Industries · Finance, insurance, SaaS
DORA compliance for finance, insurance and SaaS providers
DORA has applied since 17 January 2025 to banks, insurers, payment institutions, investment firms and more than a dozen other types of financial entities. A SaaS provider is not a financial entity, but DORA reaches it through the contract. We help both sides show the same thing: who is responsible for what, and where the evidence is.
// In short
DORA in one paragraph
Regulation (EU) 2022/2554 covers 20 types of financial entities, from credit institutions to insurance intermediaries, with exclusions such as insurance intermediaries that are micro, small or medium-sized enterprises. It requires an ICT risk management framework, reporting of major incidents, a testing program and management of ICT third-party risk, including a register of information. In Poland, the competent authority is the KNF.
As of 24 September 2026. Sources: Regulation (EU) 2022/2554, Articles 2 and 64; Dz.U. 2026 item 252, Article 2(14a) of the KSC Act (in Polish).
DORA and NIS2 in Poland: what applies to whom
| Who | DORA | KSC Act (NIS2 in Poland) |
|---|---|---|
| A bank or a financial market infrastructure entity listed in Annex 1 | Yes | Yes, but without the provisions on the ISMS and on reporting major incidents, because DORA covers those. Registration in the KSC register stays, and manager liability, yearly training and the criminal record check apply accordingly (Article 8i) |
| An insurer, a payment institution or another financial entity not listed in the KSC annexes | Yes, with the exclusions in Article 2(3) of DORA | Only the obligations after a high-risk vendor decision or a protective order, and none for entities under Article 16 of DORA (Article 67k) |
| A SaaS, cloud or managed service provider serving financial entities | Not as a financial entity. Requirements arrive through the contract (Article 30), and the ESAs can designate a provider as critical (Article 31) | Possible as a cloud computing or managed service provider in Annex 1, if Poland is the main establishment (Article 5a(3)) |
Sources: DORA, Dz.U. 2026 item 252 (in Polish).
// Register of information
The register of information: built from data, not a spreadsheet
A financial entity keeps a register of all its contractual arrangements for ICT services, marks those supporting critical or important functions and reports to its supervisor every year (Article 28(3)). The 2026 cycle used data as of 31 December 2025, collected in Poland by the KNF. The next cycle is likely to use 31 December 2026; the KNF will confirm the date.
- We build the register from data on contracts, providers and functions, with an owner for every entry
- Quality checks run before submission, not after the file is rejected
- Next year is a data update, not a new spreadsheet
As of 24 September 2026. Source: KNF (in Polish).
Resilience testing: what DORA requires, and what it doesn't
At least once a year (Article 24(6))
A financial entity other than a microenterprise tests all ICT systems and applications supporting critical or important functions at least yearly.
Independent testers (Article 24(4))
Tests are carried out by independent parties, internal or external. With an internal tester, conflicts of interest have to be avoided.
A range of tests (Article 25)
Vulnerability scans, open source analysis, source code reviews, scenario-based tests, performance tests and penetration tests, chosen according to risk.
Fixes and validation (Article 24(5))
Procedures to prioritize and remediate findings, and a check that each gap is actually closed.
TLPT only for designated entities (Article 26)
Threat-led penetration testing on live production systems, at least every 3 years, applies to entities identified by the competent authority. A regular penetration test does not replace it.
We don't run TLPT or TIBER tests
We run penetration tests as part of the Article 25 program and re-check the fixes. We scope them by critical or important function, not by a list of IP addresses. Details: penetration testing.
// SaaS providers
SaaS for financial entities: what goes into your contract
An ICT services contract with a financial entity has to include the elements in Article 30 of DORA. Your customer will ask how you meet them, and for critical or important functions it will ask for evidence.
