DORA and ICT provider agreements – what contractual requirements apply?

Short answer: DORA sets detailed requirements for how financial entities must manage risks linked to ICT third parties. Agreements with ICT service providers must therefore contain clear rules regarding the scope of services, data storage, security, incident support, monitoring, and termination. For services supporting critical or important functions, stricter requirements apply.

What is DORA?

DORA, Regulation (EU) 2022/2554, is the EU's regulatory framework for digital operational resilience in the financial sector and began to apply on January 17, 2025. The rules cover, among other things, ICT risk management, incident reporting, testing, and third-party risk.

Why is the supplier agreement central?

Article 30 requires that the rights and obligations between the financial entity and the ICT provider are clearly allocated in writing. The agreement should not only be a commercial document but also function as part of the regulated risk management.

Fundamental contractual areas

  • clear description of functions and ICT services
  • where the service is performed and where data is processed or stored
  • requirements for availability, authenticity, integrity, and confidentiality
  • access to and return of data upon termination
  • service levels and monitorable quality requirements
  • incident support and cooperation with the financial business
  • termination rights and exit

Critical or important functions

When the ICT service supports a critical or important function, the agreement normally needs to go further. This may require more detailed SLAs, reporting obligations, contingency requirements, rights to monitor and audit, and clearer control over subcontractors.

Subcontractors and supply chain risk

Cloud and SaaS services are often built on several layers of subcontractors. DORA requires the financial entity to be able to understand and manage such dependencies. The agreement should therefore regulate when subcontractors may be used, what information must be provided, and how material changes are handled.

Exit plan – more than a termination clause

A functioning exit plan should address how data is exported, in what format, what assistance the provider must provide, what transition period is needed, and how continuity is ensured. For critical services, exit should be tested and prepared before an actual supplier disruption occurs.

Common contractual shortcomings

  • generic audit clauses that do not work in practice
  • unclear rights to data upon termination or insolvency
  • subcontractors are not listed or can be changed without control
  • SLAs lack measurement methods or consequences for deviations
  • incident requirements are slower than the business's regulatory deadlines
  • no link between the agreement and the business's own ICT risk register

See Mallbutiken's DORA package for ICT supplier agreements, due diligence, and exit.

Related areas

DORA often needs to be coordinated with GDPR, information security, outsourcing rules, and personal data processing agreements. It is therefore wise to map which regulations each supplier is subject to before negotiating the agreement.

FAQ

Does DORA apply to all companies that buy cloud services?

No. DORA is aimed at specified financial actors and certain related businesses. Suppliers can still be indirectly affected through the customers' contractual requirements.

Are the supplier's standard terms sufficient?

Not necessarily. Standard terms need to be compared against DORA's requirements and the risk classification of the current service.

Must all ICT agreements have the same level of requirements?

No. Proportionality and the importance of the service matter, but certain basic requirements apply broadly and stricter requirements apply when critical or important functions are supported.

Legal source: Regulation (EU) 2022/2554 of the European Parliament and of the Council, especially Article 30.

The article is general information and does not replace legal or regulatory advice.

Back to blog