Regulation · DORA for ICT vendors

DORA for ICT vendors: what lands in your contract

If your customer is a bank, an insurer, an investment firm, a fund manager, a payment institution or a crypto-asset service provider in the EU, DORA reaches you as an ICT third-party service provider (Art. 3(19)) through the contract: your customer has to include the Art. 30 clauses, list your service in the register of information (Art. 28(3)) and assess you before and during the relationship. The supervisor does not oversee you — but you can lose the contract.

01

You are an “ICT third-party service provider”

Art. 3(19): any undertaking supplying ICT services — software, SaaS, cloud, data, support, even hardware — to a financial entity. Size is irrelevant.

02

The obligations are theirs, the work is yours

The bank needs the clauses, the register data, the assessment and an exit plan. All of it comes from you.

03

Two tiers of clauses

Art. 30(2) applies to every ICT service; Art. 30(3) adds strict conditions where the service supports a critical or important function.

04

Subcontractors too

Art. 30(2)(a) and the RTS on subcontracting: the chain below you has to be declared, and controlled where critical functions are involved.

How to tell whether you are in scope

Ask two questions. Is any customer a financial entity under Art. 2(1) DORA? Does the service you provide involve ICT — software, hosting, data processing, support, connectivity? If both answers are yes, you are an ICT third-party service provider for that customer. Whether the strict conditions in Art. 30(3) also apply depends on whether your service supports a critical or important function (Art. 3(22)) — one whose disruption would materially impair the customer's financial performance, soundness or continuity of operations, or its compliance with the rules. A core system, claims handling, payments, trading, KYC and supervisory reporting are typical examples; the marketing website is not.

What your customer has to get from you

Customer obligationArticleWhat lands on your desk
Register of informationArt. 28(3); ITS 2024/2956A request for data: entity identifiers, service description, function supported, criticality, data locations, subcontractors, contract dates, notice periods
Pre-contractual due diligenceArt. 28(4)A questionnaire on security, resilience, onward outsourcing, data location and concentration
Mandatory clauses — all servicesArt. 30(2)An addendum: service description, locations and change notification, data protection, access to and return of data on termination, service levels, incident assistance, cooperation with authorities, termination rights and notice periods, participation in security training
Mandatory clauses — critical or important functionsArt. 30(3)Full SLAs with targets, notification of events affecting the service, continuity plans and their testing, participation in TLPT, unrestricted access and audit rights, an exit strategy with a transition period
Ongoing monitoringArt. 28(1)–(2), Art. 29Periodic re-assessment, incident information, concentration analysis
Exit strategyArt. 28(8)Your cooperation on the transition plan: data return format, timeline, knowledge transfer

The order to prepare in

  1. Write down which customers are financial entities and which of your services support a function they would call critical or important. That decides whether Art. 30(3) applies.
  2. Prepare your register-of-information data once, in the ITS structure. Every customer needs the same fields.
  3. Prepare your own set of Art. 30(2) clauses. Offering them first keeps the negotiation on your text.
  4. Put an incident notification procedure in place, with a named person and a target time for informing customers — DORA gives financial entities short reporting deadlines (Art. 19) and they will pass them on to you.
  5. For critical or important functions: an exit and transition plan, audit access terms, evidence of business continuity, a statement of cooperation on TLPT.
  6. Declare your subcontractors and where they process data.

What happens if you do nothing

From the supervisor — nothing; DORA does not penalise vendors. From the customer: the contract is not renewed, or is terminated using the rights Art. 28(7) requires them to hold, because a financial entity cannot keep an ICT vendor it cannot document. You are replaced by a vendor who answered the questionnaire in one round. The full guide: How ICT vendors lose bank contracts over DORA.

Audit your DORA readiness in a 4-week pilot

Questions we get most often

Yes — Art. 3(19) has no size threshold, and the register of information has to cover every ICT service. What changes with size and criticality is the depth: a non-critical tool needs the Art. 30(2) clause set and the register data; a critical one adds Art. 30(3).
Under Art. 31 the ESAs only designate large, systemically important providers (cloud hyperscalers and the like). A typical software house will not be designated. But if you build on a designated provider, your customer will ask about that dependency.
It helps with the security questions, but it does not cover the DORA-specific parts: contract clauses, register data, customer incident notification deadlines, exit strategies, subcontractor declarations. Expect that gap to show up in the questionnaire.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Find out where you stand in four weeks

Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.