Compliance

DORA for Non-EU Vendors: What US/UK SaaS Companies Need to Know

DORA for Non-EU Vendors

A practical breakdown of DORA compliance for non-EU vendors, who’s actually in scope, what your EU financial-entity customers will put in your next contract, and how to get ahead of it.

If a European bank, insurer, or investment firm has ever sent your team a security questionnaire that mentions “Article 30” or “Register of Information,” you’ve already met the Digital Operational Resilience Act. DORA compliance for non-EU vendors isn’t a hypothetical for 2027, it’s a live commercial requirement today: DORA has applied across the EU financial sector since 17 January 2025, and any US or UK SaaS company selling into that market is now expected to prove its ICT resilience on paper, in contract language, and on request. Vendors that get ahead of it can turn a compliance audit into a competitive edge; get a head start with a DORA-readiness compliance audit before a customer forces the timeline.

This guide is written for CTOs, CIOs, and engineering leaders at non-EU SaaS and cloud companies who need a clear, no-fluff answer to one question: does this apply to us, and if so, what exactly do we need to change?

What DORA Actually Is, in Plain Terms

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is the EU’s answer to a problem that had outgrown its old rulebook: financial institutions no longer run on their own infrastructure, they run on cloud platforms, SaaS tools, and outsourced IT services built by companies the EU has no direct authority over. DORA closes that gap by making financial entities contractually responsible for the resilience of every ICT vendor in their supply chain, and by giving EU regulators direct oversight powers over the vendors that matter most.

The regulation entered into application on 17 January 2025 and now governs an estimated 22,000+ EU financial entities, from credit institutions and insurers to payment firms and crypto-asset service providers. It rests on five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. For a non-EU vendor, the one that matters most, by a wide margin, is third-party risk management, because that’s the pillar that reaches straight into your contracts.

Do Non-EU Vendors Need DORA Compliance? Direct vs. Indirect Scope

DORA does not regulate US or UK companies as a matter of EU law the way it regulates a Frankfurt-based bank. But scope works on two tracks, and most vendors land on at least one of them the moment they sign a European financial-sector customer.

Most US and UK SaaS vendors fall into indirect scope first, direct CTPP designation is reserved for systemically important providers.
  • Indirect scope (the common case): if any customer is an EU bank, insurer, investment firm, payment institution, or similar regulated entity, that customer is legally obligated to bind you to DORA-aligned contract terms. You don’t get a fine from Brussels, you get a contract amendment, a security questionnaire, and an audit clause from your customer’s compliance team.
  • Direct scope (the exception): if the European Supervisory Authorities formally designate your company a Critical ICT Third-Party Provider (CTPP), because enough of the EU financial sector depends on you, you move under direct EU oversight, with your own reporting duties and, if you’re not EU-based, a requirement to establish an EU presence.

Critical ICT Third-Party Providers: the direct-oversight track

In November 2025, the European Supervisory Authorities designated the first cohort of Critical ICT Third-Party Providers under DORA’s oversight framework, drawn heavily from hyperscale cloud platforms and large enterprise software vendors. The official list of designated CTPPs is refreshed annually, so this isn’t a one-time event, it’s a recurring assessment that any large, systemically embedded non-EU vendor should track. Non-EU CTPPs are required to stand up an EU legal presence within a set window of their designation, and financial entities may be barred from using a CTPP that hasn’t complied.

For most mid-market SaaS and platform companies, direct designation is unlikely. The practical exposure is almost always the indirect track, which is where the rest of this guide focuses.

What EU Financial-Entity Customers Will Put in Your Contract

Article 30 of DORA is the clause your legal team should read before your next EU renewal. It sets a baseline for every ICT contract with a financial entity, and a materially heavier set of requirements when the contract supports a “critical or important function,” which, for most SaaS infrastructure, payments, or data-processing tools, it usually does.

