Dev.to
7/15/2026

Is Multi-AZ Enough for Disaster Recovery? What DORA Actually Asks of Your Application
Short summary
DORA never mentions availability zones or multi-region — it asks technology-neutral questions about recovery time objectives, recovery point objectives, and physical/logical segregation of backups. The regulation's 'secondary processing site' requirement applies only to market infrastructures like central securities depositories, not typical banks or SaaS vendors. SaaS companies meet DORA indirectly through contract clauses from financial customers and must prove their recovery setup bears a distinct risk profile from primary.
- •DORA is technology-neutral: no mention of AZs or multi-region, only RTO/RPO and segregation
- •Secondary processing site requirement applies only to market infrastructures, not typical banks or SaaS
- •SaaS vendors meet DORA indirectly via customer contracts — must prove distinct risk profile per application
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



