The month DORA compliance arrived in someone else's contract, at 75K MRR
A composite founder diary. A payments customer sent an eleven page DORA addendum with a one percent of turnover penalty clause. Four days of reading the regulation showed that no EU regulator could fine us at all, that the size relief is reserved for regulated firms, and that the real cost was free incident support written into the contract.
In this story
“Please countersign the attached DORA addendum by the 30th so we can keep you in the register.”
That was the whole email. No context, no explanation, just a PDF and a deadline, from the operations lead at a small Dutch payments company who had been paying us 75K MRR worth of seats for about fourteen months. I am not a bank. I am not in the EU. I run a workflow tool with a team of six. I spent the next four days convinced that a European regulator had quietly acquired the power to fine me, and I was wrong about that in a way that took reading the actual regulation to fix.
Quick answer (2026). This diary is a composite, assembled from several real engagements and reconstructed from my own notes and contracts. The numbers and the sequence are real; the company is not one company. Here is what I learned: if you are a software vendor selling to EU financial firms, the Digital Operational Resilience Act almost certainly does apply to you in the formal sense, and almost certainly gives no EU authority the power to fine you. The enforcement runs through your customer. That distinction is worth four days of reading, and nobody's compliance checklist draws it.
The addendum, and the sentence that scared me
The addendum was eleven pages. Most of it was ordinary vendor paperwork. One clause said we would submit to inspection by the customer's competent authority. Another said we would cooperate with a body called a Lead Overseer. A third referred to penalty payments of up to one percent of worldwide turnover.
One percent of worldwide turnover, for a six-person company, reads like a bankruptcy notice. I went looking for the exemption.
What every checklist told me
There is a large, well-funded genre of DORA explainer content, mostly published by vendors selling compliance tooling. I read about nine of them. They agree on the five pillars: risk management, incident reporting, resilience testing, third-party risk, information sharing. They agree on the date, 17 January 2025.
On the question I actually had, which was whether a regulator in Frankfurt could take money from my company, they said nothing at all. The closest any of them came was a line stating that ICT providers serving financial institutions must comply. That sentence is true and it is the reason I lost four days.
The letter of the alphabet that decides everything
Regulation (EU) 2022/2554 opens with a scope article listing twenty-one categories of entity, lettered (a) through (u). Credit institutions are (a). Insurance undertakings are (n). Crowdfunding services are (s). And at the bottom of the list, at (u), sits the category "ICT third-party service providers". So yes, I am in scope. The checklists are right.
Then the very next paragraph says that the entities "referred to in paragraph 1, points (a) to (t), shall collectively be referred to as" financial entities.
Points (a) to (t). Not (u).
Almost every operative obligation in the regulation is drafted as a duty of a financial entity. My category is deliberately excluded from that collective term by one letter. I am inside the regulation and outside the definition that carries its duties. The only machinery in the whole instrument aimed directly at category (u) is the Oversight Framework, and that framework reaches you only if you are formally designated as critical.
The relief is real, three tiers deep, and none of it is for me
I went hunting for a size exemption, the way you do. The regulation contains no occurrence of "de minimis", none of "small business", none of "small entity", none of "annual revenue", none of "number of employees", none of "business-to-business", and no safe harbour of any kind. I checked all of them.
What it does contain, thirty-four times, is the word microenterprise. There is a graded proportionality ladder built right into the definitions, and it is careful work. A microenterprise "means a financial entity, other than a trading venue, a central counterparty, a trade repository or a central securities depository, which employs fewer than 10 persons" and has turnover under two million euro. A small enterprise "means a financial entity that employs 10 or more persons, but fewer than 50 persons". A medium-sized enterprise "means a financial entity that is not a small enterprise and employs fewer than 250 persons".
Three rungs. Each one opens with the same four words. The relief for being small under DORA exists, it is detailed, and it is reserved entirely for regulated firms. My customer, with eleven staff, qualifies for proportionality. I, with six, do not, because the ladder is not addressed to anyone like me. That is not an oversight. It is what the regulation is for.
Doing the arithmetic on one percent
The penalty clause my customer's addendum gestured at is in Article 35, and it applies to designated critical providers. It says the periodic penalty payment "shall be imposed on a daily basis until compliance is achieved and for no more than a period of six months", at a rate of "up to 1 % of the average daily worldwide turnover of the critical ICT third-party service provider in the preceding business year".
