Regulation (EU) 2022/2554
DORA, for a software vendor
Your bank customer is regulated; you meet DORA in its contract, which since 17 January 2025 carries 9 clauses for every ICT service and 6 more for a critical or important function.
Answer above to read the determination for your case; the full tool takes your answers with it.
Continue in the free determinationThree tools, and the standard behind the due diligence
The Article 30 clauses, with a status for each
The 9 clauses of every contract, the 6 for a critical or important function and the 12 subcontracting terms of Delegated Regulation (EU) 2025/532, verbatim in your language, each with the ISO 27001 records that answer it; a status and a note per clause, written as the document to send back.
The register of information, as your data sheet
Every customer files the same templates about you. The columns that are facts about the vendor and the service, with their codes and names from the Implementing Regulation, answered once and written as the sheet to send with the contract.
The vendor questionnaire, written by the Regulation
For the financial entity's side: the 21 items of Delegated Regulation (EU) 2024/1773 a policy must make it ask a vendor, in the Regulation's words, assembled into the questionnaire with the assurance elements and audit methods the entity uses, and the evidence an ISO 27001 system produces under each.
ISO 27001, the standard the due diligence asks for
Article 28(5) makes appropriate information security standards a condition of contracting at all; the 93 Annex A controls and the clause register are the answer a customer's questionnaire expects.
The Annex A controls, one page each
Every control with its objective and the evidence it produces, in six languages; the clause checklist points at them by reference.
NIS2 mapped to ISO 27001
A bank's vendor is often a NIS2 entity in its own right; the Implementing Regulation's sections against the same controls.
Every free template on one page
The dates
Read from the Regulation and the eight acts that fill in its detail, on 12 September 2026. DORA has no amending act.
| Date | What |
|---|---|
| 27 December 2022 | The Regulation in the Official Journal. |
| 13 March 2024 | Delegated Regulations (EU) 2024/1773 and 2024/1774: the customer's policy on contracts for critical or important functions, including the due diligence on its vendors, and its ICT risk management tools and processes. |
| 13 March 2024 | Delegated Regulation (EU) 2024/1772: the six classification criteria and the materiality thresholds that make an ICT-related incident major, among them two hours of downtime on a service supporting a critical or important function. |
| 23 October 2024 | Delegated Regulation (EU) 2025/301 and Implementing Regulation (EU) 2025/302: the content, time limits and template of the initial notification, intermediate report and final report of a major incident. |
| 29 November 2024 | Implementing Regulation (EU) 2024/2956: the standard templates of the register of information in which every vendor contract is recorded and reported. |
| 17 January 2025 | The Regulation applies (Article 64): every new ICT service contract carries the Article 30 clauses, and the registers are filed. |
| 13 February 2025 | Delegated Regulation (EU) 2025/1190: which financial entities run threat-led penetration testing, the phases, the testers, and the pooled test a vendor may run for several entities. |
| 24 March 2025 | Delegated Regulation (EU) 2025/532: what the customer assesses when a vendor subcontracts a service supporting a critical or important function. |
9 articles, from the primary sources
DORA for a software vendor: the Article 30 contract clauses your bank customer will send, the register of information you will appear in, and what ISO 27001 already answers
Since 17 January 2025 every bank, insurer, investment firm and payment institution in the Union manages its software vendors under Regulation (EU) 2022/2554, DORA. The vendor is not regulated; the contract is. Article 30 lists nine clauses every ICT service contract must carry and six more when the service supports a critical or important function: locations, data return, incident assistance at a pre-set cost, cooperation with the customer's authorities, termination notice, audit rights, exit strategies. Each clause read from the Regulation, the register of information the customer files yearly, the three delegated acts behind it, and which of the clauses an ISO 27001 system already produces the evidence for.
DORA's nineteen types of ICT service, S01 to S19: which one a SaaS product is, what the register of information records about it, and why one contract can be several rows
Every ICT service a bank, insurer or payment institution buys is recorded in its register of information under one of nineteen codes, S01 to S19, from Annex III of Implementing Regulation (EU) 2024/2956. A hosted product is S19, installed software is S13, a managed service S14, a data feed S05, and the customer files one row per service and function, so a single contract can become several. The nineteen types with the Regulation's own descriptions, the column that carries the code, what the customer must record beside it, and why the code you give one customer must match the code you give the next.
Subcontracting under DORA, RTS 2025/532: the twelve terms your contract carries when you subcontract a critical service, the ten conditions your customer checks first, and the notice period before you change a subcontractor
Since 22 July 2025 a financial entity may let its software vendor subcontract a service supporting a critical or important function only on the conditions of Delegated Regulation (EU) 2025/532. Ten conditions the customer assesses before signing, from your ability to identify every subcontractor to whether the subcontractor grants the same audit rights; twelve terms the contract then carries, from your responsibility for the subcontractor's service to the customer's right to terminate; a notice period during which you may not change a subcontractor until the customer has approved or not objected; and three cases in which the customer may terminate. Read from the Official Journal, with what the register of information records about the chain and what an ISO 27001 supplier register already answers.
