About dorasupplier.eu
dorasupplier.eu explains the Digital Operational Resilience Act from one specific position: that of a company selling ICT services to a bank, an insurer, a payment institution or an investment firm, and receiving a DORA contract addendum as a result. This page says who is behind that explanation and how it is written.
Who publishes this site
dorasupplier.eu is published by SEQ SIA (registration No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq. OffSeq is an offensive-security company: penetration testing, security assessments and continuous threat monitoring. Contact: support@offseq.com.
This is a vendor-run resource. It is not a supervisor, a standards body, a law firm or an independent publication, and it does not present itself as one.
Who writes the content
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Pages carry team attribution rather than a byline. Every page lists its sources so that a reader can check the basis for a statement instead of taking it on trust.
How the content is made
- Every article of DORA quoted here is taken from the text of Regulation (EU) 2022/2554 as published on EUR-Lex, with the article number, so you can read the clause in its surroundings.
- The same applies to the delegated and implementing regulations: (EU) 2024/1773 on the contractual-arrangements policy, (EU) 2025/532 on subcontracting, (EU) 2025/1190 on threat-led penetration testing and (EU) 2024/2956 on the register of information.
- The list of designated critical ICT third-party providers is reproduced from the document the European Supervisory Authorities published on 18 November 2025, in its own order and spelling.
- National filing dates are taken from the supervisor that publishes them. Where only one Member State’s date has been checked, the page says which one rather than generalising across the Union.
- Where the Regulation is silent or conditional, the site says so. Article 30(2)(i) requires the contract to state the conditions of participation in training, for example, and Article 13(6) says financial entities include providers “where appropriate”. Both facts appear, because only quoting the first would overstate the duty.
- No figures are used that cannot be traced to a primary source. Market sizes, contract counts and supplier-population estimates are omitted rather than repeated.
- The “Updated” date moves only when the text actually changes; an automated content-hash ledger reverts unearned date bumps.
- Everything is readable without an account, a cookie banner or an email address.
The clause decoder
The contract clause decoder runs entirely in your browser. It maps the choices you make onto the clause sets in Article 30 and the consequences the Regulation attaches to them, and it shows the same content whether or not JavaScript is available. Your selections are not transmitted, not written to browser storage and not added to any outbound link. It reads the Regulation, not your contract, and it says so on the panel.
Conflict of interest, stated plainly
The company that publishes this site sells penetration testing, threat-led testing support and security assurance work to exactly the companies this site is written for. That is a direct commercial interest in you concluding that you need help, and every recommendation here should be read with that in mind.
- Links to OffSeq services are our own links, not an independent recommendation. Footer links to them carry
rel="nofollow sponsored". - No vendor pays to be mentioned here. There is no sponsored content, no advertising and no affiliate links.
- Article 27(1) sets a qualification bar for anyone performing a threat-led penetration test. This site states that bar rather than claiming to clear it, and you should ask us to evidence points (a) to (e) like any other tester.
- Most of what this site teaches can be acted on without hiring anyone. The Regulation, the delegated acts and the ESAs’ publications are all free to read, and every one of them is linked.
What this site is not
It is not legal advice, and it is not a substitute for reading your own contract. DORA sets a floor for what must be in the arrangement; your customer is free to demand more, and frequently does. Where the two differ, the contract in front of you governs.
Corrections
If something here is wrong, out of date or unfairly characterised, write to support@offseq.com. We correct substantive errors and move the update date visibly rather than quietly.