Compliance · Last updated

DORA Compliance: What Your IT Provider Must Deliver

A practical guide to DORA compliance for hedge funds. Learn what your IT provider must deliver to meet the Digital Operational Resilience Act requirements.

Nerdster Team

Ask your IT provider one question: how do you support our DORA obligations? If the answer takes longer than a minute and contains no documents, you have found your first gap.

The Digital Operational Resilience Act (DORA) has applied since 17 January 2025 to specified EU financial entities. A UK hedge fund is not automatically directly in scope because it trades in European markets or has an EU connection; the legal entity, authorisation and operating model matter. A UK firm can be caught by DORA indirectly in two ways: through an EU-authorised entity in the group, such as an EU fund manager, or as a supplier whose EU financial clients must write DORA’s contract terms into their ICT arrangements. An in-scope firm must still manage the risks and contracts around relevant ICT providers.

This guide covers what DORA requires of you, what to demand from your provider, and the questions that will tell you within an hour whether you are covered.

What DORA compliance actually requires

DORA is prescriptive rather than principles-based. The DORA requirements sit in five pillars, and you have to evidence every one of them:

  1. ICT risk management — a documented framework for identifying, protecting against, detecting, responding to, and recovering from ICT incidents.
  2. Incident reporting — standardised reporting of major ICT incidents to your competent authority, inside strict timeframes.
  3. Resilience testing — regular testing, including threat-led penetration testing at least every three years for firms identified by their regulator.
  4. ICT third-party risk management — oversight and due diligence of every ICT provider you use, your MSP included.
  5. Information sharing — voluntary arrangements to exchange threat intelligence with other financial entities.

Pillar four is where many firms find gaps. An in-scope entity must manage ICT third-party risk and relevant contracts. Direct EU oversight applies only to providers formally designated as critical, not to every MSP. Every hedge fund IT operating committee should understand which suppliers support important services and who owns the relationship.

Expect your IT provider to prove four things

The continuity documents to ask for on day one

Your provider should hold and share their own business continuity plans, disaster recovery procedures, and incident response playbooks. DORA Article 30 also sets out what the contract must contain, including service levels, the locations where your data is processed, the conditions for subcontracting and, for services supporting critical or important functions, your rights of access, inspection and audit.

If those documents are missing or out of date, you have found a practical gap to address.

Incident reporting that meets DORA’s reporting timetable

DORA’s initial report for a major ICT incident is due within four hours after classification as major and no later than 24 hours after awareness. An intermediate report follows within 72 hours of the initial notification, and a final report within a month. The timetable is set in Commission Delegated Regulation (EU) 2025/301, one of the technical standards that now sit under DORA. You cannot classify what you have not been told about.

So your provider needs monitoring that detects in real time and an escalation path that feeds your compliance workflow directly. Ask them for their average time from detection to client notification. You are looking for a number you can write into a policy, not a reassurance.

Resilience testing before a regulator asks

DORA wants scenario-based testing, not just a vulnerability scan. For larger funds inside the threat-led penetration testing regime, your provider should either run red team exercises aligned to TIBER-EU or bring in someone who can.

DORA itself requires in-scope firms, other than microenterprises, to test all ICT systems and applications supporting critical or important functions at least yearly (Article 24). A sensible baseline is quarterly vulnerability assessments, an annual penetration test, and a tabletop disaster recovery exercise. Your provider should be organising all three and holding the evidence.

The providers your fund cannot run without

DORA takes concentration risk seriously — too many financial entities depending on the same ICT provider. Most of that is aimed at the hyperscalers, but it lands on you as a documentation duty.

DORA requires a register of information covering every contractual arrangement for ICT services, marking those that support critical or important functions (Article 28). Record each provider’s subcontractors and the jurisdictions your data is processed in. Your MSP should be maintaining it with you and flagging when it changes.

What DORA requires on contingency plans and threat intelligence

Contingency plans

DORA calls them ICT business continuity plans and ICT response and recovery plans. Article 11 requires an ICT business continuity policy, put into practice through documented plans that keep critical or important functions running, contain an incident and set out crisis communications. Those plans must be tested at least yearly and after any substantive change to the systems behind critical or important functions. For firms other than microenterprises, the tests must include cyber-attack scenarios and switchovers to backup capacity.

