Skip to content
Built for vendors with no regulator of their own

DORA & NIS2 contract compliance for vendors

Your customer's regulator is now asking about you.

DORA and NIS2 don't regulate most software and service vendors directly — but they require regulated customers to impose the same requirements on their ICT suppliers by contract. If a bank, insurer or essential entity buys from you, this is how those requirements reach you.

Just 5 quick questions — no credit card required.

Product preview
ComplyOne product screenshot: Global dashboard all enabledComplyOne product screenshot: Global dashboard detailsComplyOne product screenshot: Module dials workingComplyOne product screenshot: Regulation compliance

Why 'we're not regulated' isn't the whole answer any more

DORA Article 28 requires financial entities to manage ICT third-party risk contractually — due diligence before signing, mandatory contract clauses (audit rights, exit strategies, incident-notification duties, sub-outsourcing controls), and ongoing monitoring for the length of the relationship. NIS2 essential and important entities carry a parallel supply-chain security duty under Article 21. Neither law regulates you directly if you're not a financial entity or NIS2-scoped entity yourself — but your customer's compliance programme now runs through your contract, your security questionnaire responses, and your ability to produce evidence on request. A vendor who can't answer promptly loses the deal to one who can.

What's included in Cyber Supplier

The regulations that matter most for software, saas and service vendors selling to regulated financial and critical-infrastructure customers — covered, mapped to your business, and tracked over time.

DORA (via customer contract)

Article 28 requires financial-entity customers to impose ICT risk-management terms on their providers by contract — audit rights, incident-notification duties, exit provisions, sub-outsourcing controls. You are bound by what the contract requires, not by DORA directly, unless you separately qualify as a financial entity.

NIS2 (via customer contract)

Article 21 imposes a supply-chain security duty on essential and important entities, which in practice extends security expectations to their suppliers through contract and questionnaire. The conjunctive scope test for who counts as an essential/important entity is 50+ employees on its own, or (under 50) both annual turnover AND balance sheet exceeding EUR 10M — that's your customer's test, not yours, unless you separately meet it.

How Cyber Supplier works

1

Onboard in minutes

Quick signup, then 5 questions about your business — sector, locations, data flows. No credit card required.

2

Get your compliance map

See exactly which regulations apply to your business, where the gaps are, and what severity each carries.

3

Act on it

A prioritised task list, document templates, and an evidence pack organised for audit — guided through to a defensible compliance baseline.

Daily regulatory horizon scanning

ComplyOne scans EU regulatory sources every day — directives, implementing acts, regulator guidance, enforcement notices. When something changes that affects your obligation map, you get a structured alert: what changed, why it applies to you, and what you need to do. No more discovering enforcement deadlines from a news headline.

How to approach software, saas and service vendors selling to regulated financial and critical-infrastructure customers compliance

1

Read the actual contract clauses, not the cover email

A customer's 'DORA requirements' email usually links to specific contract clauses — audit rights, notification windows, sub-processor approval, exit assistance. Extract exactly what's being asked before responding generically. Different customers' DORA-driven clauses are not identical.

2

Build one evidence pack, reuse it per customer

Security questionnaires from different regulated customers overlap heavily — ISO 27001 status, incident-response plan, sub-processor list, penetration-test cadence, data-flow diagrams. Assemble this once as a structured pack rather than re-answering the same questions from scratch for every deal.

3

Track incident-notification commitments separately from your own policy

A contract clause committing you to notify a customer within a fixed window after an incident is a commercial obligation, not a regulatory one — but missing it damages the relationship exactly like missing a legal deadline would. Track it against the specific window each contract sets, not a generic internal SLA.

4

Know your own sub-processors before a customer asks

DORA and NIS2 supply-chain duties are chain-shaped — your customer's regulator cares about their exposure through you, and increasingly through your own vendors. Maintain a current sub-processor list before it's requested under audit, not after.

5

Decide, deliberately, whether you're actually in scope yourself

Some vendors grow into direct DORA or NIS2 scope — as a critical ICT third-party provider under DORA's oversight regime, or by crossing NIS2's own size/sector thresholds. That's a different, larger compliance programme than responding to contract flow-down. Revisit the question as you grow rather than assuming the answer never changes.

Swiss-hosted

All data hosted in Switzerland — outside US data-access frameworks.

9 EU regulations

GDPR, AI Act, NIS2, DORA, FADP, UK GDPR, Data Act, CSRD, AMLR — one platform.

Daily horizon scanning

Regulatory changes alerted, mapped to your obligations, every day.

Frequently asked questions

Are we directly regulated under DORA or NIS2?+

Not automatically. DORA applies directly to financial entities (banks, insurers, investment firms, payment institutions and similar) and to ICT providers formally designated as 'critical' under DORA's oversight regime — a small, named list. NIS2 applies directly to entities meeting its own sector and size tests. Most software and service vendors are neither — but still feel both laws through customer contracts.

What exactly is a DORA-driven contract clause asking us to do?+

Typically: cooperate with the customer's audit rights, notify them within a set window if you have a security incident affecting their data or service, maintain the sub-processors you disclosed (or seek approval before adding new ones), and support an orderly exit if the contract ends. The specific wording varies by customer — read the actual clause, not a summary of DORA in general.

We serve five different regulated customers with five different questionnaires — do we need five separate answers?+

No — the underlying facts (your security posture, incident-response process, sub-processor list, certifications) are the same regardless of who's asking. Build one structured evidence pack and map each customer's specific questionnaire format onto it, rather than re-deriving the answers each time.

How fast do we need to notify a customer after an incident?+

That's set by your contract, not by DORA or NIS2 directly — but it's often modelled on the regulatory timelines those laws set for the regulated entity itself. DORA's own initial-notification clock for a financial entity is 4 hours from classification of the incident as major; NIS2's is 24 hours of becoming aware of the significant incident. A customer's contractual window for you is commonly tighter than either, precisely so they have time left to make their own regulatory deadline after hearing from you.

How quickly can we get started?+

The compliance check takes about 5 minutes and identifies which contract-driven requirements are most likely to apply based on your customer base. From there, ComplyOne tracks the DORA Article 28 contract checklist, supports security-questionnaire responses against your evidence pack, and exports a supply-chain evidence pack you can hand to any customer or auditor.

See where you stand — in 60 seconds

Free compliance check, just 5 quick questions. No credit card required — get your obligation map and gap report.

Related guides

Practical guidance for software, saas and service vendors selling to regulated financial and critical-infrastructure customers.