DORA for ICT Third-Party Providers: What SaaS Vendors Must Test (2026 Guide)
Pentestas Team
Security Analyst

💫 DORA for ICT third-party providers — the short version
- If you sell software, cloud or IT services to EU financial entities, DORA reaches you by contract — there is no vendor exemption.
- Your customers must maintain a register of information on you and secure contractual rights to testing, audit and evidence (DORA Art. 28-30).
- Expect third-party risk teams to ask for penetration testing evidence on the product you provide — scoped, re-tested, and mapped to the risk it covers.
- A vendor that can hand over continuous, assessor-ready testing evidence wins faster reviews and fewer stalled deals.
Plenty of B2B SaaS and cloud vendors read DORA, saw ‘financial entities’, and assumed it was someone else's problem. It is not. If your product supports a function at an EU bank, insurer, payment firm or investment house, DORA's third-party rules reach you — through the contract your customer is now required to put in place.
This is the vendor's side of DORA: how the obligation flows to you, what your customers must now demand, and specifically what penetration testing evidence you need ready before their third-party risk team asks — because they will.
How it reaches you
DORA has no vendor exemption
DORA governs the financial entity, but Articles 28-30 make managing ICT third-party risk a core obligation — which means the requirements land on you through the contract. Your customers must keep a register of information covering every ICT provider, secure specific contractual provisions (audit and access rights, security requirements, incident cooperation, sub-outsourcing controls, and exit strategies), and pay closer attention where you support a critical or important function.
The largest, most systemic providers can additionally be designated critical ICT third-party providers and fall under a direct EU oversight framework run by the European Supervisory Authorities. Most vendors will not be designated — but nearly all will feel DORA through customer contracts and questionnaires.
How DORA reaches a SaaS vendor
What they will ask
The evidence your customers now need
A financial entity's third-party risk team cannot simply take ‘we take security seriously’ for an answer any more — DORA requires them to evidence your resilience. In practice that means requests for: the scope and results of penetration testing on the service you provide; proof that exploitable findings were remediated and re-tested; your testing cadence, especially after significant change; and how quickly you would detect and report an incident that touches their data.
Vendors who treat this as a once-a-year PDF end up stuck in review, because the PDF is stale by the time procurement reads it. Vendors who can produce current, mapped evidence on demand close reviews fast.
What to test
Scoping your product for DORA-driven reviews
Scope the service the way your customer's function depends on it. That means the external surface they reach over the internet and the internal surface behind your own perimeter — the internal APIs, admin planes, and, for multi-tenant SaaS, the isolation controls that keep one customer's data away from another's. Tenant-isolation failures are the finding a financial customer fears most, and the one a shallow external-only test never reaches.
Test at both the application and network layers, re-test every exploitable finding after you fix it, and keep the evidence in a form you can share — scope, proof, remediation, and re-test, mapped to the risk each one covers.
What your assessor opens first
Make it repeatable
Continuous evidence beats the annual scramble
The vendors who turn DORA into a sales advantage are the ones whose product is tested continuously, so the evidence pack is always current and every review starts from a green baseline. Instead of scrambling to commission a test each time a big financial prospect sends a questionnaire, you hand over living evidence and keep the deal moving.
For vendors, Pentestas runs as pentesting as a service your financial-entity customers can point to directly: an AI penetration testing system that tests your product after every release. It is penetration testing with AI at the core — penetration testing with Claude for deep exploit reasoning and penetration testing with DeepSeek for high-volume regression — and as a B2B SaaS pentest it produces the mapped, re-tested evidence a bank's third-party risk team actually asks for.
Cost of staying in-scope
FAQ
DORA for ICT third-party providers, quick answers
I'm a SaaS vendor, not a bank — does DORA apply to me?
Indirectly but firmly. DORA binds the financial entity, but its third-party rules (Art. 28-30) require your customers to push security, testing, audit and exit terms into your contract. If you serve EU financial entities, you will feel DORA through those contracts and their third-party risk reviews.
What is a 'critical ICT third-party provider'?
The largest, most systemically important providers can be designated critical and placed under a direct EU oversight framework run by the European Supervisory Authorities. Most vendors won't be designated, but nearly all still inherit DORA obligations through customer contracts.
What penetration testing evidence will customers ask for?
Scope and results of testing on the service you provide, proof that exploitable findings were fixed and re-tested, your testing cadence (especially after significant change), and — for multi-tenant SaaS — evidence that tenant isolation holds.
How do we keep evidence current without constant manual tests?
Test continuously. A platform that re-runs after every release keeps a live, mapped evidence pack, so a financial customer's review starts from a current baseline instead of a stale annual PDF.
A straight answer on manual vs. AI
A manual penetration test by senior humans is still the deepest assurance you can show a financial customer, and it costs 20-30× more than an AI-driven platform — both belong in a vendor's story. Use continuous, AI-driven pentesting to keep an always-current evidence pack — full-scope, re-tested after every release, mapped to the risk — so third-party reviews never stall on stale artefacts. Commission a manual pentest for the annual deep assessment your biggest customers expect. Show both and you out-position vendors who show a yearly PDF.
Bottom line: DORA has no vendor exemption. If you sell to EU financial entities, the obligation reaches you through their contracts, and their third-party risk teams will ask for penetration testing evidence on your product. Keep that evidence continuous, full-scope and mapped, and DORA becomes a reason customers pick you rather than a deal-blocker.
Turn DORA third-party reviews into a fast yes
Continuous, full-scope penetration testing of your product with assessor-ready, mapped evidence your financial customers can point to, from $79/month.
See plans & pricing
Alexander Sverdlov
Founder of Pentestas. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
