DORA compliance for fintechs with EU licences.
You have obligations. Most of you aren't meeting them.

Payment institutions and e-money institutions that expanded into the EU are fully in scope for DORA. Your cloud-native stack, your dozens of SaaS vendors, your Stripe and AWS contracts — all of it needs to be mapped, documented, and submission-ready. We move fast for fintech clients.

DORA EU 2022/2554
Payment Institutions
E-Money Institutions
Register of Information
Article 30

You built on SaaS. DORA wants a map of every layer.

Fintechs run on cloud-native, heavily outsourced stacks — often 30-50 vendors touching critical functions. DORA requires you to map every one of them, classify which functions they support, document their subcontractor chains, and ensure your contracts include specific mandatory clauses. Most fintech compliance teams have never done this.

Your SaaS contracts weren't written for DORA

Stripe, Intercom, Salesforce, AWS, your payment gateway, your KYC provider — all standard commercial contracts. None of them include DORA's mandatory Article 30 clauses: audit rights, exit strategies, subcontractor disclosure, incident notification timelines. Renewals are coming.

Your Register of Information doesn't exist yet

The EBA ITS data model requires 15 interconnected templates covering every ICT vendor, the critical functions they support, and their subcontractor chains. Most fintechs filed nothing or filed a spreadsheet that fails the EBA data quality checks.

Your regulator knows what to look for

The Central Bank of Ireland, BaFin, and DNB are conducting active DORA reviews in 2026. Payment institutions and EMIs are on the list. The EBA peer review on DORA implementation is scheduled for Q3 2026. Firms with incomplete Registers received 60-day remediation notices in the first supervisory wave.

From gap to compliant. We move at fintech speed.

We understand that fintechs operate fast and don't have time for six-month consulting engagements. Our work is structured, fixed-scope, and produces supervisor-ready outputs — not slide decks.

€399

DORA Scoping Determination

A written memo confirming your exact DORA obligations — entity type, applicable articles, proportionality assessment, recommended next steps. Delivered in 3 business days. The right place to start.

€2,999

DORA Diagnostic

Two to three days of structured review across all five DORA pillars. Gap register, prioritised roadmap, board summary. Fixed price. Designed for fintechs that implemented in 2024 and need to know where they actually stand in 2026.

Register of Information

We map your full vendor stack — every SaaS tool, API, cloud provider, and subprocessor — against the EBA ITS data model. We classify critical functions, document subcontractor chains, and produce a submission-ready Register.

ICT Contract Review (Article 30)

We review your vendor contracts against Article 30 mandatory provisions and deliver a gap matrix with negotiation language for every missing clause. We prioritise contracts at risk of near-term renewal. Technical governance work — not legal advice.

Incident Reporting Framework

DORA's incident reporting timelines are tight: 4 hours for initial notification, 72 hours for the intermediate report, one month for the final. We design your decision tree, classification thresholds, and NCA reporting templates so your team can respond without scrambling.

Ongoing DORA Maintenance

Your Register needs updating as your vendor stack evolves. Your board needs quarterly ICT risk reviews. We provide affordable ongoing DORA maintenance at a fraction of what an internal hire would cost. Learn more →

Senior expertise. Fintech pace. Accessible pricing.

We work with fintechs that are too regulated to ignore DORA and too lean to hire a full-time compliance function. Our engagements are scoped to what you actually need.

We understand cloud-native stacks

We've mapped vendor ecosystems for fintech clients across multiple frameworks. We know how to classify Stripe, AWS, Twilio, and your KYC provider against DORA's critical function categories.

Cross-framework experience

DORA, ISO 27001, GDPR, PSD2. Where your existing controls already satisfy DORA requirements, we document that and move on. No rebuilding what you already have.

Fixed scope. Fixed price.

No open-ended retainers, no hourly billing surprises. You know what you're getting and what it costs before we start.

Written outputs every time

Gap registers, contract review matrices, board packs, Register builds. Documents that go in your compliance file and survive supervisory scrutiny.

John Smutniak, Managing Partner

John Smutniak

Managing Partner, Regulatory Compliance Practice

With a background in quantitative measurement and financial institution operations, John helps mid-market firms navigate complex regulatory frameworks without the overhead of a Big Four engagement. BS, Massachusetts Institute of Technology.

Free DORA gap review — written summary within 5 business days.

Tell us about your EU licence, your tech stack, and where you are on DORA. We'll come back with an honest picture of your gaps. No pitch. No obligation.

No obligation, no pressure Written summary within 5 business days Confidential — NDA on request Payment institutions and EMIs welcome

Your information is kept strictly confidential.

Thank you — we will be in touch within one business day.

Questions fintech teams ask us

Does DORA apply to my fintech if we only recently got an EU licence?

Yes. DORA applies from the date your entity is authorised as a payment institution, e-money institution, or other financial entity under EU law. There is no grace period for newly licensed firms. If you received your licence before January 2025, your DORA obligations were live from day one.

We are a US-headquartered company with an EU payment licence. Does DORA apply to us?

Yes. DORA applies to the EU-licensed entity regardless of where the parent company is headquartered. Your EU subsidiary or branch is a regulated financial entity and must comply in full. Your US parent's systems that support the EU entity's critical functions are also in scope for third-party ICT risk management.

What is the Register of Information and why is it hard for fintechs?

The Register of Information is a mandatory inventory of every ICT vendor contract supporting your critical functions, submitted annually to your national regulator in the EBA ITS format. Fintechs typically run on heavily outsourced, cloud-native stacks — dozens of SaaS tools, APIs, and subprocessors. Mapping all of these correctly is genuinely complex without structured help.

Our contracts with Stripe, AWS, and Intercom were signed before DORA. Do we need to update them?

Yes, if those services support critical or important functions. Article 30 mandatory clauses must be in every contract supporting critical functions. Contracts that predate DORA must be remediated at next renewal. If the renewal has already passed, seek an addendum now.

How long does DORA compliance take for a fintech with 30-100 staff?

For a fintech with a cloud-native stack and no prior DORA work, initial compliance typically takes 8-14 weeks. The Register of Information and ICT contract review tend to take longest. Fintechs with existing ISO 27001 or SOC 2 programmes can move significantly faster by mapping existing controls.

← Back to DORA Compliance overview