Skip to content
Article

DORA in practice: what regulators ask about your Software vendors

DORA has applied since January 17, 2025. It is now clear what regulators focus on: a complete register, substantiated classifications, and contracts that meet the requirements.

  • July 14, 2026
  • 5 min

The Digital Operational Resilience Act (DORA) has applied to financial institutions in the EU since January 17, 2025. A year and a half later, the focus has shifted from preparation to supervision. Particular attention is given to managing ICT service providers, including Software vendors.

What does DORA require?

  • A register of all ICT contracts. The so-called Register of Information includes every contractual agreement with an ICT service provider, detailing the service, classification, and subcontractor chain.

  • Insight into concentration risk. You must know where you are overly dependent on a single party for critical or important functions.

  • Contracts with the right provisions. DORA prescribes which clauses must be included in contracts, e.g., regarding access, audits, exit, and security.

Where it goes wrong in practice

An incomplete register. Large cloud and platform providers are usually well represented. The hundreds of smaller Software vendors and their subcontractors often are not.

Insufficiently substantiated classification. Why is a service critical or not? Supervisors want to see that assessment documented.

Contracts not yet updated. Many contracts predate DORA and have never been renegotiated to include required provisions.

Critical providers under direct supervision

On November 18, 2025, European supervisors designated the first 19 critical ICT service providers, including AWS, Microsoft, Google Cloud, Oracle, and SAP. They are subject to direct European supervision. This does not exempt your organization from its own obligations: you remain responsible for your register and contracts.

What can you do now?

  1. Compare your register with your actual Software landscape, including tools purchased outside IT.

  2. Record per service why it is considered critical or not.

  3. Use each renewal to add missing contract clauses.

  4. Reduce the number of Software vendors where possible: fewer parties mean a more manageable register.

How SoftVaro helps

SoftVaro maps your entire Software portfolio, including the long tail often missing in registers. At every renewal, we include the terms your organization needs. This article is not legal advice; coordinate DORA implementation with your compliance or legal department.

Frequently Asked Questions

The most asked questions about this topic.

Should small Software vendors also be included in the register?

The register covers all contractual agreements with ICT service providers. Smaller Software vendors are often overlooked.

What does it mean if my supplier is designated critical?

That supplier then falls under direct European supervision. Your own obligations, such as the register and contractual agreements, remain in place.

Ready to save on software?

SoftVaro negotiates the best deal on your behalf with over 4,000 suppliers. Independent, transparent, within 24 hours.

More from the knowledge base

Change language

More pages

Choose per category what we may place. Strictly necessary cookies cannot be turned off.

  • Third-party analytics (Google)

    Google Analytics 4 for product improvement: page views, time on page, button clicks. In addition to our own privacy-friendly Umami (always active, no consent required). Data is transferred to Google in the US — under Standard Contractual Clauses.

  • Marketing

    Leadinfo identifies companies visiting the site by IP address, for B2B lead follow-up (no personal data of individual visitors). Google Ads sets advertising cookies for remarketing and conversion measurement; this transfers data to Google in the US under the Standard Contractual Clauses.

  • Strictly necessary

    For basic site functionality: remembering your language preference, rate-limiting, session handling. No third parties.

    Always on

No Umami measurement

Umami qualifies for the analytics exception and does not require consent, but you can opt out of being measured.