DORA in practice: what supervisors ask about your Software manufacturers
DORA applies since 17 January 2025. It is now clear what supervisors focus on: a complete register, substantiated classifications and contracts that meet requirements.
- 14 July 2026
- 5 min
The Digital Operational Resilience Act (DORA) has applied to financial institutions in the EU since 17 January 2025. A year and a half later, the focus has shifted from preparation to supervision. Particular attention is given to the management of ICT service providers, including Software vendors.
What does DORA require?
A register of all ICT contracts. The so-called Register of Information contains every contractual agreement with an ICT service provider, including details such as the service, classification, and chain of subcontractors.
Insight into concentration risk. You must be aware of where you are overly dependent on one party for critical or important functions.
Contracts with appropriate stipulations. DORA prescribes which clauses must be included in contracts, such as access, audits, exit, and security.
Where things go wrong in practice
An incomplete register. The major cloud and platform providers are usually well recorded. Hundreds of smaller Software vendors and their subcontractors are often missing.
Insufficiently substantiated classification. Why is a service critical or not? Regulators want to see that assessment documented.
Contracts not yet updated. Many contracts predate DORA and have never been renegotiated to include the required provisions.
Critical providers under direct supervision
On 18 November 2025, European regulators designated the first 19 critical ICT service providers, including AWS, Microsoft, Google Cloud, Oracle, and SAP. They fall under direct European supervision. This does not exempt your organisation from its own obligations: you remain responsible for your register and contracts.
What can you do now?
Compare your register with your actual Software landscape, including tools procured outside IT.
Record for each service why it is considered critical or not.
Use each renewal to add missing contract clauses.
Reduce the number of Software vendors where possible: fewer parties means a more manageable register.
How SoftVaro helps
SoftVaro maps your complete Software portfolio, including the long tail that is often missing in the register. At each renewal, we incorporate the terms your organisation needs. This article is not legal advice; coordinate the application of DORA with your compliance or legal department.
Frequently Asked Questions
The most commonly asked questions on this topic.
Should even small Software manufacturers be in the register?
The register includes all contractual agreements with ICT service providers. It is precisely smaller Software manufacturers that are often overlooked.
What does it mean if my supplier is designated as critical?
That supplier then falls under direct European supervision. Your own obligations, such as the register and contractual agreements, remain fully in place.
Ready to save on software?
SoftVaro negotiates the best deal for you with over 4,000 suppliers. Independent, transparent, within 24 hours.