GRC
DORA and NIS2 for SaaS vendors
You may not be in scope directly. Your EU customers are, and their obligations flow down through contracts and questionnaires. Here is what they will ask for and how to answer without a separate program.
7 min read · Certifyi compliance team · Updated September 2026
Short answer. DORA (in force since January 2025) makes EU banks, insurers and investment firms responsible for the ICT risk of their third-party providers, so SaaS vendors to financial customers receive contractual and assurance requirements. NIS2 (transposed across member states from late 2024) puts security and incident-reporting duties on essential and important entities and, through them, on their suppliers. An ISO 27001 management system with vendor management, incident response and resilience testing covers most of what both flow down.
DORA in practice for a vendor
The Digital Operational Resilience Act requires financial entities to keep a register of ICT providers, classify critical ones, include specific contract clauses, and be able to exit or substitute a provider. If you serve a bank or fintech in the EU, expect a DORA contract addendum covering service levels, incident notification, audit and access rights, data location, sub-contracting and termination assistance. Expect questionnaires on resilience testing and incident management, and possibly a request to participate in their threat-led penetration testing.
NIS2 in practice for a vendor
NIS2 applies to organisations in listed sectors above size thresholds: energy, transport, health, digital infrastructure, digital providers, manufacturing of critical products and more. Those entities must manage supply-chain security, which means assessing vendors like you on risk management, incident handling, business continuity, secure development and encryption. Incident reporting timelines (24-hour early warning, 72-hour notification) flow into the notification clauses they will want from you.
| Customer asks for | DORA | NIS2 | Where an ISO 27001 base already answers it |
|---|---|---|---|
| Incident notification timelines | Yes, contractual | Yes, 24h / 72h | Incident management process; add customer-specific clocks |
| Resilience and continuity testing | Yes, incl. TLPT for critical providers | Yes | Continuity plan and annual test; add scenario evidence |
| Audit and access rights | Yes | Sometimes | Provide assurance reports; Auditor Workspace access for their assessor |
| Sub-contractor transparency | Yes | Yes | Sub-processor list and vendor register |
| Exit and data return | Yes | Contractual | Data return and deletion procedure |
How to answer without a second program
Run one management system and map the requirements onto it. In Certifyi, DORA and NIS2 obligations sit in the same control library as ISO 27001 and SOC 2, so the incident process, continuity testing, vendor register and encryption controls are evidenced once. The remaining work is contractual: a template addendum for DORA customers, and notification clocks that match NIS2 for the rest.
Prepare these before the first request
- A sub-processor and sub-contractor list with locations.
- An incident notification procedure with named contacts and timelines you can commit to.
- Evidence of the last continuity or resilience test.
- A data return and deletion procedure with timelines.
- Your assurance package: ISO 27001 certificate or SOC 2 report, penetration-test summary, policy list.
Frequently asked questions
Are we directly regulated by DORA as a SaaS vendor?
Only if you are designated a critical ICT third-party provider by the EU supervisors, which applies to a small number of large providers. Everyone else is affected through customer contracts.
Does NIS2 apply to a company outside the EU?
If you provide services in the EU in a covered sector above the thresholds, it can. More commonly, it reaches you through customers who are in scope.
Is ISO 27001 enough?
It is the right base. Add customer-specific notification clocks, resilience-test evidence and the contract addendum, and most DORA and NIS2 requests are answered from the same record.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.