All case studies

FinTech · Regulated

DORA + NIS2 Readiness for a FinTech SaaS

Engineering-side DORA and NIS2 preparation for a FinTech vendor serving EU banks: subcontractor register, exit strategy, pen-test reports.

Industry
FinTech · Regulated
Duration
4 months

Results at a glance

  • Audit-ready in 4 months instead of an estimated 9
  • Audit passed on the first attempt

Starting situation

A FinTech vendor sold its SaaS product to banks in the EU. Those banks fall under the Digital Operational Resilience Act (DORA), which has applied since 17 January 2025 and makes financial institutions responsible for the ICT risk of their software suppliers. They pass those requirements on to vendors like this one. The NIS2 Directive adds cybersecurity obligations of its own.

The preparation had been estimated at nine months.

Constraints

  • Regulated customers. The banks needed evidence from the vendor that would hold up in an audit.
  • Engineering scope. The work covered the engineering side of the preparation.

What was done

Wolf-Tech took on the engineering side of the DORA and NIS2 preparation. The deliverables included:

  • A subcontractor register listing the third parties involved in delivering the service.
  • An exit strategy describing how the service can be moved away from a provider if needed.
  • Pen-test reports as evidence of security testing.

These articles go into more detail on what DORA and NIS2 ask of SaaS vendors:

Results

  • Audit-ready in four months instead of the estimated nine.
  • The audit was passed on the first attempt.

Duration

Four months from start to audit readiness.

Have a similar challenge?

If any of these problems resonate, let's talk.

Contact us