DORA in practice: what regulators ask about your Software vendors
DORA has applied since January 17, 2025. It is now clear what regulators focus on: a complete register, substantiated classifications, and contracts that meet the requirements.
- July 14, 2026
- 5 min
The Digital Operational Resilience Act (DORA) has applied to financial institutions in the EU since January 17, 2025. A year and a half later, the focus has shifted from preparation to supervision. Particular attention is given to managing ICT service providers, including Software vendors.
What does DORA require?
A register of all ICT contracts. The so-called Register of Information includes every contractual agreement with an ICT service provider, detailing the service, classification, and subcontractor chain.
Insight into concentration risk. You must know where you are overly dependent on a single party for critical or important functions.
Contracts with the right provisions. DORA prescribes which clauses must be included in contracts, e.g., regarding access, audits, exit, and security.
Where it goes wrong in practice
An incomplete register. Large cloud and platform providers are usually well represented. The hundreds of smaller Software vendors and their subcontractors often are not.
Insufficiently substantiated classification. Why is a service critical or not? Supervisors want to see that assessment documented.
Contracts not yet updated. Many contracts predate DORA and have never been renegotiated to include required provisions.
Critical providers under direct supervision
On November 18, 2025, European supervisors designated the first 19 critical ICT service providers, including AWS, Microsoft, Google Cloud, Oracle, and SAP. They are subject to direct European supervision. This does not exempt your organization from its own obligations: you remain responsible for your register and contracts.
What can you do now?
Compare your register with your actual Software landscape, including tools purchased outside IT.
Record per service why it is considered critical or not.
Use each renewal to add missing contract clauses.
Reduce the number of Software vendors where possible: fewer parties mean a more manageable register.
How SoftVaro helps
SoftVaro maps your entire Software portfolio, including the long tail often missing in registers. At every renewal, we include the terms your organization needs. This article is not legal advice; coordinate DORA implementation with your compliance or legal department.
Frequently Asked Questions
The most asked questions about this topic.
Should small Software vendors also be included in the register?
The register covers all contractual agreements with ICT service providers. Smaller Software vendors are often overlooked.
What does it mean if my supplier is designated critical?
That supplier then falls under direct European supervision. Your own obligations, such as the register and contractual agreements, remain in place.
Ready to save on software?
SoftVaro negotiates the best deal on your behalf with over 4,000 suppliers. Independent, transparent, within 24 hours.