The duty reaches your suppliers too. Where a provider supports a critical or important function, Article 30 requires the contract to oblige it to implement and test its own business contingency plans. That is why the continuity documents above are the first thing to ask for.

Threat intelligence

Article 13 requires in-scope firms to have the capabilities and staff to gather information on vulnerabilities and cyber threats and to analyse how they could affect the firm. Sharing threat intelligence with other financial entities is voluntary under Article 45. If your provider runs your security monitoring, it is a natural source of that intelligence, so ask how threat information reaches you and who acts on it.

The four DORA gaps we find most

We work with hedge funds across London, and the same four things are missing almost every time a DORA readiness assessment starts:

  • No ICT risk register. You track investment risk to the decimal point and have nothing equivalent for technology.
  • No third-party oversight process. The provider relationship runs on goodwill rather than contractual response times and audit rights.
  • Backups that have never been restored. They exist, and nobody has tested them under controlled conditions. DORA requires backup and restoration procedures to be tested periodically (Article 12).
  • No incident classification framework. Without an agreed definition of “major”, you cannot start the reporting clock, let alone meet it.

These gaps are much easier to fix before an incident than during one.

A DORA readiness checklist for your provider

Take these into your next review and write down the answers:

  • Can you send us your business continuity and disaster recovery documentation today?
  • What are your contractual response times for incident detection and notification?
  • How do you manage and disclose your subcontracting chain?
  • What resilience testing have you run in the last 12 months, and can we see the report?
  • Can you give us structured incident data we can use in a regulatory submission?
  • Where is our data stored, and under which jurisdictions?
  • What is the exit plan if we move away from you?

If your provider struggles on more than one of these, start looking at alternatives while you still have time to move calmly.

One framework for DORA and the FCA

The FCA’s operational resilience rules apply to specified UK firms, which must identify important business services, set impact tolerances and test their ability to remain within them. From 18 March 2027 the FCA adds its own operational incident and third-party reporting rules, which cover similar ground to DORA’s reporting and register duties. DORA is a separate EU regime with more prescriptive ICT requirements.

If you are dual-regulated across the UK and the EU, treat that overlap as an opportunity. Build one framework that satisfies both, rather than running two compliance programmes that describe the same systems in different words.

Starting where the gap is widest

DORA compliance is not a project you finish. It is an operating discipline, and it works best when your IT provider is involved in the framework itself, not only in the day-to-day support.

At Nerdster we help hedge funds, private equity firms and wealth managers maintain the technical controls, records and testing evidence used in FCA and DORA work where those regimes apply. If you are unsure about scope, confirm it with legal or compliance advisers; we can then assess the technology and set out practical priorities.

DORAcompliancefinancial serviceshedge funds

FAQ

DORA Compliance: your questions answered

Does DORA apply to UK firms?

Not automatically. DORA has applied since 17 January 2025 to specified EU financial entities, and a UK firm is not directly in scope just because it trades in European markets. DORA can reach a UK firm indirectly, through an EU-authorised entity in their group or as a supplier whose EU financial clients must write DORA's contract terms into their ICT arrangements.

What does DORA require for contingency plans?

Article 11 requires an ICT business continuity policy put into practice through documented plans, plus ICT response and recovery plans. They must be tested at least yearly and after substantive changes to systems behind critical or important functions, and for firms other than microenterprises the tests must include cyber-attack scenarios and switchovers to backup capacity.

What are DORA's threat intelligence requirements?

Article 13 requires in-scope firms to have the capabilities and staff to gather information on vulnerabilities and cyber threats and analyse how they could affect the firm. Sharing threat intelligence with other financial entities under Article 45 is voluntary.

How quickly must a major ICT incident be reported under DORA?

The initial notification is due within four hours of classifying the incident as major and no later than 24 hours after becoming aware of it. An intermediate report follows within 72 hours of the initial notification, and a final report within a month.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report