A boutique registered investment advisor (RIA) in the Bay Area gets a contract renewal from a European fund administrator. Buried on page 14 is a new clause requiring the firm to maintain an information and communication technology (ICT) risk management framework consistent with the EU’s Digital Operational Resilience Act (DORA). Nobody flagged it. The compliance officer has never heard of DORA. The contract gets signed anyway.

That scenario is playing out at small financial firms right now - quietly, contractually, and with real consequences.

The Problem: US Firms Are Assuming DORA Doesn’t Apply to Them

When DORA took effect on January 17, 2025, most US-based boutique advisory firms, registered investment advisors, and wealth management shops did exactly what you’d expect: they ignored it. It’s a European regulation. They’re not European entities. End of story.

Except it’s not that simple.

DORA applies directly to EU-regulated financial entities - banks, investment firms, insurance companies, crypto-asset service providers, and others operating under EU financial law. But here’s what most US firms haven’t thought through: DORA requires those EU-regulated entities to flow down specific ICT risk management requirements to their third-party service providers and technology vendors through contractual obligations.

That means if your firm sub-advises for an EU-domiciled fund, provides analytical services to an EU-regulated counterparty, or even maintains a custodial or data-sharing relationship with an EU-regulated institution, you may already be in their DORA compliance chain - whether you know it or not.

The regulation doesn’t need to name your firm directly to affect it. Your EU counterparty’s legal team will name it for you, in the contract they send you next quarter.

This isn’t theoretical. Since January 2025, EU-regulated financial entities have been required to ensure their third-party ICT providers meet DORA’s standards. That pressure moves downstream fast, and small US firms with niche EU relationships are often the last to realize it’s arrived.

Why This Matters for Boutique Financial Firms

You’re already operating in a demanding regulatory environment. The Securities and Exchange Commission’s (SEC) Regulation S-P governs how you protect client financial data. The SEC’s cybersecurity disclosure rules now require material incident reporting. The Financial Industry Regulatory Authority (FINRA), if applicable, adds its own layer of supervisory expectations.

DORA doesn’t replace any of that - but it adds a parallel set of expectations if EU relationships are in the picture.

DORA’s core pillars are: ICT risk management frameworks, incident detection and reporting, digital operational resilience testing, third-party ICT risk management, and information sharing. Sound familiar? They should. These map closely to the National Institute of Standards and Technology (NIST) Cybersecurity Framework categories you may already use and to the SEC’s own guidance on operational resilience.

The real exposure for a US boutique firm that ignores DORA-related contractual requirements isn’t a fine from a European regulator - it’s a breach of contract with an EU counterparty, a lost mandate, or a damaged relationship with a fund that can’t pass its own DORA audit if your firm can’t demonstrate adequate ICT controls.

For firms managing assets on behalf of EU pension funds, endowments, or family offices, the reputational and financial stakes are real. Losing a sub-advisory mandate because you couldn’t produce documentation of your incident response process is entirely avoidable - but only if you’ve done the work.

Even firms with no current EU exposure should pay attention. DORA is a preview of where US regulators are heading. The SEC’s operational resilience posture has been moving steadily in this direction, and what becomes contractually required by EU counterparties today tends to become regulatory standard in the US within a few years.

How to Address This: A Practical Framework for Small Firms

If you’re already running a reasonably mature cybersecurity and compliance program, you’re not starting from zero. Here’s how to approach this systematically.

Step 1: Audit your EU-connected relationships. Pull every service agreement, sub-advisory contract, data-sharing arrangement, or vendor relationship that involves an EU-regulated entity. Look specifically for clauses referencing DORA, ICT risk management requirements, incident notification timelines, or resilience testing obligations. If those clauses aren’t there yet, they may be coming on renewal.

Step 2: Map DORA’s requirements against what you already have. DORA’s ICT risk management pillar requires documented policies for identifying, protecting against, detecting, responding to, and recovering from ICT incidents. If you’ve built your program around NIST or the SEC’s cybersecurity guidance, you likely have partial coverage. The gaps are usually in formal resilience testing (tabletop exercises, penetration testing, business continuity tests) and in the documentation rigor EU counterparties will ask for.

