Back to feed
Dev.to
Dev.to
7/15/2026
Is Multi-AZ Enough for Disaster Recovery? What DORA Actually Asks of Your Application

Is Multi-AZ Enough for Disaster Recovery? What DORA Actually Asks of Your Application

Short summary

DORA never mentions availability zones or multi-region — it asks technology-neutral questions about recovery time objectives, recovery point objectives, and physical/logical segregation of backups. The regulation's 'secondary processing site' requirement applies only to market infrastructures like central securities depositories, not typical banks or SaaS vendors. SaaS companies meet DORA indirectly through contract clauses from financial customers and must prove their recovery setup bears a distinct risk profile from primary.

  • DORA is technology-neutral: no mention of AZs or multi-region, only RTO/RPO and segregation
  • Secondary processing site requirement applies only to market infrastructures, not typical banks or SaaS
  • SaaS vendors meet DORA indirectly via customer contracts — must prove distinct risk profile per application

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more