DORA for ICT vendors: what lands in your contract
If your customer is a bank, an insurer, an investment firm, a fund manager, a payment institution or a crypto-asset service provider in the EU, DORA reaches you as an ICT third-party service provider (Art. 3(19)) through the contract: your customer has to include the Art. 30 clauses, list your service in the register of information (Art. 28(3)) and assess you before and during the relationship. The supervisor does not oversee you — but you can lose the contract.
You are an “ICT third-party service provider”
Art. 3(19): any undertaking supplying ICT services — software, SaaS, cloud, data, support, even hardware — to a financial entity. Size is irrelevant.
The obligations are theirs, the work is yours
The bank needs the clauses, the register data, the assessment and an exit plan. All of it comes from you.
Two tiers of clauses
Art. 30(2) applies to every ICT service; Art. 30(3) adds strict conditions where the service supports a critical or important function.
Subcontractors too
Art. 30(2)(a) and the RTS on subcontracting: the chain below you has to be declared, and controlled where critical functions are involved.
How to tell whether you are in scope
Ask two questions. Is any customer a financial entity under Art. 2(1) DORA? Does the service you provide involve ICT — software, hosting, data processing, support, connectivity? If both answers are yes, you are an ICT third-party service provider for that customer. Whether the strict conditions in Art. 30(3) also apply depends on whether your service supports a critical or important function (Art. 3(22)) — one whose disruption would materially impair the customer's financial performance, soundness or continuity of operations, or its compliance with the rules. A core system, claims handling, payments, trading, KYC and supervisory reporting are typical examples; the marketing website is not.
What your customer has to get from you
| Customer obligation | Article | What lands on your desk |
|---|---|---|
| Register of information | Art. 28(3); ITS 2024/2956 | A request for data: entity identifiers, service description, function supported, criticality, data locations, subcontractors, contract dates, notice periods |
| Pre-contractual due diligence | Art. 28(4) | A questionnaire on security, resilience, onward outsourcing, data location and concentration |
| Mandatory clauses — all services | Art. 30(2) | An addendum: service description, locations and change notification, data protection, access to and return of data on termination, service levels, incident assistance, cooperation with authorities, termination rights and notice periods, participation in security training |
| Mandatory clauses — critical or important functions | Art. 30(3) | Full SLAs with targets, notification of events affecting the service, continuity plans and their testing, participation in TLPT, unrestricted access and audit rights, an exit strategy with a transition period |
| Ongoing monitoring | Art. 28(1)–(2), Art. 29 | Periodic re-assessment, incident information, concentration analysis |
| Exit strategy | Art. 28(8) | Your cooperation on the transition plan: data return format, timeline, knowledge transfer |
The order to prepare in
- Write down which customers are financial entities and which of your services support a function they would call critical or important. That decides whether Art. 30(3) applies.
- Prepare your register-of-information data once, in the ITS structure. Every customer needs the same fields.
- Prepare your own set of Art. 30(2) clauses. Offering them first keeps the negotiation on your text.
- Put an incident notification procedure in place, with a named person and a target time for informing customers — DORA gives financial entities short reporting deadlines (Art. 19) and they will pass them on to you.
- For critical or important functions: an exit and transition plan, audit access terms, evidence of business continuity, a statement of cooperation on TLPT.
- Declare your subcontractors and where they process data.
What happens if you do nothing
From the supervisor — nothing; DORA does not penalise vendors. From the customer: the contract is not renewed, or is terminated using the rights Art. 28(7) requires them to hold, because a financial entity cannot keep an ICT vendor it cannot document. You are replaced by a vendor who answered the questionnaire in one round. The full guide: How ICT vendors lose bank contracts over DORA.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Find out where you stand in four weeks
Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.