If you are searching for a DORA-compliant document management system, the most important question is not whether a vendor displays a “DORA compliant” badge. DORA compliance remains the financial entity’s responsibility. What matters is whether the document management system gives your team the security controls, evidence, data portability and written ICT-provider terms needed to assess and manage the relationship.
The short answer
Folderit supports DORA readiness for financial-sector customers with encrypted document management, granular access control, audit trails, version history, workflows, e-signatures, EU-region hosting, backups and export capabilities. Folderit can also document relevant responsibilities in a DORA supplementary agreement for an agreed service scope. No software vendor, however, can make an organisation DORA compliant on its own.
What DORA means for document management
The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025. It covers a broad range of financial entities, including banks, payment and e-money institutions, investment firms, insurers, pension institutions, credit-rating agencies, crowdfunding providers and crypto-asset service providers. It also establishes obligations connected with ICT third-party service providers.
For a document management system, DORA is especially relevant in two ways. First, the financial entity needs reliable evidence for ICT risk management, incident handling, testing and third-party oversight. Second, its contract with an ICT provider must clearly describe the service, data arrangements, support, cooperation and exit rights.
That second point is central to DORA Article 30. It requires ICT service contracts to allocate rights and obligations in writing. The required clauses depend partly on whether the service supports a critical or important function.
What makes a DORA-compliant document management system?
“DORA-compliant document management system” is a useful search phrase, but it can be misleading if read as a certification claim. DORA regulates the financial entity’s overall digital operational resilience. The customer must classify its functions, assess ICT risk, maintain governance and registers, manage incidents, test resilience and oversee providers.
A DMS can support that work. It can supply appropriate controls, preserve evidence and provide contractual information for third-party due diligence. The final result depends on how the customer configures and uses the system, what documents it stores, which workflows it runs and whether the service supports a critical or important function.
How Folderit supports DORA compliance
For example, Folderit combines document control with features that help regulated teams maintain a clear and exportable evidence trail:
- Encryption and secure connections: encryption at rest and in transit, with TLS/SSL for data exchange.
- Granular access control: role-based permissions, personal credentials, optional two-factor authentication, SSO options and additional account security controls.
- Traceable document activity: audit trails, logs, version history and workflow history show who did what and when.
- Controlled processes: visual workflows, approvals, acknowledgements, reminders and electronic signatures help teams execute documented procedures consistently.
- Evidence organisation: folders, metadata, OCR search, document links and records-management tools make policies, incidents, contracts and reviews easier to retrieve.
- Backups, recovery and deletion safeguards: regular backups, point-in-time database recovery and Recycle Bin or delayed-deletion safeguards support resilience.
- Portability: customers can access, download and export their data through standard features.
In addition, you can review Folderit’s public Security & Compliance overview, Data Processing Addendum, Privacy Notice, Terms of Use and sub-processor list during vendor due diligence.
DORA Article 30 checklist for a document management provider
Article 30(2) lists the baseline elements for ICT service contracts. Therefore, a financial entity should translate each requirement into a practical due-diligence question.
Service, data and security clauses
| DORA contract area | What a financial entity should verify | Folderit’s approach for an agreed standard-service scope |
|---|---|---|
| Service description and subcontracting | Functions, service boundaries and conditions for subcontracting | The supplement can describe document storage and metadata, permissions, search, versioning, audit trails, workflows, e-signatures and ordered standard features. Additionally, Folderit publishes its current sub-processors online. |
| Service and data locations | Regions or countries where the service runs and where Folderit processes or stores data | For the relevant cloud scope, Folderit hosts its main servers, customer documents and server-side backups in the EEA using AWS’s Ireland region. The supplement can also give customers advance written notice before a storage-location change. |
| Data protection | Availability, authenticity, integrity and confidentiality controls | Folderit uses encryption in transit and at rest, access controls, audit logging, backups and documented technical and organisational measures. |
| Access, recovery and return | How the customer can access, recover and retrieve its data, including at termination | Standard features let customers access, download and export their data. Contractual exit and data-return provisions support those capabilities. |
Support, cooperation and exit clauses
| DORA contract area | What a financial entity should verify | Folderit’s approach for an agreed standard-service scope |
|---|---|---|
| Service levels | Support, recovery objectives, revisions and review | Standard support applies. The parties can record relevant recovery objectives and customer-specific service levels in the signed agreement. |
| Incident assistance | Support during an ICT incident and the treatment of additional costs | Folderit offers reasonable assistance within standard support. The parties can scope and price work that goes beyond the agreement. |
| Regulatory cooperation | Cooperation with the customer, competent authorities, resolution authorities and appointed auditors | The supplement can state cooperation duties. However, the parties separately agree any additional audits, on-site checks, special reports or integrations outside the standard service, and Folderit may charge for them. |
| Termination and transition | Termination rights, data portability and an orderly move to another provider or in-house solution | Export and return provisions support portability. Where needed, the parties can agree bespoke transition assistance separately. |
| Security awareness and training | Conditions for provider participation in the financial entity’s training | Folderit applies internal ICT-security awareness measures. The parties can also agree Folderit’s participation in customer-specific training. |

What Folderit’s DORA supplementary agreement adds
Folderit’s standard Terms of Use, Privacy Notice and DPA remain the contractual foundation. For an eligible financial-sector customer, a supplementary agreement can map the agreed standard service to the relevant Article 30(2) topics without silently expanding the service into unlimited audit, reporting or custom-development obligations.
