How DORA Treats Unsupported and End-of-Life Software
DORA has applied to EU financial entities since January 2025. Unsupported components are a resilience problem you must document.

The Digital Operational Resilience Act (DORA) has applied to European Union financial entities since January 17, 2025. It does not name "end-of-life software," but its information and communication technology (ICT) risk-management and third-party requirements make running unsupported components a resilience and governance problem you must identify, document, and manage.
What does DORA require?
DORA sets out an ICT risk-management framework, mandatory incident reporting, digital operational resilience testing, and oversight of ICT third-party and supply-chain risk. It applies broadly across banks, insurers, investment firms, and many of the ICT providers that serve them, and it places accountability with management bodies.
Where does end-of-life software land under DORA?
An unsupported component is, by definition, a known ICT risk. Under DORA it needs to appear in your risk assessments and treatment plans rather than sit unrecorded. Because an end-of-life component has no upstream patch, it directly weakens operational resilience and complicates the third-party assurance DORA expects, particularly where the component is embedded in a service you provide or consume.
What should boards and CISOs be asking?
Three questions surface the exposure quickly. Do we know what in our estate is end of life, including transitive dependencies? Is that documented in our ICT risk register? And what is the remediation or continuity plan for each item, with owners and timelines? If any answer is unclear, that is the gap to close first.
What are the practical steps?
Build an inventory that tracks end-of-life status, record unsupported components in the risk register with a treatment plan, establish a migration runway, and use extended support as a documented mitigating control for components that cannot be retired on the required timeline. HeroDevs Never-Ending Support provides a supported patch stream that can serve as that control for end-of-life open source.
This article is general information, not legal advice. Confirm your obligations with counsel.
Frequently asked questions
When did DORA start applying?
January 17, 2025, for in-scope European Union financial entities.
Does DORA mention end-of-life software?
Not by name, but unsupported components fall under its ICT risk-management and third-party requirements.
Who is in scope for DORA?
Banks, insurers, investment firms, and many of the ICT providers serving them.
How should EOL software be handled under DORA?
Identify it, record it in the ICT risk register, and document a remediation or mitigation plan.
Can extended support serve as a DORA control?
It can act as a documented mitigating control by restoring a supported patch stream.
Resources
View All Articles
.png)

.png)