or legal department.

Frequently Asked Questions

The most commonly asked questions on this topic.

Who does DORA apply to?

DORA applies to a broad range of financial entities in the EU, such as banks, insurers, investment firms, payment institutions and crypto service providers. ICT service providers encounter DORA requirements through their contracts with these clients.

Does DORA also apply to my Software vendor?

Indirectly, yes. Your organisation must contractually embed DORA requirements with the Software manufacturers you use. Providers designated as critical are furthermore subject to direct European supervision.

What are the penalties for non-compliance with DORA?

Penalties for financial entities are determined by national regulators. For critical ICT service providers, the European regulator has its own enforcement measures.

Ready to save on software?

SoftVaro negotiates the best deal for you with over 4,000 suppliers. Independent, transparent, within 24 hours.

More from the knowledge base

Change language

More pages

Choose per category what we may place. Strictly necessary cookies cannot be turned off.

  • Third-party analytics (Google)

    Google Analytics 4 for product improvement: page views, time on page, button clicks. In addition to our own privacy-friendly Umami (always active, no consent required). Data is transferred to Google in the US — under Standard Contractual Clauses.

  • Marketing

    Leadinfo identifies companies visiting the site by IP address, for B2B lead follow-up (no personal data of individual visitors). Google Ads sets advertising cookies for remarketing and conversion measurement; this transfers data to Google in the US under the Standard Contractual Clauses.

  • Strictly necessary

    For basic site functionality: remembering your language preference, rate-limiting, session handling. No third parties.

    Always on

No Umami measurement

Umami qualifies for the analytics exception and does not require consent, but you can opt out of being measured.