GRC

DORA and NIS2 for SaaS vendors

You may not be in scope directly. Your EU customers are, and their obligations flow down through contracts and questionnaires. Here is what they will ask for and how to answer without a separate program.
7 min read · Certifyi compliance team · Updated September 2026
Short answer. DORA (in force since January 2025) makes EU banks, insurers and investment firms responsible for the ICT risk of their third-party providers, so SaaS vendors to financial customers receive contractual and assurance requirements. NIS2 (transposed across member states from late 2024) puts security and incident-reporting duties on essential and important entities and, through them, on their suppliers. An ISO 27001 management system with vendor management, incident response and resilience testing covers most of what both flow down.

DORA in practice for a vendor

The Digital Operational Resilience Act requires financial entities to keep a register of ICT providers, classify critical ones, include specific contract clauses, and be able to exit or substitute a provider. If you serve a bank or fintech in the EU, expect a DORA contract addendum covering service levels, incident notification, audit and access rights, data location, sub-contracting and termination assistance. Expect questionnaires on resilience testing and incident management, and possibly a request to participate in their threat-led penetration testing.

NIS2 in practice for a vendor

NIS2 applies to organisations in listed sectors above size thresholds: energy, transport, health, digital infrastructure, digital providers, manufacturing of critical products and more. Those entities must manage supply-chain security, which means assessing vendors like you on risk management, incident handling, business continuity, secure development and encryption. Incident reporting timelines (24-hour early warning, 72-hour notification) flow into the notification clauses they will want from you.
Customer asks forDORANIS2Where an ISO 27001 base already answers it
Incident notification timelinesYes, contractualYes, 24h / 72hIncident management process; add customer-specific clocks
Resilience and continuity testingYes, incl. TLPT for critical providersYesContinuity plan and annual test; add scenario evidence
Audit and access rightsYesSometimesProvide assurance reports; Auditor Workspace access for their assessor
Sub-contractor transparencyYesYesSub-processor list and vendor register
Exit and data returnYesContractualData return and deletion procedure

How to answer without a second program

Run one management system and map the requirements onto it. In Certifyi, DORA and NIS2 obligations sit in the same control library as ISO 27001 and SOC 2, so the incident process, continuity testing, vendor register and encryption controls are evidenced once. The remaining work is contractual: a template addendum for DORA customers, and notification clocks that match NIS2 for the rest.

Prepare these before the first request

Frequently asked questions

Only if you are designated a critical ICT third-party provider by the EU supervisors, which applies to a small number of large providers. Everyone else is affected through customer contracts.

If you provide services in the EU in a covered sector above the thresholds, it can. More commonly, it reaches you through customers who are in scope.

It is the right base. Add customer-specific notification clocks, resilience-test evidence and the contract addendum, and most DORA and NIS2 requests are answered from the same record.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top