Open the register builder →

Does your SaaS vendor belong in your DORA register?

Every contractual arrangement for ICT services belongs in your Register of Information — and "ICT services" reaches much further than most firms expect. Here is the plain-English test: what counts, the grey areas everyone argues about, what changes when a vendor supports a critical function, and the four questions that settle any vendor in two minutes.

The test, in one sentence

DORA treats as ICT services the digital and data services provided through ICT systems on an ongoing basis — with traditional analogue telephone services the notable carve-out. Three words do the work: digital, ongoing, relied on. If a service is delivered digitally, runs continuously rather than as a one-off, and your firm leans on it to operate, it belongs in the register.

What that catches

VendorVerdictWhy
Cloud hosting (AWS, Azure, GCP…)InThe canonical ICT service — digital, ongoing, relied on.
SaaS your operations run on (core ledger, CRM, comms, accounting)InSoftware delivered as an ongoing service is an ICT service, whatever the department using it.
Market data & data feedsInData services provided through ICT systems are named in the definition.
Managed IT / managed security (MSP, SOC)InOngoing digital operation of your estate by a third party.
Intra-group IT (a group service company)InStill an ICT third-party arrangement — recorded as intra-group, but recorded.
A perpetual software licence, self-hosted, no ongoing serviceGreyThe licence itself is a one-off; any ongoing support, maintenance or update contract around it points back in. Assess the arrangement, not the label.
Consultants writing a reportGreyProfessional services aren't ICT services — unless what they actually deliver is the ongoing operation of a system.
Analogue telephone lineOutThe definition's explicit carve-out.

The distinction that actually matters: critical or important

Everything above goes in the register — but the register is not a flat list. The consequential call is whether the provider supports a critical or important function of your firm. For those arrangements, DORA demands more of the contract itself:

This is exactly where registers fail validation: a provider marked critical with no recorded exit strategy or audit rights is one of the first gaps a regulator's automated check flags.

The four questions that settle any vendor

  1. Is it delivered digitally, through ICT systems? If it's a person or a paper process, it's not an ICT service.
  2. Is it ongoing? A subscription, a service contract, continuous availability — versus a genuine one-off purchase.
  3. Does your firm rely on it to operate? Reliance — not contract size — is what the regime cares about.
  4. Does it support a critical or important function? If yes: exit strategy, audit rights, and the concentration lens apply on top.

Yes to the first three: it goes in the register. Yes to all four: it goes in with the full critical-function treatment.

What about tools that never touch your data?

An increasingly common case: software that runs entirely on your own machines — browser-native tools where nothing is hosted and no data leaves the firm. Registration is driven by reliance, not only by data flow, so the honest answer is: the classification is an assessment your firm makes with its counsel. But the architecture materially changes what that assessment weighs — there is no hosted service whose outage interrupts a process holding your data, no data-processing relationship, and nothing to exit from. We've set out that argument, as it applies to CleanDesk itself, on our trust page — with the architecture facts stated so your counsel can make the call.

Recording it properly

For every arrangement the register wants the details a validator will actually check: the provider's LEI (checksum-valid), country of provision, the service description, contract dates and annual cost, the criticality flag — and for critical providers, the exit-strategy and audit-rights answers. Missing or malformed entries here are precisely what NCA ingestion checks reject. The full register walkthrough is here.

Build a register that survives the cross-check

Open the register builder →
Structure-checked against the published ESA rules — LEI checksums, criticality controls, exit & audit gaps flagged. In your browser · nothing uploaded

This guide is general information, not legal advice. Definitions and requirements are set by Regulation (EU) 2022/2554 (DORA) — notably Articles 3, 28 and 30 — and the ESA templates; confirm the current requirement against the regulation and, where needed, qualified counsel. CleanDesk is decision-support: it flags and drafts, your firm reviews and files.