Average daily. Not annual.
Six months is at most 184 days. At the absolute ceiling that is 184 lots of one percent of a single average day, which comes to 1.84 days of a year's revenue, or a fraction over half of one percent of annual turnover. There is also a grace period: no such decision can even be adopted until "after the expiry of a period of at least 30 calendar days" from notification of the underlying measures, and the payment is coercive rather than punitive, so it stops the moment you comply.
For comparison, the top tier of the GDPR is a fine of "up to 4 % of the total worldwide annual turnover of the preceding financial year". Both instruments say a percentage of worldwide turnover. One adjective sits between "worldwide" and "turnover" in the DORA version, and it makes the ceiling roughly eight times smaller. I had read the clause three times without seeing the word daily.
The list is published, and you can read it
The part that ended the anxiety properly is Article 31(9). The supervisory authorities "shall establish, publish and update yearly the list of critical ICT third-party service providers at Union level".
There is a list. It is public. The European Banking Authority announced on 18 November 2025 that the authorities "publish today the list of designated critical ICT third-party providers", following an assessment that weighed systemic importance, support of critical functions, and "the level of substitutability of its services". The list itself names Amazon Web Services, Google Cloud, Microsoft, Bloomberg, LSEG, NTT DATA and their peers. Designation requires a finding against "all of the following criteria", including whether the financial system could absorb your disappearance.
Three further things I did not expect. Designation "shall not apply to the following" includes "ICT third-party service providers providing ICT services solely in one Member State to financial entities that are only active in that Member State", so a purely domestic vendor is carved out. Designation can be declined in substance but not in form, since you get a hearing and six weeks to make your case. And a provider not on the list "may request to be designated as critical". You can volunteer for direct European supervision. I still find that remarkable, and I understand it now: for a vendor whose whole market is banks, being overseen centrally is cheaper than being audited by every customer separately.
What it actually cost me
None of the above meant the addendum was free. It meant the cost was labour rather than fines, and it landed in the contract clauses my customer is legally obliged to impose.
The expensive one is Article 30(2)(f). Every such contract must set out "the obligation of the ICT third-party service provider to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante" when an incident occurs. Read that twice. Incident support for regulated customers is either free or pre-priced, forever, by regulation. We had been quoting emergency engineering at an hourly rate. That option is gone unless the number is in the contract before anything breaks, so we put a number in the contract.
The second is Article 30(2)(b), which requires "the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed", plus advance notice of any change. We had never enumerated our subprocessor regions in a contract. Doing it properly took a fortnight and turned up two vendors nobody had inventoried.
Who can actually compel me to do anything
The clearest sentence in the regulation on this point is in the powers granted to competent authorities. They include "summoning representatives of the financial entities for oral or written explanations", and separately, "interviewing any other natural or legal person who consents to be interviewed".
Summon the regulated firm. Interview anyone else, with their consent.
That is the whole architecture in two clauses. The regulator cannot compel me. It can compel my customer, whose continued authorisation depends on managing me. So the pressure arrives with full force, applied by a party who is being penalised for my conduct and whose only real lever over me is to leave. I have never been in a situation where the person enforcing a rule against me was the person being punished under it.
What I got wrong
I was wrong three times, and the corrections are the useful part.
I assumed being listed in the scope article meant being subject to the duties. It does not; the duties attach to a defined term that excludes my category.
I assumed the absence of a small-vendor exemption meant the drafters had not thought about size. They had thought about it in detail, across three tiers, and directed all of it elsewhere.
And I assumed legal uncertainty would help me. I had spent a lot of last year reading about another statute where the absence of clear law is a genuine defence, because the penalty tier there turns on whether a reasonable reading was available. DORA has no such tier for providers. I checked. There is no negligence standard for me to fall under, because there is no penalty aimed at me to reduce. Uncertainty was neither a shield nor a threat. It was just noise.