Contract elementEvery ICT contract (baseline)Critical or important functions (enhanced)
Service descriptionClear, complete description of services providedFull service-level descriptions with quantitative, measurable KPIs
Data locationRegions or countries where data is processed and storedSame, plus stricter monitoring and reporting on any change
SubcontractingDisclosure of whether subcontracting is permittedPrior notice, financial-entity objection rights, and pass-through of obligations to subcontractors
Incident notificationGeneral cooperation obligationsDefined notice periods and mandatory reporting of any development that could affect service resilience
Audit & access rightsBasic access and information rightsFull audit and inspection rights for the financial entity, its regulator, and appointed third parties
Exit & terminationStandard termination clausesDocumented, tested exit strategy with defined transition timelines and data-portability terms
What EU Financial-Entity Customers Will Put in Your Contract

Two of these deserve special attention because they’re where most non-EU vendors are furthest behind: subcontracting transparency and exit strategy documentation.

Subcontracting chains: the visibility problem

If your service depends on your own vendors, another cloud region, a managed database provider, a monitoring platform, DORA expects your EU customer to see and assess that whole chain, not just your direct relationship. That means your contract needs to name material subcontractors, commit to advance notice before changing them, and guarantee that the same security and resilience standards flow all the way down the chain. A well-structured cloud landing zone with clearly documented regions, providers, and data flows makes this disclosure far easier to produce on demand instead of reconstructing it under deadline pressure.

Exit strategies: the requirement almost everyone skips

An exit strategy under DORA isn’t a termination paragraph, it’s a tested plan: how the financial entity would transition off your platform, how data gets returned in a usable format, what continuity looks like during migration, and whether the plan has actually been rehearsed. Industry surveys around DORA’s 2025 application date found exit-plan testing to be the least mature area of compliance across financial entities, which means it’s also the area where a vendor that shows up with a ready answer stands out immediately during procurement.

The Register of Information: Why You’ll Keep Getting Asked the Same Questions

Every EU financial entity must maintain a Register of Information (RoI), a structured inventory of every ICT contract it holds, including your company, the services you provide, whether they support a critical function, where data is processed, and your subcontracting chain. That register gets submitted to national competent authorities on a recurring cycle. The practical effect for a non-EU vendor is that compliance isn’t a one-time questionnaire, it’s a standing data-collection relationship: your customer will come back to you, often annually, to refresh the same fields, and inconsistent or incomplete answers become a finding against your customer, not just against you. Vendors that maintain a standing, audit-ready answer set, service descriptions, data-location maps, subcontractor lists, incident-response documentation, turn this from a recurring fire drill into a five-minute update.

Where DORA meets EU data sovereignty: the Article 30 requirement to disclose exact processing locations sits inside a much broader EU push toward cloud and data sovereignty, reflected in initiatives like Gaia-X. Vendors that can already answer “where does the data live, precisely” tend to clear DORA’s data-location questions with far less friction.

Penalties and Enforcement: What’s Actually at Risk in 2026

The risk profile is different depending on which track you’re on. Financial entities that fail to meet DORA’s obligations, including maintaining compliant vendor contracts, face administrative penalties that can reach a significant percentage of annual worldwide turnover under their national regulator’s enforcement powers. For a non-EU vendor in indirect scope, the more immediate risk isn’t a fine, it’s the contract: a financial-entity customer that can’t legally keep a non-compliant vendor will either force remediation on a deadline or move the business to a competitor that’s already compliant.

For designated Critical ICT Third-Party Providers, the exposure is direct and specific: periodic penalty payments of up to 1% of average daily worldwide turnover for every day a breach of the oversight framework continues. Combined with the requirement to establish an EU presence within a fixed window of designation, this makes CTPP status a board-level issue the moment a company is anywhere close to that threshold.

A Practical DORA Compliance Checklist for Non-EU SaaS Vendors

If you sell to even one EU financial-sector customer, this is the sequence that gets you from “we got a questionnaire” to “we have a standing answer”:

  1. Map your EU financial-sector exposure. Identify every contract with a bank, insurer, payment institution, investment firm, or crypto-asset service provider, and flag which of your services support a function your customer would classify as critical or important.
  2. Gap-test your contracts against Article 30. Compare current terms to the baseline and enhanced requirements above, most gaps cluster around data-location precision, subcontracting disclosure, audit rights, and exit-strategy documentation.
  3. Document your subcontracting chain. List every material subcontractor, their location, and their role, and build a change-notification process before a customer asks for it.
  4. Build and test an exit strategy. Define the transition plan, data-portability format, and continuity approach, then actually rehearse it once, not just write it down.
  5. Operationalize incident notification. Set internal SLAs for detecting and escalating any development that could affect service resilience, so you can meet customer notice periods without a scramble.
  6. Keep an audit-ready evidence pack. Service descriptions, security certifications, data-flow diagrams, and subcontractor lists, maintained continuously so RoI refresh requests take minutes, not weeks.