Every contract (Article 30(2))
- A description of the services and the conditions for subcontracting
- Where services are provided and data processed, with advance notice of changes
- Access to, recovery and return of data when the contract ends
- Incident assistance at no extra cost, or at a cost agreed in advance
- Cooperation with the supervisory authorities
Critical or important functions (Article 30(3))
- Measurable service levels
- Business contingency plans that you test
- Taking part in the customer's TLPT
- Rights of access, inspection and audit
- An exit strategy with a transition period
How to prepare
- A penetration test report with re-checked fixes
- A business continuity plan with a test result
- A list of subcontractors and data locations
- A library of questionnaire answers backed by evidence
NIS2 lists SaaS among the cloud service models (recital 33). If your service meets the definition of a cloud computing provider in Article 2(4e) of the Polish KSC Act and Poland is your main establishment, the act can cover you regardless of DORA. You then apply the measures of Implementing Regulation (EU) 2024/2690 (Article 8b(1)). As of 24 September 2026.
// How we help
Services that fit finance and SaaS
01Register
A DORA register of information built from data
A data model for the register linked to contracts, providers and functions, with quality checks and owners.
Data platformsFirst step, 6 weeks
A register built from contract data
- Register data model and source map
- Quality checks before submission
- An owner for every entry
Key deliverable: a register generated from source data, ready for the next cycle
02Testing
Penetration tests of critical functions
The applications, APIs and cloud that critical or important functions depend on. A report with evidence for every finding.
Penetration testing03ICT providers
An evidence pack for financial customers
For SaaS providers: questionnaire answers and Article 30 requirements linked to evidence, before your customer asks.
DORA04Continuity
ICT business continuity
Continuity and recovery plans, restore tests and provider failure scenarios, with results for your supervisor or your customer.
Business continuity
// Scope
What we do, and what we don't
We agree the scope and date in writing before we start.
We do
- DORA gap analysis for one area: ICT risk, incidents, testing or third parties
- A register of information built from data, with quality checks
- Penetration tests of systems supporting critical or important functions
- An evidence pack for an ICT provider, mapped to Article 30
We don't
- TLPT or TIBER tests
- Reselling GRC tool licenses
- A year-long program on slides with no working first step
We designed FutureCode Evidence Box for finance and SaaS, among other industries: it runs inside your network without internet access, and every piece of evidence carries a hash and a timestamp.
// FAQ
Questions about DORA
Does DORA cover a small insurance intermediary?
No. Insurance, reinsurance and ancillary insurance intermediaries that are micro, small or medium-sized enterprises are excluded (Article 2(3)(e)). So are smaller insurers referred to in Article 4 of the Solvency II Directive (Article 2(3)(b)).
We provide SaaS to a bank. Does DORA cover us?
Not as a financial entity. You are an ICT third-party service provider, so the requirements reach you through the Article 30 contract terms, and for critical or important functions also through audit rights and taking part in the bank's TLPT. The European Supervisory Authorities can designate a provider as critical (Article 31). Separately from DORA, check whether the Polish KSC Act covers you as a cloud computing provider.
A bank falls under DORA and the KSC Act. Which rules apply?
The ISMS and the reporting of major incidents follow DORA. From the KSC Act, registration in the register of essential and important entities remains, and manager liability, yearly training and the criminal record check for staff doing Article 8 and 11 work apply accordingly (Article 8i). As of 24 September 2026.
When is the next register of information due?
The 2026 cycle used data as of 31 December 2025 (ESA deadline: 31 March 2026), collected in Poland by the KNF. The next cycle will likely use 31 December 2026. The KNF will confirm the exact dates, so plan your work around year-end data.
Does a penetration test count as TLPT?
No. TLPT under Article 26 is threat-led, runs on live production systems and is mandatory for entities designated by the competent authority, at least every 3 years. A regular penetration test belongs to the Article 25 testing program and helps you prepare for TLPT, but does not replace it.
From the blog: cloud and data security
Let's start with one DORA area
In 30 minutes we work out which DORA area has the biggest evidence gaps today: the register, testing, incidents or third parties.
Book a 30-minute callAre you a SaaS provider?
Send us the questionnaire or requirements from your financial customer. We will send back the scope and date of the first step. We reply within one business day.
Request the first step