DORA datasheet

DORA for financial institutions in two minutes.

What the Digital Operational Resilience Act requires, whom it affects — and why an on-premise licence is not an ICT service within the meaning of the regulation, according to BaFin’s published position.

To the Sentinel validation layer

General information, not legal advice. Applicability and classification must be assessed case by case. As of August 2026.

The facts

The regulation at a glance

Legal actRegulation (EU) 2022/2554 — Digital Operational Resilience Act (DORA)
Applicable since17 January 2025
Whom it affectsFinancial entities (banks, insurers, investment firms and others) and their ICT third-party service providers
Four pillarsICT risk management · ICT incident reporting · digital operational resilience testing · ICT third-party risk management
Supervisor (DE)BaFin

DORA incident reporting runs in parallel with the NIS2 reporting logic: NIS2 incident reporting in practice →

The crux

The form of procurement decides: licence or service

Art. 3(21) DORA deliberately defines ICT services broadly — classifying a specific procurement remains the financial entity’s task. For the line between licence and SaaS, BaFin’s DORA FAQ draws a clear boundary:

“Pure software licences are typically usage rights that do not constitute an ICT service within the meaning of Art. 3 No. 21 DORA.”

— BaFin, DORA FAQ on ICT third-party risk management, on isolated software procurement (translated)

“Software-as-a-Service applications are an ICT service that falls under Art. 3 No. 21 DORA when procured on an ongoing basis.”

— BaFin, DORA FAQ, on pure Software-as-a-Service (translated)

On-premise licence

  • The Sentinel validation layer runs offline inside your perimeter — no network access, 185 tests, delivered as a pure usage right.
  • Per BaFin’s position, not an ICT service (Art. 3 No. 21).
  • The vendor does not become a registered ICT third-party service provider.
  • No contractual obligations from Art. 30, no register entry, no exit plan (Art. 28).

Hosted service (SaaS)

  • The same software procured as an ongoing hosted service — data and logic run at the provider.
  • An ICT service when procured on an ongoing basis (Art. 3 No. 21).
  • The provider falls within the ICT third-party framework.
  • Minimum contract contents (Art. 30), register entry and exit strategy (Art. 28).
BaFin also notes: maintenance and support contracts accompanying a licence can themselves be ICT services. What counts is the actual form of procurement, not the label. For purchasing this means: because the validation layer ships as an offline licence, buying it triggers neither the third-party register nor exit planning — which is how even a one-person company can supply a regulated financial institution.
Its use in an audit

Evidence you can put in front of the examiner

The validation layer binds every detection rule deterministically against Microsoft’s own KQL parser; whatever cannot be verified against your real schema is flagged rather than silently shipped. The resulting report documents reproducibly that your detections hold — evidence towards DORA’s expectations for resilience testing and record-keeping. The report stays with you; the validation runs inside your perimeter.

How the validation works technically →

Not legal advice. This datasheet is general information and does not replace legal counsel. Whether DORA applies to your organisation, and how a specific procurement is to be classified, is for your legal advisors and, where relevant, BaFin. No deadlines, thresholds or article numbers are invented here; the quoted statements come from the BaFin FAQ and Regulation (EU) 2022/2554. As of August 2026.

Let’s talk about your DORA context

On-premise, offline, verifiable — for regulated financial institutions and their security teams. Directly at info@tippel.ai.