Skip to content
Article

DORA in practice: what supervisors ask about your Software manufacturers

DORA applies since 17 January 2025. It is now clear what supervisors focus on: a complete register, substantiated classifications and contracts that meet requirements.

  • 14 July 2026
  • 5 min

The Digital Operational Resilience Act (DORA) has applied to financial institutions in the EU since 17 January 2025. A year and a half later, the focus has shifted from preparation to supervision. Particular attention is given to the management of ICT service providers, including Software vendors.

What does DORA require?

  • A register of all ICT contracts. The so-called Register of Information contains every contractual agreement with an ICT service provider, including details such as the service, classification, and chain of subcontractors.

  • Insight into concentration risk. You must be aware of where you are overly dependent on one party for critical or important functions.

  • Contracts with appropriate stipulations. DORA prescribes which clauses must be included in contracts, such as access, audits, exit, and security.

Where things go wrong in practice

An incomplete register. The major cloud and platform providers are usually well recorded. Hundreds of smaller Software vendors and their subcontractors are often missing.

Insufficiently substantiated classification. Why is a service critical or not? Regulators want to see that assessment documented.

Contracts not yet updated. Many contracts predate DORA and have never been renegotiated to include the required provisions.

Critical providers under direct supervision

On 18 November 2025, European regulators designated the first 19 critical ICT service providers, including AWS, Microsoft, Google Cloud, Oracle, and SAP. They fall under direct European supervision. This does not exempt your organisation from its own obligations: you remain responsible for your register and contracts.

What can you do now?

  1. Compare your register with your actual Software landscape, including tools procured outside IT.

  2. Record for each service why it is considered critical or not.

  3. Use each renewal to add missing contract clauses.

  4. Reduce the number of Software vendors where possible: fewer parties means a more manageable register.

How SoftVaro helps

SoftVaro maps your complete Software portfolio, including the long tail that is often missing in the register. At each renewal, we incorporate the terms your organisation needs. This article is not legal advice; coordinate the application of DORA with your compliance or legal department.

Frequently Asked Questions

The most commonly asked questions on this topic.

Should even small Software manufacturers be in the register?

The register includes all contractual agreements with ICT service providers. It is precisely smaller Software manufacturers that are often overlooked.

What does it mean if my supplier is designated as critical?

That supplier then falls under direct European supervision. Your own obligations, such as the register and contractual agreements, remain fully in place.

Ready to save on software?

SoftVaro negotiates the best deal for you with over 4,000 suppliers. Independent, transparent, within 24 hours.

More from the knowledge base

Change language

More pages

Choose per category what we may place. Strictly necessary cookies cannot be turned off.

  • Third-party analytics (Google)

    Google Analytics 4 for product improvement: page views, time on page, button clicks. In addition to our own privacy-friendly Umami (always active, no consent required). Data is transferred to Google in the US — under Standard Contractual Clauses.

  • Marketing

    Leadinfo identifies companies visiting the site by IP address, for B2B lead follow-up (no personal data of individual visitors). Google Ads sets advertising cookies for remarketing and conversion measurement; this transfers data to Google in the US under the Standard Contractual Clauses.

  • Strictly necessary

    For basic site functionality: remembering your language preference, rate-limiting, session handling. No third parties.

    Always on

No Umami measurement

Umami qualifies for the analytics exception and does not require consent, but you can opt out of being measured.