DORA Compliance: What Your IT Provider Must Deliver
A practical guide to DORA compliance for hedge funds. Learn what your IT provider must deliver to meet the Digital Operational Resilience Act requirements.
Nerdster Team
Ask your IT provider one question: how do you support our DORA obligations? If the answer takes longer than a minute and contains no documents, you have found your first gap.
The Digital Operational Resilience Act is enforceable for specified EU financial entities. A UK hedge fund is not automatically directly in scope because it trades in European markets or has an EU connection; the legal entity, authorisation and operating model matter. An in-scope firm must still manage the risks and contracts around relevant ICT providers.
This guide covers what DORA requires of you, what to demand from your provider, and the questions that will tell you within an hour whether you are covered.
What DORA compliance actually requires
DORA is prescriptive rather than principles-based. The DORA requirements sit in five pillars, and you have to evidence every one of them:
- ICT risk management — a documented framework for identifying, protecting against, detecting, responding to, and recovering from ICT incidents.
- Incident reporting — standardised reporting of major ICT incidents to your competent authority, inside strict timeframes.
- Resilience testing — regular testing, including threat-led penetration testing for systemically important firms.
- ICT third-party risk management — oversight and due diligence of every ICT provider you use, your MSP included.
- Information sharing — voluntary arrangements to exchange threat intelligence with other financial entities.
Pillar four is where many firms find gaps. An in-scope entity must manage ICT third-party risk and relevant contracts. Direct EU oversight applies only to providers formally designated as critical, not to every MSP. Every hedge fund IT operating committee should understand which suppliers support important services and who owns the relationship.
Expect your IT provider to prove five things
The continuity documents to ask for on day one
Your provider should hold and share their own business continuity plans, disaster recovery procedures, and incident response playbooks. DORA Article 28 also means you need contractual assurances covering availability targets, where your data lives, who they subcontract to, and your right to audit.
If those documents are missing or out of date, you have found a practical gap to address.
Incident reporting that meets DORA’s reporting timetable
DORA’s initial report for a major ICT incident is due within four hours after classification as major and no later than 24 hours after awareness. You cannot classify what you have not been told about.
So your provider needs monitoring that detects in real time and an escalation path that feeds your compliance workflow directly. Ask them for their average time from detection to client notification. You are looking for a number you can write into a policy, not a reassurance.
Resilience testing before a regulator asks
DORA wants scenario-based testing, not just a vulnerability scan. For larger funds inside the threat-led penetration testing regime, your provider should either run red team exercises aligned to TIBER-EU or bring in someone who can.
At a minimum, every fund should run quarterly vulnerability assessments, an annual penetration test, and a tabletop disaster recovery exercise. Your provider should be organising all three and holding the evidence.
The providers your fund cannot run without
DORA takes concentration risk seriously — too many financial entities depending on the same ICT provider. Most of that is aimed at the hyperscalers, but it lands on you as a documentation duty.
Keep a register of your critical ICT providers, their subcontractors, and the jurisdictions your data is processed in. Your MSP should be maintaining it with you and flagging when it changes.
The four DORA gaps we find most
We work with hedge funds across London, and the same four things are missing almost every time a DORA readiness assessment starts:
- No ICT risk register. You track investment risk to the decimal point and have nothing equivalent for technology.
- No third-party oversight process. The provider relationship runs on goodwill rather than contractual response times and audit rights.
- Backups that have never been restored. They exist, and nobody has tested them under controlled conditions. Under DORA, an untested backup counts for nothing.
- No incident classification framework. Without an agreed definition of “major”, you cannot start the reporting clock, let alone meet it.
These gaps are much easier to fix before an incident than during one.
A DORA readiness checklist for your provider
Take these into your next review and write down the answers:
- Can you send us your business continuity and disaster recovery documentation today?
- What are your contractual response times for incident detection and notification?
- How do you manage and disclose your subcontracting chain?
- What resilience testing have you run in the last 12 months, and can we see the report?
- Can you give us structured incident data we can use in a regulatory submission?
- Where is our data stored, and under which jurisdictions?
- What is the exit plan if we move away from you?
If your provider struggles on more than one of these, start looking at alternatives while you still have time to move calmly.
One framework for DORA and the FCA
The FCA’s operational resilience rules apply to specified UK firms, which must identify important business services, set impact tolerances and test their ability to remain within them. DORA is a separate EU regime with more prescriptive ICT requirements.
If you are dual-regulated across the UK and the EU, treat that overlap as an opportunity. Build one framework that satisfies both, rather than running two compliance programmes that describe the same systems in different words.
Starting where the gap is widest
DORA compliance is not a project you finish. It is an operating discipline, and it works best when your IT provider is involved in the framework itself, not only in the day-to-day support.
At Nerdster we help hedge funds, private equity firms and wealth managers maintain the technical controls, records and testing evidence used in FCA and DORA work where those regimes apply. If you are unsure about scope, confirm it with legal or compliance advisers; we can then assess the technology and set out practical priorities.