- Clear scope: the document lists the ordered ICT and document-management functions and records the parties’ classification of the service.
- Location commitments: for the applicable cloud scope, it identifies AWS Ireland in the EEA for main servers, customer documents and server-side backups. It can also require 90 days’ written notice before changing that storage location.
- Material-change notice: it can require 30 calendar days’ written notice of planned material changes that could negatively affect Folderit’s ability to perform its customer obligations.
- Recovery objectives: the standard-service supplement can document database point-in-time recovery with an RPO of up to five minutes, a target of restoring service within minutes after an in-region infrastructure failure through automatic failover, and a backup-based database restore that may take up to one to two hours.
- Cooperation and exit: it addresses regulatory cooperation, data access and return, termination, and a separately agreed transition for any additional services.
- Commercial clarity: audits, bespoke reports, integrations, customisations, transition work or other services outside the standard scope require prior written agreement, and Folderit may charge for them.
As a result, this balance is useful for both sides. The customer gets written answers to the DORA questions relevant to the service it is buying. Folderit avoids creating vague promises that no provider could responsibly deliver without a defined scope.
Critical or important functions require a separate assessment
DORA Article 30(3) adds requirements when an ICT service supports a critical or important function. These include more precise service levels, reporting obligations, business-continuity testing, security measures, possible participation in threat-led penetration testing, expanded audit and inspection rights, and a mandatory transition period.
Folderit designed its current supplementary framework for a standard-service scope that the parties agree does not support a critical or important function. A customer planning to use Folderit in a critical or important function should raise that classification during due diligence. Both parties would then need to assess the use case and agree any additional terms before relying on the service for that purpose.
A precise compliance claim is a stronger one
Folderit does not claim that buying a DMS automatically makes a financial entity DORA compliant. Instead, Folderit offers practical controls, auditable records, current legal documentation and a contract path that can support the customer’s own DORA programme.
A practical DORA vendor due-diligence checklist
Therefore, before selecting any DORA-ready document management system, ask the provider these questions:
- Which exact functions and service components are included?
- Where are documents, metadata and backups stored and processed?
- Which sub-processors are used, and how are customers notified about changes?
- How are encryption, access control, audit logging and account security implemented?
- Can the customer export documents and relevant records in an accessible format?
- What support, recovery objectives and incident-assistance terms apply?
- What cooperation, audit and regulatory-access rights are included?
- What happens at termination, and which transition services cost extra?
- Has the financial entity classified the supported function as critical or important?
For the operational evidence your team should retain inside a DMS, see Folderit’s companion guide: DORA in 2026: Evidence Your DMS Must Capture.
Is Folderit the right DORA-ready DMS for your organisation?
Folderit is a strong fit for teams that want secure, user-friendly document management with traceable workflows, approvals, e-signatures, metadata, version history, audit trails and EU-region cloud hosting. For financial-sector customers, the contract can be supplemented with a focused DORA agreement when the proposed use and service classification fit the available scope.
This article is general product and compliance information, not legal advice. Your organisation should assess DORA applicability, service classification and contractual requirements with its legal, compliance and ICT-risk advisers.
Frequently asked questions
Is Folderit a DORA-compliant document management system?
Folderit supports DORA compliance with security controls, auditability, document workflows, EU-region hosting, export capabilities and an available supplementary contract framework. However, DORA compliance belongs to the financial entity’s overall governance and use of ICT services; it is not a standalone software certification.
Does DORA apply to document management software vendors?
DORA applies directly to covered financial entities and establishes requirements for their management of ICT third-party providers. ICT providers therefore need to supply contractual information, cooperate as agreed and support customer due diligence. The exact duties depend on the service, the contract and whether the provider or service falls into a special DORA category.
Where does Folderit store customer documents?
For the relevant standard cloud-service scope described here, Folderit’s main servers, customer documents and server-side backups are hosted in the EEA using Amazon Web Services in Ireland. Folderit’s public Privacy Notice, DPA and sub-processor list provide more detail about processing and safeguards.
Will Folderit sign a DORA supplementary agreement?
Folderit can discuss a supplementary agreement that maps an agreed standard-service scope to relevant DORA Article 30 topics. Availability and exact terms depend on the customer’s use case, service classification and requested obligations.
What if Folderit supports a critical or important function?
Tell Folderit during due diligence. Article 30(3) adds requirements for ICT services supporting critical or important functions. The parties must assess the proposed use and agree any additional service levels, reporting, testing, audit or transition terms before that use.