DORA in one diagram
Blockwyse Insights · October 1st, 2026
"Our vendor is DORA compliant" is one of the most common sentences in European financial services, and it rarely means what people think. DORA puts almost all of its obligations on the regulated firm. This picture shows where the technology provider actually sits.

Left: the regulated entity holds the obligations
Everything in the heavy box belongs to the bank, investment firm or crypto-asset service provider. The management body has "ultimate responsibility" for ICT risk (Article 5). The firm runs the risk framework, classifies incidents and reports major ones within 4 hours of classification, then at 72 hours and one month. It tests its systems yearly, with threat-led penetration testing every three years if its supervisor requires it. And it manages third-party risk: due diligence, a register of every ICT contract, and exit plans.
Right: the provider works through the contract
A provider such as Blockwyse usually has no direct DORA obligations. DORA reaches it through the contract its client must sign. Article 30 requires the provider to describe its service, name data locations, assist with incidents at a cost agreed in advance, cooperate with the client's supervisor, grant audit rights and support an exit. Subcontractors sit below the provider, and the client needs visibility of that chain too.
Dashed box: direct oversight for a few
The only place DORA supervises providers directly is the dashed box. The European Supervisory Authorities designate critical providers based on how many firms depend on them and how hard they are to replace. The first list, in November 2025, named 19, mostly large cloud and infrastructure companies. Their clients' obligations didn't change.
Dotted line: responsibility stays left
Article 28(1) says financial firms "remain fully responsible" when they use ICT providers. Service levels, incident data, audit evidence and exit plans cross the line. Accountability doesn't. When a supervisor asks why an incident report was late, "our vendor" is not an answer.
That's why the register of information matters. It is the supervisor's map of your right-hand boxes, and it's harder to draw than it looks: in the ESAs' 2024 dry run, only 6.5% of almost 1,000 registers passed every data quality check.
What to ask of your provider
A good provider makes your left-hand box easier to run. Look for contract terms that already cover Article 30, named data locations and subcontractors that drop straight into your register, incident alerts fast enough for a 4-hour clock, and an exit plan written on day one.
Frequently asked questions
Can a technology provider be "DORA compliant"?
Only in a limited sense. A provider can give its clients the contracts, controls and evidence they need. Only designated critical providers have direct DORA obligations.
Does DORA apply to crypto-asset service providers?
Yes. Article 2 brings MiCA-authorised crypto-asset service providers into scope alongside banks and investment firms.
Want to see where your stack sits on this diagram? We can map your digital asset providers against DORA's third-party rules. Get in touch or read how we contract with regulated institutions.
Sources: DORA (Regulation (EU) 2022/2554), Arts 2, 5, 17-19, 24-31; EBA, CTPP designation, 18 Nov 2025; ESAs 2024 dry run findings. General information only, not legal advice.
Disclaimer
Everything here is published openly and written for an undifferentiated audience. It describes markets, protocols, technology and risk, and presents facts separately from opinion. It contains no recommendations about crypto-assets, no price targets, no buy/sell/hold signals and no directional calls, and it is not tailored to the circumstances of any reader; nothing here is investment advice or a personal recommendation. We do not accept payment to publish coverage of any asset, protocol or venue, and neither the author nor any related party holds an undisclosed position in the assets discussed. Sources are cited where used; where none is cited, the analysis is the author's own. This note reflects the position as of the publication date and may become outdated. For more information: Terms of Service.
Transparency note
This article reflects our own views and conclusions. AI tools may have assisted with research, fact-checking, and language editing, but the content, opinions, and final judgment remain ours. Despite reasonable efforts to verify sources, errors or omissions may exist.