DORA: What It Is and Why a Bank or Insurer Is Asking
If your customer is a bank, insurer, payment institution or fintech, this explains where the questionnaire comes from.
DORA (EU Regulation 2022/2554) is the Digital Operational Resilience Act, in force since 17 January 2025. Unlike NIS2, it’s a directly-applicable regulation — the same text across all 27 member states.
It covers five areas: ICT risk management, incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information-sharing arrangements. The third-party risk chapter is the one that reaches you: financial entities must maintain a register of ICT suppliers, perform due diligence, and include specific contractual clauses — this questionnaire is usually how they do it.
Who does this apply to?
Directly: a broad range of EU financial entities. Indirectly: any ICT supplier to one of them — software, hosting, cloud, cybersecurity, data processing.
Typical questions
Do you have a documented ICT risk management framework?
ICT risk governance
Can you map the full subcontracting chain involved in our service?
third-party risk
Evidence you’d need
- Documented ICT risk framework
- Subcontractor map for the service
Is your customer in the financial sector?
Upload the questionnaire — we classify every question by control, even if it doesn’t cite DORA explicitly.
Analyze my questionnaire for freeFAQ
Does DORA apply to me directly if I’m not a financial entity?
Not directly — it reaches you by contract, because your financial customer must oversee its ICT suppliers’ risk.
