Back to Blog
Compliance9 min read

DORA for ICT Third-Party Providers: What SaaS Vendors Must Test (2026 Guide)

P

Pentestas Team

Security Analyst

7/28/2026
DORA for ICT Third-Party Providers: What SaaS Vendors Must Test (2026 Guide)
DORA third-party ICT provider penetration testing for SaaS vendors

💫 DORA for ICT third-party providers — the short version

  • If you sell software, cloud or IT services to EU financial entities, DORA reaches you by contract — there is no vendor exemption.
  • Your customers must maintain a register of information on you and secure contractual rights to testing, audit and evidence (DORA Art. 28-30).
  • Expect third-party risk teams to ask for penetration testing evidence on the product you provide — scoped, re-tested, and mapped to the risk it covers.
  • A vendor that can hand over continuous, assessor-ready testing evidence wins faster reviews and fewer stalled deals.

Plenty of B2B SaaS and cloud vendors read DORA, saw ‘financial entities’, and assumed it was someone else's problem. It is not. If your product supports a function at an EU bank, insurer, payment firm or investment house, DORA's third-party rules reach you — through the contract your customer is now required to put in place.

This is the vendor's side of DORA: how the obligation flows to you, what your customers must now demand, and specifically what penetration testing evidence you need ready before their third-party risk team asks — because they will.

🔗

How it reaches you

DORA has no vendor exemption

DORA governs the financial entity, but Articles 28-30 make managing ICT third-party risk a core obligation — which means the requirements land on you through the contract. Your customers must keep a register of information covering every ICT provider, secure specific contractual provisions (audit and access rights, security requirements, incident cooperation, sub-outsourcing controls, and exit strategies), and pay closer attention where you support a critical or important function.

The largest, most systemic providers can additionally be designated critical ICT third-party providers and fall under a direct EU oversight framework run by the European Supervisory Authorities. Most vendors will not be designated — but nearly all will feel DORA through customer contracts and questionnaires.

How DORA reaches a SaaS vendor

EU financial entitybound by DORAContract clauseArt. 28-30 termsYou, the vendormust show testingRegister of infoyour entryPentest evidencethey will ask
DORA has no vendor exemption — it flows to you through your customer's contract.
🎯

What they will ask

The evidence your customers now need

A financial entity's third-party risk team cannot simply take ‘we take security seriously’ for an answer any more — DORA requires them to evidence your resilience. In practice that means requests for: the scope and results of penetration testing on the service you provide; proof that exploitable findings were remediated and re-tested; your testing cadence, especially after significant change; and how quickly you would detect and report an incident that touches their data.

Vendors who treat this as a once-a-year PDF end up stuck in review, because the PDF is stale by the time procurement reads it. Vendors who can produce current, mapped evidence on demand close reviews fast.

🧠

What to test

Scoping your product for DORA-driven reviews

Scope the service the way your customer's function depends on it. That means the external surface they reach over the internet and the internal surface behind your own perimeter — the internal APIs, admin planes, and, for multi-tenant SaaS, the isolation controls that keep one customer's data away from another's. Tenant-isolation failures are the finding a financial customer fears most, and the one a shallow external-only test never reaches.

Test at both the application and network layers, re-test every exploitable finding after you fix it, and keep the evidence in a form you can share — scope, proof, remediation, and re-test, mapped to the risk each one covers.

What your assessor opens first

Scope + methodologysigned offFindings + PoCreal exploit evidenceRe-test proofbefore / afterIndependencetester separationRemediation logdates + owners
A DORA evidence folder is five things — most first attempts are missing two of them.

Make it repeatable

Continuous evidence beats the annual scramble

The vendors who turn DORA into a sales advantage are the ones whose product is tested continuously, so the evidence pack is always current and every review starts from a green baseline. Instead of scrambling to commission a test each time a big financial prospect sends a questionnaire, you hand over living evidence and keep the deal moving.

For vendors, Pentestas runs as pentesting as a service your financial-entity customers can point to directly: an AI penetration testing system that tests your product after every release. It is penetration testing with AI at the core — penetration testing with Claude for deep exploit reasoning and penetration testing with DeepSeek for high-volume regression — and as a B2B SaaS pentest it produces the mapped, re-tested evidence a bank's third-party risk team actually asks for.

Cost of staying in-scope

Manual pentest (periodic)$10k–$30k+once per cycle · stale in a dayAI platform (continuous)from $79/more-runs after every change
Point-in-time manual testing vs. continuous AI-driven coverage.

FAQ

DORA for ICT third-party providers, quick answers

I'm a SaaS vendor, not a bank — does DORA apply to me?

Indirectly but firmly. DORA binds the financial entity, but its third-party rules (Art. 28-30) require your customers to push security, testing, audit and exit terms into your contract. If you serve EU financial entities, you will feel DORA through those contracts and their third-party risk reviews.

What is a 'critical ICT third-party provider'?

The largest, most systemically important providers can be designated critical and placed under a direct EU oversight framework run by the European Supervisory Authorities. Most vendors won't be designated, but nearly all still inherit DORA obligations through customer contracts.

What penetration testing evidence will customers ask for?

Scope and results of testing on the service you provide, proof that exploitable findings were fixed and re-tested, your testing cadence (especially after significant change), and — for multi-tenant SaaS — evidence that tenant isolation holds.

How do we keep evidence current without constant manual tests?

Test continuously. A platform that re-runs after every release keeps a live, mapped evidence pack, so a financial customer's review starts from a current baseline instead of a stale annual PDF.

A straight answer on manual vs. AI

A manual penetration test by senior humans is still the deepest assurance you can show a financial customer, and it costs 20-30× more than an AI-driven platform — both belong in a vendor's story. Use continuous, AI-driven pentesting to keep an always-current evidence pack — full-scope, re-tested after every release, mapped to the risk — so third-party reviews never stall on stale artefacts. Commission a manual pentest for the annual deep assessment your biggest customers expect. Show both and you out-position vendors who show a yearly PDF.

Bottom line: DORA has no vendor exemption. If you sell to EU financial entities, the obligation reaches you through their contracts, and their third-party risk teams will ask for penetration testing evidence on your product. Keep that evidence continuous, full-scope and mapped, and DORA becomes a reason customers pick you rather than a deal-blocker.

Turn DORA third-party reviews into a fast yes

Continuous, full-scope penetration testing of your product with assessor-ready, mapped evidence your financial customers can point to, from $79/month.

See plans & pricing
Alexander Sverdlov

Alexander Sverdlov

Founder of Pentestas. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.