• Overview
    Key features
    • Enterprise cloud platform
    • Observability
    • Auto-scaling
    • Multiframework
    • Security
    Frameworks
    • Django
    • Next.js
    • Drupal
    • WordPress
    • Symfony
    • Magento
    • See all frameworks
    Languages
    • PHP
    • Python
    • Node.js
    • Ruby
    • Java
    • Go
  • Industries
    • Consumer Goods
    • Media/Entertainment
    • Higher Education
    • Government
    • Ecommerce
  • Pricing
  • Featured articles
    • Switching to Platform.sh can help IT/DevOps organizations drive 219% ROI
    • Organizations, the ultimate way to manage your users and projects
  • Support
  • Docs
  • Login
  • Watch a demo
  • Free trial
Meet Upsun. The new, self-service, fully managed PaaS, powered by Platform.sh.Try it now
Blog

DORA Compliance: How Platform.sh supports our financial services customers

securitycompliance
08 Jul, 2025
Sophie Van der Kindere
Sophie Van der Kindere
Data Privacy Counsel

The Digital Operational Resilience Act (DORA) is set to reshape how financial institutions in the EU manage and contract with their technology providers. Since January 17, 2025, DORA requires financial entities to meet stricter rules for managing digital risks, especially when it comes to the third-party ICT (Information and Communication Technology) service providers they rely on.

While Platform.sh is not directly subject to DORA–we are a Platform-as-a-Service (PaaS) provider, not a regulated financial entity, some of our customers are, and for them, the new regulation creates real contractual and operational obligations.

We are ready to help!

Why DORA matters to you and how we support it

DORA was introduced to strengthen the financial services industry’s ability to withstand IT-related disruptions. It applies not just to outsourcing, but to all ICT services. This includes cloud platforms like Platform.sh, where our infrastructure and deployment automation plays a key role in the digital delivery chain for banks, insurance firms, investment funds, and other financial entities.

One of DORA’s central requirements is that contracts with third-party ICT service providers must contain specific clauses to help financial entities manage digital risk, maintain oversight, and cooperate with regulators. These provisions vary depending on whether the ICT services are deemed to support “critical or important functions.”

To assist our customers in meeting these new expectations, our legal team has prepared a DORA Contractual Addendum. This addendum aligns with requirements under Articles 28 and 30 of DORA and reflects the key areas DORA covers, including service levels, data handling, subcontracting, termination rights, and incident response.

This DORA Contractual Addendum is available upon request and is designed to easily integrate with our standard agreements, helping customers close any regulatory gaps quickly and without unnecessary complexity.

Do Platform.sh services support a “critical or important function”?

One of the distinctions DORA introduces is between standard third-party ICT services and those that support “critical or important functions.” These are functions where a disruption could severely impact a financial entity’s ability to operate or remain compliant with applicable laws.

At Platform.sh, our default is that our services will not necessarily fall into this category. That said, we understand that each customer’s setup is unique. If you believe our platform supports critical or important functions within your organization, we’re happy to have that conversation. We will work with you to ensure the DORA Addendum reflects the heightened standards required for such services.

What you need to do

For our part, Platform.sh is committed to being a proactive and responsible partner. If you’re an existing customer and need DORA-compliant terms, your account manager or legal contact can provide you with our DORA Contractual Addendum.

Together, we’ll ensure your digital operations remain resilient, compliant, and ready for the future.

For questions or to request the Dora Contractual Addendum, kindly contact us via Support, or by visiting the Platform.sh Trust Center to contact customer care.

Get the latest Platform.sh news and resources
Subscribe

Related Content

Common Magento deployment pitfalls and how cloud automation fixes them

Common Magento deployment pitfalls and how cloud automation fixes them

Company
AboutSecurity and complianceTrust CenterCareersPressContact us
Thank you for subscribing!
  •  
Field required
G2 Award - Grid Leader - Spring 2025Certified B CorporationIBM Cloud for Financial Services Validated
System StatusPrivacyTerms of ServiceImpressumWCAG ComplianceAcceptable Use PolicyManage your cookie preferencesReport a security issue
© 2025 Platform.sh. All rights reserved.
Supported by Horizon 2020's SME Instrument - European Commission 🇪🇺