Regulation
DORA: does it apply to you? (Usually not)
DORA is often mentioned in AI contexts, but the law targets a narrow group. Here is the straight answer on whether you need to care.
The short answer: if you are not a financial company (or an IT provider to the financial sector), DORA probably does not apply to you. We’ll go through it anyway, so you can put the question to rest with a clear conscience.
What DORA is
DORA (Digital Operational Resilience Act) is an EU regulation intended to make the financial sector resilient to IT disruptions and cyberattacks. It has applied since January 2025, and in Sweden the Finansinspektionen supervises compliance.
Who it applies to
- Banks, insurance companies, payment service providers, fund management companies, crypto companies, and others.
- Critical IT providers to these (e.g., large cloud providers).
Are you an ordinary consultant, shop, agency, or tradesperson? Then you are not covered.
When it may still affect you
Two cases to keep track of:
- You sell IT services to the financial sector. Then your financial customers may impose DORA requirements on you as a subcontractor: regarding contracts, incident reporting, and security.
- You work in finance. Then DORA applies to your employer, and it affects which tools you are allowed to use.
What you do if it applies to you
Start from the Swedish Financial Supervisory Authority’s guidance, map your IT providers and their contracts, and prioritize providers with clear EU data storage and documented security. Our provenance labeling and certification information can be a first screening, but the final assessment is made by your compliance function.
Tools with a strong security profile — for example the password manager 1Password, the cloud storage Nextcloud, and Bitwarden — are often easier to defend in a DORA review than unknown consumer services.
For everyone else: this was one less thing to worry about.
Sources
Tools mentioned
Bitwarden
Bitwarden Inc.
The open-source standard among password managers with low price and selectable EU region for data storage. The catch: the company is American, so the CLOUD Act applies regardless of where data is stored. If you want to avoid it completely you must self-host yourself.
- Open source with annual third-party audits
- EU server region can be selected at registration
- American company covered by the CLOUD Act even with EU storage
Best for: Cost-conscious small businesses that want open source and the option to self-host
Nextcloud
Nextcloud
German platform for files, collaboration, chat and calendar, Europe's great alternative to Google Workspace and Microsoft 365.
- Comprehensive: files, chat, calendar, documents
- German, can run on own EU servers
- Requires server operation
Best for: Companies that want control over files and collaboration within the EU.
1Password
AgileBits Inc.
The market's most polished password manager with the industry's broadest certification portfolio (ISO 27001/27017/27018/27701, SOC 2). The catch: Canadian company with American venture capital, no free tier, and not open source.
- Best in class on usability and design, which drives high adoption among employees
- EU data residency can be selected at account creation
- No free tier, only 14-day trial
Best for: Companies that prioritize usability and certifications over EU jurisdiction
Related articles
This is general information, not legal advice. See How we review.