DORA, Regulation (EU) 2022/2554, has applied to EU financial entities since 17 January 2025. It covers ICT risk management, incident reporting, resilience testing and third-party risk. Teddy's agents map the requirements onto your controls, check every ICT contract against Art. 30 and keep the register of information current.

DORA is an EU regulation and applies directly, without national transposition. It covers banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and other financial entities, with proportionate rules for smaller ones. Here is what it asks for and where it lives in Teddy.
Strategies, policies and tools to protect ICT systems, detect anomalies, respond, recover and learn. Some smaller entities can apply a simplified framework under Art. 16.
The management body defines, approves and oversees the ICT risk framework, bears ultimate responsibility and keeps its knowledge current through regular training.
Classify ICT-related incidents with the EU criteria. For major incidents: an initial notification within 4 hours of classification and no later than 24 hours after becoming aware, then an intermediate and a final report.
A testing programme in which systems that support critical or important functions are tested at least yearly. Entities identified by the authority also run threat-led penetration testing at least every three years.
A third-party risk strategy and ICT contracts with the provisions of Art. 30, with stricter ones where a service supports critical or important functions.
A register of all contractual arrangements for ICT services, at entity and group level, in the EU templates and available to the competent authority on request.
DORA turned supplier management into a regulatory duty. Every ICT contract needs specific provisions, and the register of information has to be complete and current.
The Contract Agent lists missing clauses and suggests wording.
Teddy fills it in the official EU format from your contracts and supplier list.
Clear criteria and owners decide quickly whether an incident must be reported.
Legal holds the contracts, procurement holds the supplier list, and the register lives in a workbook with broken links. ChatGPT can explain Art. 30, but it cannot read your 400 contracts against it. Teddy's Contract Agent reads every ICT contract, flags missing provisions and fills the register from the source.
Miriam · LegalThe supervisor wants our register of information by month end.
Priya · ProcurementWhich of the 400 contracts support critical functions?
Tobias · ITBluefin moved our data to a new region. Is that in the contract?
Frank · CFODo we need an exit strategy for every supplier?
Claudia · CEOThe board wants the DORA status on Thursday.
Teddy's agents map the requirements, read the contracts and keep the register current. Legal and management decide, and a compliance engineer is there when the supervisor asks.
Teddy works out which DORA rules apply to each entity in your group and whether the simplified framework under Art. 16 is an option.
Requirements from Art. 5 to 16 are mapped onto the controls you already run for ISO 27001 or NIS2. You see what is covered and what DORA adds.
The Contract Agent reads each contract, marks whether the service supports a critical or important function and checks the provisions that apply.
The register of information is filled from the contracts themselves. New or changed contracts update the draft, and nothing is final before you approve it.
The Policy Agent drafts the classification checklist and the report templates, linked to your incident response, so the clock never surprises you.
Ask in plain language whether an incident is major or a contract is complete. Teddy answers from your live program. For supervisory requests, our compliance engineers are at your side.
Ask TeddyIs this incident major? Which contracts support critical functions? Teddy knows DORA and your setup.
Agents do the workContract checks, register entries, report templates and gap analysis, each with its source.
Our team backs you upCompliance engineers help with supervisory requests, register submissions and audits.
DORA applies directly to financial entities. ICT providers feel it through their contracts, because financial entities must include the Art. 30 provisions. Providers designated as critical are also overseen directly by the European Supervisory Authorities.
Much of the ICT risk management framework. DORA adds incident classification and reporting deadlines, resilience testing, specific contract provisions and the register of information.
Art. 30(2) lists provisions every ICT contract needs, such as data locations, service levels and termination rights. Art. 30(3) adds stricter ones for services that support critical or important functions, such as exit strategies and full audit rights.
Only if your competent authority identifies you for it. Every entity needs a testing programme, and systems that support critical or important functions are tested at least yearly.
Start with an Art. 30 check of your ICT contracts.
Reviewed by Sven Moritz, former CISO · October 2026
Institutions had a two-year window, and many still did not finish. Before the deadline, fewer than half were confident they would make it, and over a third planned full compliance only for 2026.
Register of information built from your contracts, every ICT contract checked against Art. 30 and the gaps listed with owners. After that, Teddy keeps the register current all year.
Many existing ICT contracts still lack the Art. 30 minimum clauses, and many agreements have no exit plan at all.
Supervisors ask for credible, tested exit strategies for critical or important functions. With critical cloud providers that is hard, and most institutions know it.
It has to reflect every contract signed or ended during the year, including tools teams bought on their own. Treat it as a living inventory, not an annual form.