What Are DORA IT Controls?

Definition

DORA IT controls are the governance, security, monitoring, testing, incident response, and third-party risk management measures used to meet the Digital Operational Resilience Act requirements. DORA, Regulation (EU) 2022/2554, is the EU framework for digital operational resilience in the financial sector. It has applied since 17 January 2025 and is designed to ensure that financial entities can withstand, respond to, and recover from ICT-related disruptions such as cyberattacks, system failures, and third-party service outages.

For product, compliance, and SaaS teams, DORA IT controls are not only internal security policies. They define how systems are designed, operated, monitored, tested, documented, and supported when serving regulated financial customers.

Why DORA IT Controls Matter

DORA IT controls matter because financial entities must manage ICT risk in a consistent and auditable way. This affects banks, insurers, investment firms, payment institutions, crypto-asset service providers, and other financial entities covered by DORA.

For SaaS vendors serving financial customers, DORA can influence procurement, contractual requirements, service-level expectations, incident reporting workflows, audit rights, resilience testing, subcontractor management, and evidence requests. A product may be technically strong but still create customer risk if it cannot support operational resilience expectations.

Core Areas of DORA IT Controls

ICT risk management

Teams need policies, processes, and technical controls to identify, protect, detect, respond to, and recover from ICT risks. This may include asset inventories, access management, vulnerability management, backup and recovery, encryption, logging, change management, business continuity, and disaster recovery.

ICT incident management

DORA requires structured handling of ICT-related incidents. Product and SaaS teams should define incident classification, escalation paths, customer notification workflows, root cause analysis, evidence retention, and communication responsibilities.

Digital operational resilience testing

Resilience controls must be tested. This can include vulnerability assessments, scenario testing, penetration testing, business continuity tests, failover tests, backup restoration tests, and, for certain entities, advanced threat-led penetration testing.

Third-party ICT risk management

DORA places strong emphasis on ICT third-party risk. SaaS teams should expect customers to ask for information about hosting providers, subcontractors, critical dependencies, data locations, exit plans, security controls, and contractual safeguards.

Information sharing and governance

DORA also supports structured governance and, in some contexts, information sharing on cyber threats. Internally, teams need clear ownership, board-level accountability where applicable, documented policies, control evidence, and regular review cycles.

Common Implementation Questions

Are DORA IT controls only relevant to financial institutions?

No. DORA directly applies to covered financial entities, but SaaS vendors and ICT providers may be affected through customer contracts, due diligence, outsourcing requirements, oversight expectations, and requests for evidence.

What should SaaS teams prepare first?

Start with a control inventory mapped to DORA-relevant areas: ICT risk management, incident response, resilience testing, third-party dependencies, access control, logging, business continuity, and data protection. Then identify which controls are already documented and which need stronger evidence.

What evidence do customers usually request?

Common evidence may include security policies, SOC 2 or ISO certifications, penetration test summaries, business continuity plans, disaster recovery test results, incident response procedures, subcontractor lists, data processing locations, access control policies, audit logs, and service-level documentation.

Can a vendor claim DORA compliance?

Use caution. “Fully compliant” is risky unless the vendor clearly defines its role, scope, services, customer type, contractual obligations, and evidence base. Stronger wording explains what the vendor supports: resilience testing, incident workflows, audit evidence, third-party risk documentation, access controls, logging, and continuity planning.

Related Standards and Frameworks

DORA IT controls often overlap with established security and resilience frameworks, including ISO/IEC 27001, ISO/IEC 22301, SOC 2, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, and COBIT. These frameworks do not replace DORA, but they can help structure control design, evidence collection, and audit readiness.