If you are searching for a DORA-compliant document management system, the most important question is not whether a vendor displays a “DORA compliant” badge. DORA compliance remains the financial entity’s responsibility. What matters is whether the document management system gives your team the security controls, evidence, data portability and written ICT-provider terms needed to assess and manage the relationship.

The short answer

Folderit supports DORA readiness for financial-sector customers with encrypted document management, granular access control, audit trails, version history, workflows, e-signatures, EU-region hosting, backups and export capabilities. Folderit can also document relevant responsibilities in a DORA supplementary agreement for an agreed service scope. No software vendor, however, can make an organisation DORA compliant on its own.

What DORA means for document management

The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025. It covers a broad range of financial entities, including banks, payment and e-money institutions, investment firms, insurers, pension institutions, credit-rating agencies, crowdfunding providers and crypto-asset service providers. It also establishes obligations connected with ICT third-party service providers.

For a document management system, DORA is especially relevant in two ways. First, the financial entity needs reliable evidence for ICT risk management, incident handling, testing and third-party oversight. Second, its contract with an ICT provider must clearly describe the service, data arrangements, support, cooperation and exit rights.

That second point is central to DORA Article 30. It requires ICT service contracts to allocate rights and obligations in writing. The required clauses depend partly on whether the service supports a critical or important function.

What makes a DORA-compliant document management system?

“DORA-compliant document management system” is a useful search phrase, but it can be misleading if read as a certification claim. DORA regulates the financial entity’s overall digital operational resilience. The customer must classify its functions, assess ICT risk, maintain governance and registers, manage incidents, test resilience and oversee providers.

A DMS can support that work. It can supply appropriate controls, preserve evidence and provide contractual information for third-party due diligence. The final result depends on how the customer configures and uses the system, what documents it stores, which workflows it runs and whether the service supports a critical or important function.

How Folderit supports DORA compliance

For example, Folderit combines document control with features that help regulated teams maintain a clear and exportable evidence trail:

In addition, you can review Folderit’s public Security & Compliance overview, Data Processing Addendum, Privacy Notice, Terms of Use and sub-processor list during vendor due diligence.

DORA Article 30 checklist for a document management provider

Article 30(2) lists the baseline elements for ICT service contracts. Therefore, a financial entity should translate each requirement into a practical due-diligence question.

Service, data and security clauses

DORA contract areaWhat a financial entity should verifyFolderit’s approach for an agreed standard-service scope
Service description and subcontractingFunctions, service boundaries and conditions for subcontractingThe supplement can describe document storage and metadata, permissions, search, versioning, audit trails, workflows, e-signatures and ordered standard features. Additionally, Folderit publishes its current sub-processors online.
Service and data locationsRegions or countries where the service runs and where Folderit processes or stores dataFor the relevant cloud scope, Folderit hosts its main servers, customer documents and server-side backups in the EEA using AWS’s Ireland region. The supplement can also give customers advance written notice before a storage-location change.
Data protectionAvailability, authenticity, integrity and confidentiality controlsFolderit uses encryption in transit and at rest, access controls, audit logging, backups and documented technical and organisational measures.
Access, recovery and returnHow the customer can access, recover and retrieve its data, including at terminationStandard features let customers access, download and export their data. Contractual exit and data-return provisions support those capabilities.

Support, cooperation and exit clauses

DORA contract areaWhat a financial entity should verifyFolderit’s approach for an agreed standard-service scope
Service levelsSupport, recovery objectives, revisions and reviewStandard support applies. The parties can record relevant recovery objectives and customer-specific service levels in the signed agreement.
Incident assistanceSupport during an ICT incident and the treatment of additional costsFolderit offers reasonable assistance within standard support. The parties can scope and price work that goes beyond the agreement.
Regulatory cooperationCooperation with the customer, competent authorities, resolution authorities and appointed auditorsThe supplement can state cooperation duties. However, the parties separately agree any additional audits, on-site checks, special reports or integrations outside the standard service, and Folderit may charge for them.
Termination and transitionTermination rights, data portability and an orderly move to another provider or in-house solutionExport and return provisions support portability. Where needed, the parties can agree bespoke transition assistance separately.
Security awareness and trainingConditions for provider participation in the financial entity’s trainingFolderit applies internal ICT-security awareness measures. The parties can also agree Folderit’s participation in customer-specific training.
DORA Article 30 contract readiness covering service scope, data location, access control, recovery, audits and exit planning
A DORA-ready ICT services contract should address scope, data location, protection, recovery, cooperation and exit.

