DORA clauses for LatAm software suppliers
What DORA, the EU regulation on digital operational resilience for the financial sector, asks of a software supplier outside the EU, why it arrives through your customer's contract and how to answer it with evidence.
Updated:
How DORA reaches you
DORA (Regulation (EU) 2022/2554) sets duties for the financial entities listed in the regulation, such as EU banks, payment institutions and electronic money institutions (art. 2).
It reaches a software supplier outside the EU through the contract with its financial-entity customer, or with the information and communication technology (ICT) provider that subcontracts it (arts. 28 and 30): when your customer uses ICT services, it remains fully responsible for complying with DORA (art. 28(1)(a)), and it must set the required terms in writing in its contract with you (art. 30(1)).
The exception is a supplier that the European Supervisory Authorities designate under DORA as a critical ICT third-party service provider (art. 31). That supplier is overseen directly, and if it is based outside the EU, financial entities can keep using it only if it sets up a subsidiary in the Union within the period the regulation sets (art. 31(12)).
If your company holds its own EU licence, for example as a payment institution, it is itself a financial entity under DORA (art. 2(1)), and its duties go beyond what its customers put in their contracts.
The clauses to expect
Article 30 of DORA sets two levels of contract terms, and your customer also keeps a register of information on all its contracts for ICT services (art. 28(3)), so expect questions that feed that register.
Every ICT services contract (art. 30(2))
A description of the services, including whether subcontracting is allowed and on what terms; the locations where they are provided and where data is processed, with advance notice of changes; terms on the availability, authenticity, integrity and confidentiality of data, and on access to it, its recovery and its return; service level descriptions; assistance with ICT incidents; cooperation with the authorities; termination rights and notice periods; and participation in your customer's security awareness and digital operational resilience training.
Services that support a critical or important function (art. 30(3))
On top of those terms: full service levels with precise quantitative and qualitative targets, notification and reporting duties, business contingency plans that you implement and test, ICT security measures, participation in your customer's threat-led penetration testing (TLPT), ongoing access, inspection and audit rights, and exit strategies with an adequate transition period.
The evidence that answers them
These clauses are answered with evidence that you keep up to date: which services your customer contracts, how long each one can be down, how recovery is tested and what each test showed.
Contract-readiness memo
Your customer's clauses read against DORA art. 30(2) and, where your service supports a critical or important function, art. 30(3), mapped to what you already have in place.
Short business impact analysis
The services your customer contracts, with the recovery time objective (RTO) and the recovery point objective (RPO) of each one.
Recovery test plan and evidence
What gets tested, in which scenario and in what order, and the dated evidence each test leaves: scope, conditions, result and corrective actions.
Exit support
How your service can be handed over to another provider or back to your customer at the end of the contract, in support of the exit strategy that DORA art. 30(3) refers to.
Where to start
The first step is knowing what your customers asked for. From there:
- Collect the contract annexes and questionnaires your financial-sector customers sent.
- Ask each customer whether your service supports a critical or important function: that decides which level of DORA art. 30 the contract follows.
- List the services each customer contracts and agree internally how long each one can be down.
- Plan a recovery test for those services and keep its dated evidence.
How we help
We read your customer's clauses against DORA art. 30, run a short business impact analysis of the services in scope and prepare the recovery test plan. Your engineering team or your provider runs the technical recovery tests; we design them, observe them and document their evidence.
Sources
These are the official sources for this guide, checked as of its update date. When a standard is sold by its publisher, we cite it by number and clause.
Let's talk about your next step.
In 30 minutes we review where you stand and suggest where to start.