ART. 30
Every bank asks. Every quarter.
Since January 2025, EU financial entities must run due diligence on every ICT provider. If you sell software to banks, insurers or fintechs, the questionnaires are already landing in your inbox.
Regulation (EU) 2022/2554 · In force since 17 Jan 2025
Your customers — banks, insurers, fintechs — must now run DORA due diligence on every ICT vendor they use. VendorDORA is the readiness toolkit that gets your Article 30 answers, evidence and register of information done once, and reused everywhere.
The problem
ART. 30
Since January 2025, EU financial entities must run due diligence on every ICT provider. If you sell software to banks, insurers or fintechs, the questionnaires are already landing in your inbox.
200+ QUESTIONS
Each institution sends its own format — Excel portals, PDF forms, procurement platforms. Your team rewrites the same security answers from scratch, every single time.
DEAL RISK
Procurement won't close until your DORA answers are in. Weeks of back-and-forth kill momentum — and sometimes the deal itself.
What's inside
01
Pre-written, engineer-reviewed answers mapped to DORA Articles 28–30, RTS on ICT risk management, and the most common bank questionnaire sections.
02
A ready-to-adapt model for the contractual documentation your customers' regulators expect — including the clauses Article 30 mandates.
03
Exactly which certificates, policies and test reports to attach — ISO 27001, penetration tests, BCM plans — and how to present gaps honestly.
04
Map your own ICT subcontractors and concentration risk the way examiners will ask about it, before they ask.
05
The operational-resilience commitments banks look for: notification timelines, severity classes, escalation contacts.
06
When ESAs guidance or national interpretations shift, you get a plain-English diff of what changed for your answers.
Free resource
The nine areas a bank's due-diligence questionnaire covers, what to prepare for each and which evidence closes the answer.
Free sample
The question as it arrives, the answer you send, the evidence that closes it — register, subcontractors, incidents, exit.
Early access
The toolkit launches soon. Join the list now and lock the price below — no charge today, no obligation.
Self-serve, for one product team
€249€399
One-time · lifetime updates to the answer library
We adapt it to your stack with you
€990€1.500
One-time · includes 3 working sessions
Questions
You can — and most teams try. The catch is time and reuse: drafting defensible Article 30 answers takes days of senior engineering time you'd rather ship with, and every new customer questionnaire restarts the exercise. The toolkit is that first draft, already reviewed against RTS expectations and real bank questionnaires, plus the update briefings that keep it true. You still own the final wording; we remove the blank page and the quarterly refresh.
No. VendorDORA is an operational toolkit built by engineers who have answered these questionnaires. It prepares your answers and evidence; your legal counsel reviews contractual commitments.
The opposite. DORA applies to your customers regardless of your size, and small vendors are exactly who banks scrutinize hardest. The toolkit is sized for teams without a compliance department.
DORA is an EU regulation, so it applies to any ICT provider selling into EU financial entities — wherever your company is incorporated.
You get one email when the toolkit launches, with early-bird pricing reserved for the list. Founding members also get a 30-minute setup call to adapt the materials to their stack.