Regulation (EU) 2022/2554 · applicable since 17 January 2025
DORA turns your IT vendor list into a supervisory register.
EU financial entities must register every contractual arrangement with ICT providers, secure it contractually and monitor it continuously. Their suppliers inherit the requirements through the contract.
The Digital Operational Resilience Act applies to banks, insurers, payment institutions and other financial entities in the EU. Chapter V deals exclusively with ICT third-party risk – from the data centre and the core banking system down to a small SaaS tool in a business unit.
For Swiss companies DORA is rarely a direct obligation, but very directly a market requirement. Supplying an EU financial entity as an IT provider, software house or outsourcing partner means delivering register data, accepting contract clauses and granting audit and access rights. Without that evidence you drop out of procurement.
Who is affected
- EU financial entities of any size, small institutions included under proportionality.
- Swiss groups with subsidiaries or branches in the EU financial sector.
- Swiss ICT providers serving EU financial entities – bound through their contracts.
What DORA demands in vendor governance
- Art. 28
- A register of information on all contractual arrangements with ICT third-party providers at entity, sub-consolidated and consolidated level.
- Art. 28
- A clear split of which services support critical or important functions.
- Art. 29
- Assessment of concentration risk before signing – subcontractors included.
- Art. 30
- Minimum contract content: service description, processing locations, access and audit rights, termination rights, service levels.
- Art. 28
- Documented exit strategies for services supporting critical or important functions.
How SCRM covers it
Register-ready data
Suppliers, contracts, functions and locations in structured fields instead of prose – exportable for the filing.
Criticality flags
Every service mapped to the function it supports and to a criticality level.
Subcontractors
Make the chain visible: who sits behind your provider, and where do dependencies pile up?
Contract attributes
Audit rights, notice periods and data locations as checked fields with reminders before expiry.
Frequently asked
Does DORA apply to Swiss companies?
Not directly. Swiss entities are caught where they operate through EU financial subsidiaries. As a supplier to an EU financial entity you are pulled in by contract – commercially the difference is small.
How is DORA different from ordinary outsourcing rules?
The level of detail and the filing duty. The register of information is a structured dataset with prescribed fields that goes to the supervisor. A Word list does not satisfy it.
We sell software to an EU bank. What lands on us?
Register data about your company, your subcontractors and processing locations, plus contract clauses on audit and access rights. Holding that in structured form wins you time in the procurement cycle.
As of July 2026. This page summarises regulation in plain language and is not legal advice.