What Folderit’s DORA supplementary agreement adds

Folderit’s standard Terms of Use, Privacy Notice and DPA remain the contractual foundation. For an eligible financial-sector customer, a supplementary agreement can map the agreed standard service to the relevant Article 30(2) topics without silently expanding the service into unlimited audit, reporting or custom-development obligations.

As a result, this balance is useful for both sides. The customer gets written answers to the DORA questions relevant to the service it is buying. Folderit avoids creating vague promises that no provider could responsibly deliver without a defined scope.

Critical or important functions require a separate assessment

DORA Article 30(3) adds requirements when an ICT service supports a critical or important function. These include more precise service levels, reporting obligations, business-continuity testing, security measures, possible participation in threat-led penetration testing, expanded audit and inspection rights, and a mandatory transition period.

Folderit designed its current supplementary framework for a standard-service scope that the parties agree does not support a critical or important function. A customer planning to use Folderit in a critical or important function should raise that classification during due diligence. Both parties would then need to assess the use case and agree any additional terms before relying on the service for that purpose.

A precise compliance claim is a stronger one

Folderit does not claim that buying a DMS automatically makes a financial entity DORA compliant. Instead, Folderit offers practical controls, auditable records, current legal documentation and a contract path that can support the customer’s own DORA programme.

A practical DORA vendor due-diligence checklist

Therefore, before selecting any DORA-ready document management system, ask the provider these questions:

  1. Which exact functions and service components are included?
  2. Where are documents, metadata and backups stored and processed?
  3. Which sub-processors are used, and how are customers notified about changes?
  4. How are encryption, access control, audit logging and account security implemented?
  5. Can the customer export documents and relevant records in an accessible format?
  6. What support, recovery objectives and incident-assistance terms apply?
  7. What cooperation, audit and regulatory-access rights are included?
  8. What happens at termination, and which transition services cost extra?
  9. Has the financial entity classified the supported function as critical or important?

For the operational evidence your team should retain inside a DMS, see Folderit’s companion guide: DORA in 2026: Evidence Your DMS Must Capture.

Is Folderit the right DORA-ready DMS for your organisation?

Folderit is a strong fit for teams that want secure, user-friendly document management with traceable workflows, approvals, e-signatures, metadata, version history, audit trails and EU-region cloud hosting. For financial-sector customers, the contract can be supplemented with a focused DORA agreement when the proposed use and service classification fit the available scope.

This article is general product and compliance information, not legal advice. Your organisation should assess DORA applicability, service classification and contractual requirements with its legal, compliance and ICT-risk advisers.

Frequently asked questions

Is Folderit a DORA-compliant document management system?

Folderit supports DORA compliance with security controls, auditability, document workflows, EU-region hosting, export capabilities and an available supplementary contract framework. However, DORA compliance belongs to the financial entity’s overall governance and use of ICT services; it is not a standalone software certification.

Does DORA apply to document management software vendors?

DORA applies directly to covered financial entities and establishes requirements for their management of ICT third-party providers. ICT providers therefore need to supply contractual information, cooperate as agreed and support customer due diligence. The exact duties depend on the service, the contract and whether the provider or service falls into a special DORA category.

Where does Folderit store customer documents?

For the relevant standard cloud-service scope described here, Folderit’s main servers, customer documents and server-side backups are hosted in the EEA using Amazon Web Services in Ireland. Folderit’s public Privacy Notice, DPA and sub-processor list provide more detail about processing and safeguards.

Will Folderit sign a DORA supplementary agreement?

Folderit can discuss a supplementary agreement that maps an agreed standard-service scope to relevant DORA Article 30 topics. Availability and exact terms depend on the customer’s use case, service classification and requested obligations.

What if Folderit supports a critical or important function?

Tell Folderit during due diligence. Article 30(3) adds requirements for ICT services supporting critical or important functions. The parties must assess the proposed use and agree any additional service levels, reporting, testing, audit or transition terms before that use.