Complision

DORA: What It Is and Why a Bank or Insurer Is Asking

If your customer is a bank, insurer, payment institution or fintech, this explains where the questionnaire comes from.

DORA (EU Regulation 2022/2554) is the Digital Operational Resilience Act, in force since 17 January 2025. Unlike NIS2, it’s a directly-applicable regulation — the same text across all 27 member states.

It covers five areas: ICT risk management, incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information-sharing arrangements. The third-party risk chapter is the one that reaches you: financial entities must maintain a register of ICT suppliers, perform due diligence, and include specific contractual clauses — this questionnaire is usually how they do it.

Who does this apply to?

Directly: a broad range of EU financial entities. Indirectly: any ICT supplier to one of them — software, hosting, cloud, cybersecurity, data processing.

Typical questions

  • Do you have a documented ICT risk management framework?

    ICT risk governance

  • Can you map the full subcontracting chain involved in our service?

    third-party risk

Evidence you’d need

  • Documented ICT risk framework
  • Subcontractor map for the service

Is your customer in the financial sector?

Upload the questionnaire — we classify every question by control, even if it doesn’t cite DORA explicitly.

Analyze my questionnaire for free

FAQ

Does DORA apply to me directly if I’m not a financial entity?

Not directly — it reaches you by contract, because your financial customer must oversee its ICT suppliers’ risk.

Other frameworks

DORA ICT Supplier Questionnaire | Complision