What is DORA and who does it apply to?
DORA is Regulation (EU) 2022/2554, the European Union rulebook for keeping the financial sector running when its technology fails, and it has applied since 17 January 2025. It is written for banks, insurers and payment firms, but it reaches every IT supplier they depend on, because it dictates what has to be in the contract between them.
A regulation, not a directive
The difference is practical, not academic. A directive, such as NIS2, orders member states to write their own national law, which Latvia did with the National Cyber Security Law, and the detail then varies by country. DORA is a regulation: the same text became binding in Riga, Berlin and Dublin on the same morning, with no national version in between. Two things still happen at national level. Each state names the competent authority, which in Latvia is Latvijas Banka, and each state sets the administrative penalties. A companion directive, (EU) 2022/2556, existed only to align older sectoral directives with the new rules. So if a supplier tells you Latvia has not implemented DORA yet, they have confused it with NIS2.
Who it actually touches
Article 2 lists roughly twenty categories of financial entity, and the list runs far wider than banking:
- credit institutions, payment institutions, electronic money institutions and account information service providers
- investment firms, fund managers (UCITS and AIFM) and crypto asset service providers authorised under MiCA
- insurance and reinsurance undertakings, plus insurance intermediaries above the micro and SME threshold
- trading venues, central securities depositories, central counterparties, trade repositories and data reporting service providers
- credit rating agencies, administrators of critical benchmarks, crowdfunding platforms and occupational pension institutions
ICT third party service providers are named in Article 2 as well, but only those designated critical are supervised directly. Every other supplier is pulled in through its client's contract.
Size is handled by proportionality rather than by exemption. Small and non interconnected investment firms, small pension institutions and exempted payment or e-money firms may use the simplified framework in Article 16, and microenterprises are relieved of specific duties in several places. A short list of entities really is outside: pension schemes with fewer than 15 members, sub-threshold fund managers, micro and SME insurance intermediaries. The edges are genuinely difficult, the only text that binds anyone is the regulation itself, and a page like this one is no substitute for a lawyer reading your licence.
The five pillars
| Pillar | Articles | What it forces you to do |
|---|---|---|
| ICT risk management | 5 to 16 | A documented framework, an inventory of assets and dependencies, recovery objectives that someone has signed off, and a management body that owns the risk personally and has to keep training on it. |
| Incident management and reporting | 17 to 23 | One process to detect, log and classify ICT incidents, and mandatory reporting to the supervisor for anything classified as major: an initial notification measured in hours, an intermediate report within 72 hours, a final report within a month. |
| Digital operational resilience testing | 24 to 27 | A yearly testing programme for systems supporting critical or important functions, plus threat led penetration testing at least every three years for the entities the authority selects. |
| ICT third party risk | 28 to 44 | Due diligence before signing, the register of information, mandatory contract clauses, concentration risk analysis and an exit strategy that would actually work. |
| Information sharing | 45 | Voluntary. You may share threat intelligence inside trusted communities. Nothing to file. |
The register of information
Article 28(3) makes every in-scope firm keep a register of all contractual arrangements for ICT services, at entity and group level, and report it to the supervisor at least once a year. It is not a vendor list. It is a structured dataset: the provider's legal identifier, usually an LEI, the country of the provider, the countries where the service is delivered and where data is stored and processed, the function it supports, whether that function is critical or important, and the subcontractors sitting behind it. This is why hosting companies and SaaS vendors started receiving long questionnaires in 2025 from clients who had never described them as regulated. If your provider cannot state which data centre and country the workload sits in, the client cannot file.
The clauses DORA writes into your supplier contracts
Article 30 sets a baseline for every ICT contract and a much heavier list where the service supports a critical or important function. In practice you need:
- a full description of the service, the locations where it is provided and where data is processed and stored, and notice before either changes
- service levels with precise quantitative targets where the function is critical or important
- incident notification to the financial entity, and assistance during an incident at no extra cost or at a price agreed in advance
- rights of access, inspection and audit for the client, its auditors and the competent authority, unrestricted for critical or important functions
- cooperation with supervisors, and data availability, integrity and confidentiality
- return or recovery of data on termination, insolvency or discontinuation of the service
- termination rights with a defined minimum notice period
- an exit strategy with a transition period long enough to move, during which the service keeps running
The exit strategy is the clause everyone signs and nobody tests. Article 28(8) requires one for every ICT service supporting a critical or important function, and the point is that you can leave without interrupting the business. Wording alone does not achieve that. The real questions are where the data physically lives, in what format you can get it out, and how long the provider will keep serving you while you migrate.
Critical ICT third party providers, and why your host is not one
DORA creates a second regime for a small number of providers whose failure would ripple across the EU financial system. The European Supervisory Authorities designate them under Article 31, using criteria about systemic impact, how many financial entities rely on them and how hard they are to substitute, and a Lead Overseer supervises them directly with inspection powers and recommendations. The first designations were made in 2025. The list is short and dominated by the largest global cloud and software companies, so almost no hosting provider is on it, and none should market as if it were. Not being critical does not mean being out of scope: an ordinary provider is still fully inside DORA through its client's contract, register entry and audits. That is where the work actually lands.
What the fine exposure really is
DORA does not repeat the GDPR trick of a headline percentage of turnover for financial entities. Article 50 tells member states to set effective, proportionate and dissuasive administrative penalties, so the number comes from national law, and in Latvia it sits in the sectoral acts that Latvijas Banka enforces, alongside the usual supervisory measures: orders to remediate, public statements, requirements aimed at named managers. Two exposures are sharper than any fine. A designated critical provider that ignores its Lead Overseer can face a periodic penalty payment of 1% of average daily worldwide turnover, charged daily for up to six months. And supervisors can require a financial entity to suspend or terminate the use of a critical provider's services. For a regulated firm the real risk is rarely the fine, it is a licence conversation and a forced migration on the supervisor's timetable.
What a Latvian fintech or accounting SaaS should do first
- Work out which side of the line you are on. A licensed payment institution, e-money institution or investment firm in Riga is a financial entity and carries the whole framework. An accounting SaaS usually is not: it is an ICT third party provider, and DORA arrives as its clients' contract demands. Some groups are both.
- Map your critical or important functions. Every strict requirement downstream keys off this classification, so be honest about it. Gold plating every system is how these projects die.
- Build the register before you need it. Contracts, providers, identifiers, countries, subcontractors. Most firms discover contracts that nobody in the building owns.
- Read your contracts against Article 30 and open the renegotiations early. Some suppliers will refuse audit or exit terms, and you want to know that now.
- Write down who can declare an incident major at three in the morning, on what criteria, and what happens in the next 24 hours. Then rehearse it, because the deadlines are hours, not weeks.
- Put testing in the calendar with named owners. Yearly for anything supporting critical functions. Threat led testing only if the authority puts you in scope.
- Train the board and keep the evidence. Article 5 makes the management body responsible and expects it to keep its knowledge current.
Where a hosting provider honestly fits
A hosting provider is one line in your register and one contract in your file. It cannot be compliant on your behalf, and there is no DORA certificate for suppliers, whatever a sales deck implies. What a good provider does is make its line of the register easy to complete: identify the legal entity and country, say where data is processed and stored and warn you before that changes, accept audit and inspection rights including the supervisor's, report incidents fast enough for you to meet your own clock, sign a data processing agreement, and support an exit instead of obstructing it. We run our own data centre and our own network in Riga, so data stays in the EU under EU law, engineers are available around the clock, and we will sign the processing agreement and the contractual terms your compliance team needs, which is usually where infrastructure work with a regulated client begins. The framework, the classification, the testing and the answers to your regulator stay yours.