Your bank's DORA vendor policy, RTS 2024/1773: the six due-diligence questions, the five sources of assurance, the eight conditions for accepting your ISO 27001 certificate in place of an audit, and the five reports you will owe
Every financial entity in the Union has a written policy on its contracts for ICT services supporting critical or important functions, and Delegated Regulation (EU) 2024/1773 says what that policy must contain, in force since 15 July 2024. Read from the vendor's side: the six things the customer assesses about you before signing (Article 6), the five sources of assurance it may use and the eight conditions under which it may rely on your certifications or audit reports rather than auditing you itself (Article 8), the key indicators, penalties and five kinds of report the contract will demand (Article 9), and the exit plan it must test (Article 10). With what an ISO 27001 certificate answers, and what it does not.
When your outage becomes your bank customer's major incident: DORA's six criteria, the two-hour downtime threshold of RTS 2024/1772, the four-hour, 24-hour, 72-hour and one-month clocks of RTS 2025/301, and the facts your customer will need from you
A financial entity must report a major ICT-related incident to its supervisor within four hours of classifying it and no later than 24 hours from becoming aware, follow up within 72 hours and close within one month. Whether an outage at its software vendor is major is decided by six criteria and the thresholds of Delegated Regulation (EU) 2024/1772: more than two hours of downtime on a service supporting a critical or important function, more than 24 hours of duration, more than 10 percent of clients, two or more member states, data losses, 100 000 euro. What each report must contain under Delegated Regulation (EU) 2025/301, which of those facts only the vendor holds, and what the Article 30(2)(f) incident assistance clause turns that into. Read from the Official Journal.
The nine places where your bank customer's ICT risk framework reaches into your product, RTS 2024/1774: support end dates, vulnerability reports and library tracking, settings you may not let it bypass, source code tested before production, named accounts for your staff, and your incidents as its alarms
Delegated Regulation (EU) 2024/1774, in force since 15 July 2024, specifies the ICT risk management framework every financial entity runs under DORA, and nine of its articles name the ICT third-party service provider. Read from the vendor's side: the asset register that records the end dates of your support (Article 4), the vulnerability procedure that verifies you handle and report vulnerabilities and tracks the third-party libraries in your product (Article 10), the data and system security procedure that allocates roles between you and the customer and asks for measures on your infrastructure (Article 11), encrypted connections over third-party networks (Article 13), source code from providers analysed and tested before production (Article 16), a unique account for each of your staff with access (Article 20), your incident notifications as one of its detection inputs (Article 23), continuity tests that include your service and your insolvency (Articles 25 and 26). With what an ISO 27001 system already answers.
Threat-led penetration testing under DORA, from the vendor's side: when your bank customer's red team is allowed into your production systems, the 12-week test of RTS 2025/1190, the pooled test you can run instead, and what the contract already says
Article 26 of DORA makes the largest financial entities run a threat-led penetration test on live production systems at least every 3 years, covering the critical or important functions they have outsourced, and Article 30(3)(d) puts the vendor's participation into the contract. Delegated Regulation (EU) 2025/1190, in force since 8 July 2025, sets the mechanics: a control team that may include your staff, a blue team that must not know, an active red team phase of at least 12 weeks, a replay and purple teaming within 10 weeks of its end, a remediation plan within 8 weeks. Article 26(4) lets a vendor whose other customers would be harmed contract an external tester directly and run one pooled test for several financial entities. What the vendor signs, what it may refuse, and what an ISO 27001 system already holds. Read from the Official Journal.
ISO 27001 vs SOC 2 in Europe: which one buyers actually ask for
Selling into Europe, get ISO 27001: EU public tenders named it 3,408 times in a year against 104 for SOC 2. Selling to US customers, it runs the other way. The numbers, the public TED query to re-run them, and when you need both.
CRA or NIS2: which one applies to a software company, and can it be both?
The Cyber Resilience Act regulates products placed on the market; NIS2 regulates entities that provide services. A software company can be under one, the other, both or neither, and the answer turns on two questions: do you place a product on the market, and are you a medium-sized or larger entity in a listed sector. The dates, the reporting clocks, the fines and the decision table, from the two texts.
13 of the 15 clauses are answered by an ISO 27001 record
StandardOS keeps the ISO 27001 records a financial customer's due diligence and audit right ask for, in one workspace, in six languages: supplier register, backups and restore tests, incident process, continuity plan, internal audits, the Statement of Applicability.
Dates are read from the Regulation and the acts named and never typed on this page. This is not legal advice, and the Regulation is the text to read: Regulation (EU) 2022/2554.