How Gart Solutions Helps SaaS and Fintech Teams Get DORA-Ready

Gart Solutions works with SaaS, fintech, and cloud-native engineering teams on exactly the infrastructure and compliance groundwork DORA is asking for, not generic policy templates, but the underlying architecture and evidence that makes audits fast instead of painful.

  • compliance audit that maps your current contracts, data flows, and subcontracting chain against DORA’s Article 30 baseline and enhanced requirements.
  • DevSecOps consulting that turns manual, periodic compliance checks into continuous, automated evidence for frameworks like SOC 2, ISO 27001, and DORA alike.
  • Cloud landing zone design that gives you precise, documented control over where data is processed, the exact question EU financial-entity customers keep asking.
  • Deep fintech infrastructure experience, including cloud migrations for payment and financial platforms built around zero-downtime, auditable change management.

Book a DORA readiness assessment

Roman Burdiuzha

Roman Burdiuzha

Co-founder & CTO, Gart Solutions · Cloud Architecture Expert

Roman has 15+ years of experience in DevOps and cloud architecture, with prior leadership roles at SoftServe and lifecell Ukraine. He co-founded Gart Solutions, where he leads cloud transformation and infrastructure modernization engagements across Europe and North America. In one recent client engagement, Gart reduced infrastructure waste by 38% through consolidating idle resources and introducing usage-aware automation. Read more on Startup Weekly.

You Might Also Like

FAQ

Does DORA apply to US companies?

Not directly under EU law. But if a US SaaS or cloud provider supplies ICT services to an EU bank, insurer, investment firm, or other financial entity, that customer must flow DORA's contractual and security obligations down to the vendor, making compliance a practical requirement for keeping the account.

Does DORA apply to UK SaaS companies?

DORA doesn't apply directly to UK-only firms, since the UK sits outside the EU regime. A UK SaaS company serving EU financial entities is still pulled into scope for those specific relationships, regardless of where the company is headquartered.

Who counts as a Critical ICT Third-Party Provider (CTPP) under DORA?

A vendor formally designated by the European Supervisory Authorities as systemically important to the EU financial sector, based on how many financial entities depend on it and how critical its functions are. The first cohort, named in November 2025, was dominated by hyperscale cloud and enterprise software providers.

What happens if a non-EU vendor doesn't comply with DORA?

For most non-EU vendors, the consequence is commercial: your EU financial-entity customer can't legally maintain a contract that fails Article 30, so they'll demand remediation or switch providers. Designated CTPPs face direct penalties, periodic payments of up to 1% of average daily worldwide turnover per day of continued breach.

When do non-EU vendors need to be DORA-ready?

DORA has applied since 17 January 2025, so the obligation is already live for any EU financial entity you serve. Expect contract reviews and audit requests on a rolling basis throughout 2026, tied to your customers' annual Register of Information updates, not a single deadline.

How can non-EU SaaS vendors prepare for DORA compliance?

Map which contracts touch EU financial entities, gap-test them against Article 30's baseline and enhanced requirements, document your subcontracting chain and data locations, build and test an exit strategy, and keep an evidence pack ready for recurring audit requests. Gart Solutions runs this as a structured compliance audit for SaaS and fintech infrastructure teams.

Why are EU financial-entity customers suddenly asking about DORA in vendor contracts?

Because their regulators are asking them first. Financial entities must maintain and submit a Register of Information covering every ICT vendor, and gaps in it, missing subcontractor details, no exit strategy, are a supervisory finding against the financial entity. That pressure gets passed straight to you.
arrow arrow

Thank you
for contacting us!

Please, check your email

arrow arrow

Thank you

You've been subscribed

We use cookies to enhance your browsing experience. By clicking "Accept," you consent to the use of cookies. To learn more, read our Privacy Policy