The Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA), has applied to EU financial entities since January 17, 2025, and its third-party title works a genuinely new mechanism: financial entities register their ICT contracts in a "register of information," the European Supervisory Authorities use those registers and their own indicators to designate critical ICT third-party providers, and designated providers enter direct oversight — audits, fee-funded supervision, and remediation powers that reach them without passing through their customers. For fintechs, the regulation's contract law is where the architecture becomes daily work.
3G Times publishes information, not legal advice. DORA classification and contract questions belong with European counsel and the entity's lead overseer where one exists.
What does DORA add to vendor management?
Before DORA, a cloud hyperscaler serving five hundred European banks answered to each of them separately, through contracts of uneven strength, and no supervisor saw the aggregate. DORA's design response is the designation layer. The ESAs — EBA, EIOPA, and ESMA, acting together — apply materiality indicators: criticality of the services, systemic concentration, number of clients, the substitutability of the provider. Designation does not remove the customers' duties; it adds a supervisory channel that runs in parallel, funded by fees the designated providers themselves pay. The first designations landed in the cloud and data-center world, which surprised no one who had read the concentration statistics, and financial entities' contracts with those providers now sit under two regimes at once.
What goes into the register of information?
Every ICT service contract of a financial entity, in the standardised template, goes into the register: counterparty, services, criticality, start and end dates, concentration data, sub-outsourcing chains, and the contract's compliance with DORA's mandatory provisions. The register is not a filing exercise for its own sake — it is the designation machine's input, submitted through the entity's national authority to build the Union-wide picture of who depends on whom. The practical burden fell hardest on entities with sprawling vendor estates, and the first submission cycles exposed the same gap everywhere: contract inventories that were aspirational rather than actual, sub-processor chains documented by folklore, and criticality assessments that had never been made at all. Entities that fixed the inventory fixed the register; the register was the forcing function.
| DORA mechanism | Who acts | What it changes for fintechs |
|---|---|---|
| Register of information | Each financial entity | True ICT contract inventory on a standard template |
| CTPP designation | ESAs jointly | Key vendors enter direct oversight |
| Mandatory contract provisions (Art. 30) | Entity and provider | Audit rights, termination rights, sub-outsourcing terms |
| Concentration risk analysis | Entity and overseers | Exit and substitution planning becomes documented |
| Threat-led penetration testing | Significant entities | Security testing under a regulated framework |
What do the mandatory contract provisions require?
Article 30 sets the floor: the provider must grant the financial entity, its auditors, and the competent authorities full access and audit rights over the ICT services; termination rights must exist for material deficiency, regulatory obstruction, and the entity's own regulatory needs — with the strategic option to walk away when subcontracting changes materially; and the contract must describe the services, locations, and sub-outsourcing arrangements precisely enough to be supervised. Legacy agreements negotiated on hyperscaler paper required real renegotiation to reach that floor, and the market's answer converged on addenda riders rather than full rewrites. For a fintech buying ICT services, the Article 30 checklist is now a standard annex in vendor reviews: access rights that survive the relationship's end, audit scope that covers the actual data path, termination triggers that name the regulator's voice, and sub-outsourcing notice that arrives before, not after, the change.
How does concentration risk become a legal duty?
DORA treats concentration not as a fact to note but as a risk to manage. Entities must identify their ICT concentrations, assess the substitutability of each critical service, and maintain documented exit strategies for the critical ones — tested, costed, and realistic enough that "exit" is a plan rather than a hope. The duty's bite shows in architecture decisions: a payments platform that runs one region, one cloud, one managed-database vendor, and one integration middleware has four concentrations, each needing an exit story. Overseers read those stories skeptically because the registers show, across the Union, how many entities wrote the same story about the same vendors — which is precisely the correlation the designation layer exists to surface.
What does designation of a vendor change for its fintech customers?
Less than feared, more than nothing. The customer's own DORA duties — register, contract floor, concentration file — persist unchanged. What arrives is leverage: a designated provider under direct oversight faces the ESAs' recommendations and remediation expectations, and contract negotiations inherit that pressure. Customers also gain a supervisory address: concerns about a designated provider's conduct can travel to the overseer, a channel that did not exist when the only escalation path was the customer's own contract. For providers, designation converts market position into supervision — fees, audits, and findings — and the hyperscalers' 2025 annual reports already discuss it as a compliance cost line.
What does this mean in practice?
- Treat the register as a living inventory. The designation machine reads it annually; an entity whose register is stale feeds the picture it will be supervised by.
- Audit the Art. 30 floor at renewal, not at signature. Providers amend, sub-out, and migrate; the rider that satisfied 2025 needs a re-read against the 2026 estate.
- Write exit plans that a skeptic could execute. Data export formats, transition periods, and costed alternatives — the overseer's question is whether the plan survives contact with a Monday.
- Watch the designation list. A vendor entering direct oversight changes the negotiation posture and the escalation map; the ESA designations are public and quarterly-read.
DORA's third-party title is the first Union regime to regulate financial-sector concentration as infrastructure. The fintechs that internalized its logic earliest did so through the contract file — inventory, floor, exit — and that file, not the designation headlines, is where resilience is either documented or absent.
Group-level coordination has become the quiet best practice: one exit plan per critical intra-group service, written jointly and tested once, beats thirty divergent plans written to the same deadline.
What about intra-group ICT arrangements?
Intra-group providers sit in the register like any other contract, and DORA expects the same information flow even where market discipline cannot operate. Entities may apply a proportionate approach to group-internal dependencies, but concentration is concentration: a shared services center serving thirty group entities is a concentration with one exit plan written thirty times unless someone coordinates it.
Frequently asked questions
Does DORA apply to non-EU fintechs?
It binds EU financial entities and reaches third-country providers through those entities' contracts — a US fintech serving European customers as a critical ICT provider inherits the Article 30 floor and register exposure through its customers, without itself becoming a supervised entity.
What happens if a contract lacks the Article 30 provisions?
The entity carries the exposure: supervisory findings for non-compliance and a vendor relationship that cannot be audited or exited as the regulation assumes. The transitional reality was negotiated riders, and entities that left legacy paper untouched are remediating under examiner timelines.
Is the register submitted publicly?
No — registers flow to competent authorities and the ESAs and are treated as supervisory information. The public artifacts are the designation decisions and the oversight framework they trigger.
For more context, read EU AI Act Before August 2026: Credit-Scoring Deployers, FRIAs, and the Human-Oversight File.
For more context, read cftc event contracts ruling.
For more context, read psd3 payments services directive proposal.

