What DORA software covers, and what stays a board decision
Software can hold your DORA register and your incident evidence. It cannot decide materiality, own the risk, or write your exit plan.
You can buy software that files your DORA register on time. You cannot buy anything that decides which of your suppliers is critical. That second call sits with your board, and Finanstilsynet will ask how you made it.
In compliance meetings with Norwegian financial firms this year, the opening question is almost always which product to buy. It is a fair question with an awkward answer. About half of what DORA asks for is record-keeping, and software does record-keeping better than people do. The other half is judgment, and no vendor signs for judgment.
Getting the split wrong costs you rework before it costs you anything else. Norwegian firms had to report their register of ICT service contracts to Finanstilsynet by 13 March 2026, and the files went on to the European Banking Authority by 31 March. Several came back rejected. A rejected file is rarely a product failure. It is usually nobody owning the data inside it. If you have not scoped your obligations yet, our DORA checklist for Norwegian financial firms is the cheaper place to start.
What DORA software covers well
Software covers the parts of DORA that are records, scanning and stored evidence. Three of them are worth paying for.
The register of information is the first. It is the list of every ICT service contract you hold, reported in a fixed EU format (DORA Article 28(3), with the format set by Implementing Regulation (EU) 2024/2956). A spreadsheet gets a small firm through the first reporting cycle. In the reviews I have run, it starts breaking in the second, once contract renewals, subcontractors and function mappings move independently of each other. Reporting mechanics get their own treatment in our piece on DORA audit and reporting requirements.
Asset inventory and vulnerability management are the second. DORA asks you to identify all sources of ICT risk and all information and ICT assets on a continuous basis (Articles 8(2) and 8(3)). Tenable maps its own DORA guidance to exactly those two paragraphs, plus Article 16(1)(d) on detecting anomalies, in its DORA asset inventory documentation. That is an honest claim: the platform finds assets and grades their weaknesses. It does not hand you compliance. The testing duty that sits next to it is covered in DORA and recurring penetration testing.
Detection, response and incident evidence are the third. You have four hours from the moment you classify an incident as major to notify Finanstilsynet, and no more than 24 hours from becoming aware of it (Delegated Regulation (EU) 2025/301). You cannot start reconstructing the timeline at hour three. CrowdStrike keeps detection data searchable for years and reports on it, which is the raw material your notification is built from. What you do with that material is set out in DORA continuity and response plans.
What no DORA product decides for you
Four duties stay with people, and buying more software moves none of them.
Materiality comes first. Before you sign an ICT contract, you have to assess whether it supports a critical or important function, whether it deepens your concentration risk, and whether the provider survives due diligence (Article 28(4)). A platform stores that assessment. Someone in your firm still has to make it, and defend it to a supervisor.
Board ownership is second. DORA places final responsibility for ICT risk on the management body, and expects board members to keep their knowledge current through training (Article 5). No purchase order transfers that.
The exit strategy is third. For any provider sitting behind a critical or important function, DORA wants a documented exit plan that has been tested and reviewed, with an alternative identified and a transition plan written (Article 28(8)). “We would move to another provider” is a sentence, not a plan.
Classification on the day is fourth. EU rules set the criteria and the materiality thresholds for a major incident (Delegated Regulation (EU) 2024/1772), but a person applies them while the incident is still running and the facts are half known. Call it too late and you miss the four-hour window. Call everything major and you spend the year filing noise.
The decision to put in front of your board
Decide who owns the DORA data before you decide what to buy. Name the person accountable for the register, the person who makes the criticality call on a new supplier, and the person who classifies an incident as major at two in the morning. Then buy tooling that serves those three roles. Firms that buy first tend to end up with a licence and a half-empty register.
See who FM CyberSecurity is and what we are certified to deliver on our about page. Or take 30 minutes with Johan Vorgaard on where your own split falls, through our DORA advisory service.
FAQ
Is there one DORA compliance software that covers the whole regulation?
No. Products cover the record-keeping and telemetry duties well: the register of information, asset inventory, vulnerability management, incident logging and evidence retention. The duties that require a decision, materiality, board ownership, exit planning and incident classification, are not features. Any vendor claiming full DORA coverage is describing their own scope, not the regulation’s.
Do we need a dedicated tool for the register of information?
It depends on contract count and how often your supplier base changes. Firms with a short and stable list of ICT contracts manage the first cycles from a controlled spreadsheet. Once subcontractors and function mappings start moving between reporting rounds, a spreadsheet costs more in reconciliation than a tool costs in licence.
Can our ICT provider classify an incident as major on our behalf?
No. The obligation to classify and report sits with the financial entity. Your provider can supply the timeline, the technical detail and the impact data, and a good one will. The decision that the incident is major, and the notification to Finanstilsynet, remain yours.
Does buying Tenable or CrowdStrike make us DORA compliant?
No, and neither vendor claims it does. Tenable covers asset discovery and vulnerability management, which maps to the identification duties in Article 8. CrowdStrike covers detection, response and the retained evidence you build an incident report from. Both are inputs to a DORA programme that you still have to run.
Drafted with AI assistance, reviewed and edited by Johan Vorgaard and the FM CyberSecurity editorial team.