Svenska Dokumentmallar
DORA ICT Third-Party Provider Agreement & Compliance Template Package 2026 – Word/PDF/Excel
DORA ICT Third-Party Provider Agreement & Compliance Template Package 2026 – Word/PDF/Excel
Downloading the template is available immediately after purchase. Our document templates are always delivered in customizable formats.
If you are unsure which template is appropriate or how you should complete it, please see the relevant information under the 'Legal Information' tab in our main menu.
Our templates are designed in accordance with current legislation and practice in each area to ensure that the documents you create are legally correct.
Couldn't load pickup availability
DORA ICT Provider Agreement & Compliance Template Package 2026
A complete DORA package for financial entities that need to regulate, assess, and monitor ICT third-party providers in accordance with Regulation (EU) 2022/2554. The package combines contract templates, risk assessment, exit plans, and a practical Excel register for providers, contracts, subcontracting chains, critical/important functions, and DORA measures.
DORA began to apply on January 17, 2025, and includes requirements for managing ICT third-party risk, information registers, contractual provisions, concentration risk, due diligence, subcontractors, and exit strategies. The template package is legally reviewed as of October 3, 2026, and also takes into account the supplementary technical standards from 2024–2025.
Included – 9 files
- DORA ICT Provider Agreement / Contract Addendum 2026 – Word + PDF
- Annex for Critical/Important Function & SLA – Word + PDF
- Provider Risk & Due Diligence – Word + PDF
- DORA Exit Plan for ICT Service – Word + PDF
- DORA ICT Provider Register, Risk & Exit Tool – Excel (XLSX)
DORA ICT Provider Agreement
The main template is designed as an addendum to an existing ICT, SaaS, cloud, operational, or outsourcing agreement. It covers key contractual requirements under DORA Article 30, including:
- full description of functions and ICT services
- classification of critical or important function
- service and data storage locations
- availability, authenticity, integrity, and confidentiality
- access, recovery, and return of data
- service levels and SLAs
- incident support and regulatory reporting
- cooperation with competent and resolution authorities
- subcontracting chains and material changes
- audit, inspection, and access rights
- continuity, security, and testing
- termination, transition services, and exit
- documentation for the information register
For critical and important functions
When an ICT service supports a critical or important function, enhanced DORA requirements apply. The separate SLA annex includes fields for measurable qualitative and quantitative targets, RTO/RPO, incident levels, continuity tests, audit plans, subcontractors, and notification requirements.
Subcontractors – updated with EU 2025/532
The template package takes into account Commission Delegated Regulation (EU) 2025/532 regarding subcontractors for ICT services that support critical or important functions. The contract section therefore includes, among other things:
- which ICT services may be subcontracted
- provider liability for subcontractors
- requirements for ongoing monitoring and reporting
- subcontractor service and data storage locations
- flow-down of security, continuity, audit, and access rights
- prior notification of material changes
- objection process and right of termination in relevant situations
Provider Risk & Due Diligence
The separate risk template supports assessment prior to contracting and during major changes. It covers aspects such as business reputation, financial stability, information security, BCP/DR, incident management, data protection, regulatory cooperation, assurance, subcontractor management, concentration risk, substitutability, third countries, insolvency, and geopolitical risk.
Concentration risk and substitutability
DORA requires financial entities to assess dependencies on providers that cannot be easily replaced and situations where multiple critical or important arrangements are concentrated with the same or closely linked providers. The package therefore includes specific fields for technical lock-in, shared underlying cloud infrastructure, alternative provider, migration time, and switching costs.
DORA Exit Plan
For ICT services supporting critical or important functions, exit strategies must be documented and testable. The exit plan covers:
- exit triggers
- migration to a new provider or insourcing
- data and asset inventory
- export formats and validation
- knowledge transfer
- transition period and transition services
- parallel operation and cut-over
- secure deletion and deletion certificates
- risks during exit
- tabletop and technical testing
Excel – provider register, risk and exit
The Excel tool contains separate sheets for:
- contract register
- ICT providers
- subcontracting chain
- critical/important functions
- due diligence and risk assessment
- exit plans and testing
- DORA measures
- mapping to the information register
- legal sources
The workbook is mapped to key parts of Implementing Regulation (EU) 2024/2956, including B_02.01/B_02.02, B_05.01/B_05.02, B_06.01, and B_07.01. It is an internal work and registry document and should not be described as a finished regulatory file for direct upload without verification against the Swedish Financial Supervisory Authority's (Finansinspektionen) current reporting format.
DORA Information Register
DORA Article 28.3 requires financial entities to maintain an up-to-date register of all contractual arrangements for the use of ICT services from third-party providers. Implementing Regulation (EU) 2024/2956 specifies the standard templates for the register. The package helps the business gather central data in a structured way as early as the provider and contract process.
Swedish supervision
For Swedish companies under the supervision of Finansinspektionen, DORA is supplemented by, among others, FFFS 2024:20 on incident reporting and information registers. Finansinspektionen has also explicitly made DORA implementation and digital operational resilience a supervisory priority.
Legal basis
- Regulation (EU) 2022/2554 – DORA, particularly Articles 28–30
- Commission Delegated Regulation (EU) 2024/1773
- Commission Implementing Regulation (EU) 2024/2956
- Commission Delegated Regulation (EU) 2025/532
- FFFS 2024:20, where applicable
- GDPR and other sector-specific regulation when relevant
Who is the package for?
- banks and credit institutions
- payment institutions and electronic money institutions
- insurance and reinsurance undertakings
- investment firms and market participants
- fund management companies and other DORA-regulated financial entities
- compliance, risk, legal, procurement, and IT security functions
- ICT providers that need to negotiate DORA addenda with financial clients
Note
DORA's application and proportionality depend on the type of financial entity, service, function, and risk profile involved. The templates are general professional documents and must be adapted to main agreements, sector rules, regulatory status, the technical architecture of the service, and the financial entity's risk appetite. They do not replace individual legal advice.
Format: Word (DOCX) + PDF + Excel (XLSX)
Language: Swedish
Jurisdiction: Sweden / EU
Number of files: 9
Version: 1.0 – 2026-10-03
Share



