Microsoft has published an article setting out three specific ways that it is helping its customers to comply with the requirements of DORA.
These are (verbatim):
To help customers successfully meet their contractual commitments under DORA, we are now working closely to update contract terms as required and applicable by the new regulation. This includes ensuring smooth pre-contractual risk assessments of Microsoft products and services, and fully defining the specific aspects of their obligations that dovetail with our offerings. We are also working with customers for input to update our contracts, as needed, so they remain fit for purpose under the DORA framework.
To help customers manage ICT risks and establish an internal governance and control framework, we provide in our products and services a broad set of built-in ICT risk management capabilities required by DORA. For example, on aspects related to information protection concerns, Microsoft Defender for Cloud performs continuous threat assessment, detection, and response, and Microsoft Secure Score helps assess and improve security posture across workloads. Likewise, for other aspects, such as incident management, resilience testing, and incident information sharing, vital functionality is provided by corresponding Microsoft offerings, including Microsoft Purview, Microsoft 365 Service Health dashboard, and Azure Service Health.
To help customers with incident management, classification, and reporting, our security and compliance offerings provide sophisticated capabilities for supporting incident management requirements, including tools and services for efficient incident detection and investigation, as well ensuring timely incident reporting and response as required. Azure Security Center, for example, ensures timely detection and response, and Microsoft 365 Health dashboard and Microsoft Defender work together to provide a comprehensive approach to incident management, classification, and reporting.
Microsoft says that it has established robust internal governance processes to prepare for and comply with all applicable DORA provisions as a critical third-party technology vendor and says that it will “Equally endeavor to support regulated financial institutions in meeting their requirements under DORA.” This will include aligning contractual provisions with the mandates of DORA and providing built-in ICT risk management capabilities across a broad range of Microsoft cloud and enterprise product offerings.