Step 3: Tighten your third-party vendor documentation. DORA places significant weight on third-party ICT risk. Your EU counterparties will want to know that you’ve assessed your own technology vendors - your cloud providers, your portfolio management software, your email platform - for operational resilience. Start building or updating a vendor risk register that includes contractual provisions, incident notification expectations, and continuity capabilities.

Step 4: Establish a written incident response and notification process. DORA requires EU entities to report major ICT incidents within tight timeframes. If you’re in their vendor chain, they’ll need fast notification from you too. A documented, tested incident response plan - even a simple one - positions you to meet those expectations and satisfies SEC requirements at the same time.

Step 5: Don’t wait for the contract to arrive. Proactively reaching out to EU counterparties to understand their DORA compliance program and how they view your firm’s role in it is a differentiator. It signals maturity. It also gives you lead time to address gaps before an audit cycle or contract renewal puts you on the clock.

What to Look for in an IT Partner

If you’re working with a managed IT services provider (MSP), they need to understand DORA’s ICT requirements - not just in the abstract, but in terms of what documentation and controls you’ll need to produce for EU counterparties.

Ask potential or current IT partners these questions:

  • Can you help us document our ICT risk management framework in a format that maps to DORA’s requirements and the NIST Cybersecurity Framework?
  • Do you have experience supporting financial firms with third-party risk documentation and vendor assessments?
  • Can you run or support a formal resilience test - tabletop exercise, business continuity drill, or penetration test - and produce a written report we can share with counterparties?
  • How do you handle incident notification, and can we establish contractual SLAs for notifying us in timeframes consistent with DORA’s downstream requirements?

A provider that can’t answer those questions specifically isn’t the right partner for a financial firm navigating EU-connected compliance obligations.

The Bottom Line

DORA doesn’t need to name your firm to affect it. If you have EU clients, fund relationships, or vendor chains that touch EU-regulated entities, DORA-aligned contractual requirements are likely either in your agreements already or coming soon. The firms that review their contracts now, map their existing controls, and shore up their documentation will handle this cleanly. The firms that don’t will find out the hard way - at contract renewal, or during a counterparty audit.


Frequently Asked Questions

Does DORA apply to US-based financial advisory firms?

DORA directly regulates EU-licensed financial entities, not US-domiciled firms. However, US firms that provide services to EU-regulated entities - as sub-advisors, technology vendors, or data-sharing partners - may be subject to DORA-aligned requirements through contractual obligations their EU counterparties are required to flow down. The practical impact depends on the nature and terms of your EU relationships.

What are DORA’s main requirements that could affect a small US advisory firm?

DORA’s five pillars are ICT risk management, incident detection and reporting, resilience testing, third-party ICT risk management, and information sharing arrangements. For a US firm in an EU entity’s vendor chain, the most likely contractual requirements involve documented ICT risk policies, incident notification timelines, and evidence of operational resilience testing such as business continuity exercises or penetration tests.

How does DORA compare to SEC cybersecurity requirements that US firms already follow?

DORA and the SEC’s cybersecurity rules share significant conceptual overlap - both require documented risk management frameworks, incident response plans, and vendor oversight. The differences are in scope, specificity, and testing rigor. DORA is more prescriptive about resilience testing and third-party contractual requirements. Firms with mature SEC-aligned programs have a solid foundation but may need to fill gaps in formal testing documentation and vendor risk registers.

What should a small RIA do first if they think they might have DORA exposure?

Start by reviewing your existing service agreements with any EU-connected counterparties for ICT risk management clauses or references to DORA. Then assess your current cybersecurity and operational resilience documentation against DORA’s core pillars. If you identify gaps - particularly in resilience testing or vendor documentation - those are the areas to address before your next contract renewal cycle.


If you’re working through DORA compliance and operational resilience challenges at your firm, let’s talk. One82 works exclusively with CPA firms, law firms, and financial advisory companies in the Bay Area - we know your world.