Regulation (EU) 2022/2554

DORA, for a software vendor

Your bank customer is regulated; you meet DORA in its contract, which since 17 January 2025 carries 9 clauses for every ICT service and 6 more for a critical or important function.

Does the service support a critical or important function of the customer?

Answer above to read the determination for your case; the full tool takes your answers with it.

Continue in the free determination

Three tools, and the standard behind the due diligence

The Article 30 clauses, with a status for each

The 9 clauses of every contract, the 6 for a critical or important function and the 12 subcontracting terms of Delegated Regulation (EU) 2025/532, verbatim in your language, each with the ISO 27001 records that answer it; a status and a note per clause, written as the document to send back.

The register of information, as your data sheet

Every customer files the same templates about you. The columns that are facts about the vendor and the service, with their codes and names from the Implementing Regulation, answered once and written as the sheet to send with the contract.

The vendor questionnaire, written by the Regulation

For the financial entity's side: the 21 items of Delegated Regulation (EU) 2024/1773 a policy must make it ask a vendor, in the Regulation's words, assembled into the questionnaire with the assurance elements and audit methods the entity uses, and the evidence an ISO 27001 system produces under each.

ISO 27001, the standard the due diligence asks for

Article 28(5) makes appropriate information security standards a condition of contracting at all; the 93 Annex A controls and the clause register are the answer a customer's questionnaire expects.

The Annex A controls, one page each

Every control with its objective and the evidence it produces, in six languages; the clause checklist points at them by reference.

NIS2 mapped to ISO 27001

A bank's vendor is often a NIS2 entity in its own right; the Implementing Regulation's sections against the same controls.

Every free template on one page

The dates

Read from the Regulation and the eight acts that fill in its detail, on 12 September 2026. DORA has no amending act.

The dates of DORA and its delegated and implementing acts
DateWhat
27 December 2022The Regulation in the Official Journal.
13 March 2024Delegated Regulations (EU) 2024/1773 and 2024/1774: the customer's policy on contracts for critical or important functions, including the due diligence on its vendors, and its ICT risk management tools and processes.
13 March 2024Delegated Regulation (EU) 2024/1772: the six classification criteria and the materiality thresholds that make an ICT-related incident major, among them two hours of downtime on a service supporting a critical or important function.
23 October 2024Delegated Regulation (EU) 2025/301 and Implementing Regulation (EU) 2025/302: the content, time limits and template of the initial notification, intermediate report and final report of a major incident.
29 November 2024Implementing Regulation (EU) 2024/2956: the standard templates of the register of information in which every vendor contract is recorded and reported.
17 January 2025The Regulation applies (Article 64): every new ICT service contract carries the Article 30 clauses, and the registers are filed.
13 February 2025Delegated Regulation (EU) 2025/1190: which financial entities run threat-led penetration testing, the phases, the testers, and the pooled test a vendor may run for several entities.
24 March 2025Delegated Regulation (EU) 2025/532: what the customer assesses when a vendor subcontracts a service supporting a critical or important function.

9 articles, from the primary sources

13 of the 15 clauses are answered by an ISO 27001 record

StandardOS keeps the ISO 27001 records a financial customer's due diligence and audit right ask for, in one workspace, in six languages: supplier register, backups and restore tests, incident process, continuity plan, internal audits, the Statement of Applicability.

Dates are read from the Regulation and the acts named and never typed on this page. This is not legal advice, and the Regulation is the text to read: Regulation (EU) 2022/2554.