DORA is now in force — and it has fundamentally changed the third-party risk obligations of every financial institution in the EU. The regulation doesn’t just ask you to assess your ICT vendors. It requires you to continuously monitor them, contractually bind them to specific security standards, and maintain detailed registers of every critical third-party dependency.
If your current vendor risk program relies on annual questionnaires and spreadsheet tracking, DORA has a problem with that. Here’s what the regulation actually demands, where most organisations are falling short, and how automated vendor risk management changes the equation.
What Is DORA — and Who Does It Apply To?
The Digital Operational Resilience Act (DORA) is an EU regulation that entered into force on January 17, 2023 and became fully applicable on January 17, 2025. It applies to a wide range of financial entities operating in the EU — including banks, insurance companies, investment firms, payment institutions, and crypto-asset service providers. It also directly applies to critical ICT third-party service providers (CTPPs) that serve these institutions.
The regulation covers five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. For most organisations, it’s the third-party risk pillar that requires the most significant operational change.
What DORA Actually Requires for Third-Party Risk
DORA goes well beyond a checkbox compliance model. Under Article 28 and the surrounding provisions, financial entities must:
- Maintain a register of all ICT third-party service providers, including full dependency mapping and risk tiering
- Conduct pre-contractual due diligence for all providers, with enhanced standards for critical providers
- Include mandatory contractual clauses covering audit rights, security standards, incident reporting timelines, and exit strategies
- Monitor ICT third parties on an ongoing basis — not just at onboarding or annual review
- Test the resilience of critical dependencies through threat-led penetration testing (TLPT) requirements
- Maintain exit strategies with documented contingency plans for critical provider failures
The bar for “ongoing monitoring” is what catches most compliance teams off guard. DORA does not accept a point-in-time assessment as sufficient. Regulators expect evidence of continuous oversight.
The Three Compliance Gaps Most Financial Institutions Face
Based on what we see across the financial sector, three gaps consistently surface when organisations audit their DORA readiness:
1. Incomplete provider registers. DORA requires a detailed register of all ICT third-party relationships, including sub-outsourcing chains. Most organisations have visibility into their Tier 1 vendors but lack a clear picture of Tier 2 and Tier 3 dependencies — the exact relationships DORA’s systemic risk focus targets.
2. Annual assessments passed off as continuous monitoring. Questionnaire-based annual reviews don’t satisfy DORA’s continuous monitoring expectation. Regulators are looking for evidence of real-time or near-real-time visibility into vendor security posture — not a PDF from twelve months ago.
3. Contractual clauses that don’t match DORA’s requirements. Many existing vendor contracts predate DORA and lack the mandatory provisions around audit rights, incident notification timelines (within specific hours, not days), and exit plan documentation. Renegotiating these at scale is operationally intensive.
How Cloud Telemetry Changes the Compliance Equation
The reason most firms struggle with continuous monitoring isn’t a lack of intent — it’s that traditional approaches don’t scale. Manually reviewing vendor security posture across dozens or hundreds of ICT relationships, on a continuous basis, is simply not feasible without automation.
This is where cloud telemetry-based vendor risk management changes the model entirely. Rather than relying on vendors to answer questionnaires (which they may complete inaccurately or infrequently), platforms like Findings’ CloudVRM connect directly to vendor cloud environments — AWS, Azure, GCP — and pull real-time security control data on a continuous basis.
The result: you get an always-current view of vendor compliance posture, updated daily, without sending a single questionnaire. This is the kind of continuous monitoring DORA regulators are looking for.
What You Should Be Doing Now
If you haven’t already, your immediate DORA priorities should be:
- Complete your ICT third-party register, including sub-outsourcing dependencies
- Audit existing vendor contracts against DORA’s mandatory clause requirements
- Establish a risk tiering model to identify which providers qualify as critical
- Implement continuous monitoring for critical providers — not just annual reviews
- Document exit strategies for each critical ICT dependency