What actually happened
Scroll to see more
| What I assumed | What the text says |
|---|---|
| DORA does not apply to me | It does, at Article 2(1)(u) |
| Therefore I owe its duties | The duties bind points (a) to (t) only |
| There must be a small-vendor exemption | Three size tiers exist, all defined as a financial entity |
| Penalties are 1% of turnover | 1% of average DAILY turnover, capped at six months |
| That is GDPR-scale exposure | It is roughly one eighth of the GDPR ceiling |
| Only huge vendors get designated | True, and the list is published yearly |
| The regulator is my problem | The regulator can only summon my customer |
| Compliance means security work | Most of the cost was contract drafting and free incident support |
Limits
I am not a lawyer and this is not advice. I read the consolidated English text on EUR-Lex; national implementing measures under Article 50 vary by member state and I did not review any of them. My arithmetic on the six-month ceiling treats a month as a calendar month and takes 184 days as the upper bound. I could not verify the exact number of designated providers from the published PDF, because my extraction of it was incomplete, so I have named companies I could confirm and given no total. Everything here describes a non-EU vendor selling to EU financial entities; if you are established in the EU, other instruments apply that I have not read.
The one thing I would tell you
When a regulation lands on your desk through a customer's contract, find out whether the regulator can actually reach you before you spend anything. The answer is usually in the definitions, not the obligations, and it is usually one paragraph long.
Then read the denominator on every penalty figure. The word between the percentage and the word turnover is doing more work than the percentage is.
Written by
Anya PetrovaFrequently asked questions
Is this a real founder's diary?
It is a composite. The events, contract clauses and figures are drawn from several real engagements and reconstructed from my own notes, but they are not all one company and the business described is an assembled one. Every statutory quotation is verbatim from the primary source and linked.
Who needs to comply with DORA?
Article 2(1) of Regulation (EU) 2022/2554 lists twenty-one categories, from credit institutions at (a) through to ICT third-party service providers at (u). But Article 2(2) defines the collective term financial entities as points (a) to (t) only. Software vendors are in scope of the regulation and outside the term that carries almost all of its duties.
Can an EU regulator fine a software vendor that is not a financial entity?
Not in the ordinary case. The direct penalty machinery in Article 35 applies only to providers formally designated as critical. Article 50 gives competent authorities power to summon representatives of financial entities, but only to interview any other person who consents. A non-designated vendor is reached through its customer's contract, not by the regulator.
What is the maximum DORA penalty for an ICT third-party provider?
For a designated critical provider, Article 35 sets a periodic penalty payment of up to 1 percent of average daily worldwide turnover, imposed daily for no more than six months. At the ceiling that is roughly 1.84 days of annual revenue, a little over half of one percent of yearly turnover, and it stops once you comply. The GDPR top tier of 4 percent of annual turnover is about eight times larger.
How do I know if my company is a critical ICT third-party service provider?
You check the published list. Article 31(9) requires the European Supervisory Authorities to establish, publish and update it yearly, and the first list was published on 18 November 2025. It names hyperscalers and global infrastructure firms. Designation also requires a finding against all of the Article 31(2) criteria, including systemic impact and lack of substitutability.
What does a DORA contract addendum actually require from a vendor?
The binding content is the mandatory clause list in Article 30(2). The two that cost real money are (f), which requires incident assistance at no additional cost or at a cost determined in advance, and (b), which requires you to name the countries where services are performed and data is processed and to give notice before changing them.
More stories
The month CMMC Level 2 was suspended and I kept the half I sign myself, at 69K MRR
A composite founder diary. The July 2026 suspension of CMMC Phase II cancelled the certification a third party performs on you and left the self-assessment you sign yourself, along with a contract clause whose own deadline had passed 3,116 days earlier.
The month a 1988 video store law reached my demo page at 74K MRR
A composite founder diary. At 74K MRR a letter arrived calling us a video tape service provider, on the strength of a two minute demo clip and an advertising pixel. What I found in 18 U.S.C. 2710: no size exemption, no state of mind tier, a 2,500 dollar floor set in 1988, and a definition of who may sue that three federal appeal courts read two different ways.
The month my bank was allowed not to read the name, at 82K MRR
A composite founder diary at 82K MRR. When a payment order names one person and numbers another, the receiving bank may pay on the number and need not check the name. The escape the statute gives a non bank originator is deleted by a signature, and the right to chase the stranger follows the loss.