What DORA Requires for Software Dependencies
DORA Article 8 requires financial entities to maintain a register of all ICT assets and their information assets. This register must document: all ICT systems in use, the software components within those systems, the interdependencies between systems, and the third-party service providers (including software vendors) upon which those systems depend. The register must be updated regularly and made available to competent authorities upon request.
While DORA does not use the specific term "Software Bill of Materials," the practical requirements of the ICT asset register overlap significantly with SBOM content — particularly the requirement to document software components, their versions, and the relationships between them. Organizations that have already built SBOM programs have found that their SBOM data provides a strong foundation for the DORA ICT register.
ICT Third-Party Risk Management
DORA places significant emphasis on third-party ICT risk — the risk from software vendors, cloud providers, and other technology service providers upon which financial entities depend. Financial institutions must: assess the concentration risk from critical ICT third-party providers; conduct thorough due diligence on third-party ICT services; require contractual provisions for access to SBOMs and vulnerability information from critical technology vendors; and monitor the security posture of critical third-party providers on an ongoing basis.
Who Is Affected
DORA applies to a broad range of financial entities: credit institutions (banks), payment institutions, electronic money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, pension funds, trading venues, and critical ICT third-party providers that serve these entities. The regulation also affects non-EU technology companies that provide ICT services to EU financial entities — a significant extraterritorial scope.
The Connection to SBOM Programs
Financial institutions with mature SBOM programs are in a significantly better position to comply with DORA's ICT asset management requirements. An SBOM provides the component-level detail that the ICT register requires for software assets, while SCA tooling provides the continuous monitoring capability that supports DORA's requirement for ongoing vulnerability tracking. Organizations that have not yet invested in SCA and SBOM tooling should treat DORA compliance as the business case for that investment in 2025.
Support DORA Compliance with Fossity's ICT Asset Tracking
Fossity — Fossity helps financial institutions meet DORA ICT asset management requirements with comprehensive SBOM generation and continuous component monitoring. Build the software component inventory that DORA requires — and the vulnerability intelligence to keep it current.
Visit Fossity.com →