The Digital Operational Resilience Act (DORA) became applicable on 17 January 2025. It directly regulates EU financial entities — but every obligation flows through to the vendors that support them. If you sell cloud, SaaS, software, data, hosting, managed IT, or any other ICT service into a bank, insurer, investment firm or crypto-asset service provider in the EU, your clients now need contractual, operational and evidentiary changes from you. This guide explains what changes, why, and how to be ready.
Who is in scope
DORA distinguishes two kinds of providers:
- ICT third-party service providers (ICT TPPs). Any undertaking providing ICT services to a financial entity — covered indirectly, through Article 28–30 obligations that the client must pass through in contracts.
- Critical ICT third-party providers (CTPPs). Designated by the European Supervisory Authorities under Article 31, based on systemic impact, substitutability, number of financial-entity clients and operational criticality. CTPPs sit under a direct EU Oversight Framework with on-site inspections, recommendations and penalties of up to 1% of average daily worldwide turnover.
Article 30 contractual requirements your clients now demand
Every new or renewed contract with an EU financial entity must cover the following at a minimum — and contracts supporting critical or important functions get a stricter extended list:
- A clear and complete description of all functions and ICT services provided, including subcontracted services.
- Locations where data is processed and services delivered, with prior notice of material changes.
- Service-level descriptions with quantitative and qualitative performance targets and remedies.
- Provisions on data availability, integrity, confidentiality and access to personal and non-personal data.
- Assistance to the financial entity at no additional cost (or at a pre-agreed cost) during ICT incidents.
- Full cooperation with competent authorities and resolution authorities of the financial entity.
- Termination rights, notice periods and exit strategies including transition assistance.
- Right of access, inspection and audit by the financial entity, its auditors and competent authorities — including for subcontractors.
- Participation in the financial entity's ICT security awareness and digital operational resilience training where relevant.
The Register of Information and what you'll be asked for
Under Article 28(3), every financial entity must maintain a Register of Information on all contractual arrangements with ICT TPPs and submit it annually to its competent authority. The reporting templates (Commission Implementing Regulation (EU) 2024/2956) require vendor-side details you will be repeatedly asked for:
- • Legal name and LEI of your entity (and of any subcontractors).
- • Parent undertaking and corporate group structure.
- • Country of registration and country of service delivery.
- • Whether the service supports a critical or important function.
- • Type of ICT service (using the standard taxonomy in the ITS).
- • Data sensitivity and locations of data storage and processing.
- • Subcontracting chain — including the subcontractors actually performing the service.
- • Contract start, end, notice period and renewal terms.
Practical implication: maintain a single "DORA fact sheet" you can hand to every financial-entity client on request, so each of them can populate their register without chasing your account managers individually.
Incident reporting, subcontracting and exit
- Incident notification. You must notify financial-entity clients of ICT-related incidents that affect them quickly enough for the client to meet its own classification and reporting deadlines (initial, intermediate and final notifications under the DORA ITS on major incident reporting).
- Subcontracting controls. For services supporting critical or important functions, you cannot subcontract — or materially change a subcontractor — without giving the financial entity sufficient prior notice and an objection right.
- Threat-Led Penetration Testing (TLPT). Where the financial entity is in scope for TLPT, you may be required to participate in scenario-based red-team testing under Articles 26–27.
- Exit strategy. Every contract supporting a critical or important function must contain a documented exit strategy and transition plan, with the cooperation obligations baked into the contract.
A 10-step readiness checklist for ICT providers
- Identify which of your services support critical or important functions for any EU financial-entity client.
- Publish a DORA fact sheet covering entity details, LEI, processing locations and subcontractors.
- Update master service agreements and DPAs to cover the Article 30 minimum (and extended) clauses.
- Map and document your subcontracting chain — including cloud sub-processors and SaaS dependencies.
- Define your incident notification workflow with client-meeting SLAs aligned to DORA classification windows.
- Maintain an audit and inspection pack so client and supervisor audits can be served on request.
- Document your business continuity, disaster recovery and resilience testing programme.
- Stand up an exit assistance plan with timelines, data extraction formats and knowledge transfer.
- Track whether your firm may be designated a CTPP and prepare for direct Oversight Framework engagement.
- Run an annual self-review against the latest RTS/ITS — the technical standards continue to evolve.
Need to evidence DORA readiness to a client?
RisQo profiles ICT third-party providers across credit, cyber, country, ESG and AI risk in seconds — the same lenses financial-entity procurement and second-line teams now use for DORA onboarding and ongoing monitoring.
This guide is general information and does not constitute legal advice. Refer to the Digital Operational Resilience Act (Regulation (EU) 2022/2554) and the EBA, EIOPA and ESMA technical standards for binding requirements.
