{"product_id":"dora-ikt-leverantorsavtal-compliance-mallpaket-2026","title":"DORA ICT Third-Party Provider Agreement \u0026 Compliance Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eDORA ICT Provider Agreement \u0026amp; Compliance Template Package 2026\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete DORA package for financial entities that need to regulate, assess, and monitor ICT third-party providers in accordance with Regulation (EU) 2022\/2554.\u003c\/strong\u003e The package combines contract templates, risk assessment, exit plans, and a practical Excel register for providers, contracts, subcontracting chains, critical\/important functions, and DORA measures.\u003c\/p\u003e\n\n\u003cp\u003eDORA began to apply on \u003cstrong\u003eJanuary 17, 2025\u003c\/strong\u003e, and includes requirements for managing ICT third-party risk, information registers, contractual provisions, concentration risk, due diligence, subcontractors, and exit strategies. The template package is legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, and also takes into account the supplementary technical standards from 2024–2025.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eDORA ICT Provider Agreement \/ Contract Addendum 2026 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eAnnex for Critical\/Important Function \u0026amp; SLA – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eProvider Risk \u0026amp; Due Diligence – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eDORA Exit Plan for ICT Service – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eDORA ICT Provider Register, Risk \u0026amp; Exit Tool – Excel (XLSX)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eDORA ICT Provider Agreement\u003c\/h3\u003e\n\u003cp\u003eThe main template is designed as an addendum to an existing ICT, SaaS, cloud, operational, or outsourcing agreement. It covers key contractual requirements under DORA Article 30, including:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003efull description of functions and ICT services\u003c\/li\u003e\n\n\u003cli\u003eclassification of critical or important function\u003c\/li\u003e\n\n\u003cli\u003eservice and data storage locations\u003c\/li\u003e\n\n\u003cli\u003eavailability, authenticity, integrity, and confidentiality\u003c\/li\u003e\n\n\u003cli\u003eaccess, recovery, and return of data\u003c\/li\u003e\n\n\u003cli\u003eservice levels and SLAs\u003c\/li\u003e\n\n\u003cli\u003eincident support and regulatory reporting\u003c\/li\u003e\n\n\u003cli\u003ecooperation with competent and resolution authorities\u003c\/li\u003e\n\n\u003cli\u003esubcontracting chains and material changes\u003c\/li\u003e\n\n\u003cli\u003eaudit, inspection, and access rights\u003c\/li\u003e\n\n\u003cli\u003econtinuity, security, and testing\u003c\/li\u003e\n\n\u003cli\u003etermination, transition services, and exit\u003c\/li\u003e\n\n\u003cli\u003edocumentation for the information register\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFor critical and important functions\u003c\/h3\u003e\n\u003cp\u003eWhen an ICT service supports a critical or important function, enhanced DORA requirements apply. The separate SLA annex includes fields for measurable qualitative and quantitative targets, RTO\/RPO, incident levels, continuity tests, audit plans, subcontractors, and notification requirements.\u003c\/p\u003e\n\n\u003ch3\u003eSubcontractors – updated with EU 2025\/532\u003c\/h3\u003e\n\u003cp\u003eThe template package takes into account Commission Delegated Regulation (EU) 2025\/532 regarding subcontractors for ICT services that support critical or important functions. The contract section therefore includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewhich ICT services may be subcontracted\u003c\/li\u003e\n\n\u003cli\u003eprovider liability for subcontractors\u003c\/li\u003e\n\n\u003cli\u003erequirements for ongoing monitoring and reporting\u003c\/li\u003e\n\n\u003cli\u003esubcontractor service and data storage locations\u003c\/li\u003e\n\n\u003cli\u003eflow-down of security, continuity, audit, and access rights\u003c\/li\u003e\n\n\u003cli\u003eprior notification of material changes\u003c\/li\u003e\n\n\u003cli\u003eobjection process and right of termination in relevant situations\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eProvider Risk \u0026amp; Due Diligence\u003c\/h3\u003e\n\u003cp\u003eThe separate risk template supports assessment prior to contracting and during major changes. It covers aspects such as business reputation, financial stability, information security, BCP\/DR, incident management, data protection, regulatory cooperation, assurance, subcontractor management, concentration risk, substitutability, third countries, insolvency, and geopolitical risk.\u003c\/p\u003e\n\n\u003ch3\u003eConcentration risk and substitutability\u003c\/h3\u003e\n\u003cp\u003eDORA requires financial entities to assess dependencies on providers that cannot be easily replaced and situations where multiple critical or important arrangements are concentrated with the same or closely linked providers. The package therefore includes specific fields for technical lock-in, shared underlying cloud infrastructure, alternative provider, migration time, and switching costs.\u003c\/p\u003e\n\n\u003ch3\u003eDORA Exit Plan\u003c\/h3\u003e\n\u003cp\u003eFor ICT services supporting critical or important functions, exit strategies must be documented and testable. The exit plan covers:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eexit triggers\u003c\/li\u003e\n\n\u003cli\u003emigration to a new provider or insourcing\u003c\/li\u003e\n\n\u003cli\u003edata and asset inventory\u003c\/li\u003e\n\n\u003cli\u003eexport formats and validation\u003c\/li\u003e\n\n\u003cli\u003eknowledge transfer\u003c\/li\u003e\n\n\u003cli\u003etransition period and transition services\u003c\/li\u003e\n\n\u003cli\u003eparallel operation and cut-over\u003c\/li\u003e\n\n\u003cli\u003esecure deletion and deletion certificates\u003c\/li\u003e\n\n\u003cli\u003erisks during exit\u003c\/li\u003e\n\n\u003cli\u003etabletop and technical testing\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eExcel – provider register, risk and exit\u003c\/h3\u003e\n\u003cp\u003eThe Excel tool contains separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003econtract register\u003c\/li\u003e\n\n\u003cli\u003eICT providers\u003c\/li\u003e\n\n\u003cli\u003esubcontracting chain\u003c\/li\u003e\n\n\u003cli\u003ecritical\/important functions\u003c\/li\u003e\n\n\u003cli\u003edue diligence and risk assessment\u003c\/li\u003e\n\n\u003cli\u003eexit plans and testing\u003c\/li\u003e\n\n\u003cli\u003eDORA measures\u003c\/li\u003e\n\n\u003cli\u003emapping to the information register\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe workbook is mapped to key parts of Implementing Regulation (EU) 2024\/2956, including B_02.01\/B_02.02, B_05.01\/B_05.02, B_06.01, and B_07.01. It is an internal work and registry document and should not be described as a finished regulatory file for direct upload without verification against the Swedish Financial Supervisory Authority's (Finansinspektionen) current reporting format.\u003c\/p\u003e\n\n\u003ch3\u003eDORA Information Register\u003c\/h3\u003e\n\u003cp\u003eDORA Article 28.3 requires financial entities to maintain an up-to-date register of all contractual arrangements for the use of ICT services from third-party providers. Implementing Regulation (EU) 2024\/2956 specifies the standard templates for the register. The package helps the business gather central data in a structured way as early as the provider and contract process.\u003c\/p\u003e\n\n\u003ch3\u003eSwedish supervision\u003c\/h3\u003e\n\u003cp\u003eFor Swedish companies under the supervision of Finansinspektionen, DORA is supplemented by, among others, FFFS 2024:20 on incident reporting and information registers. Finansinspektionen has also explicitly made DORA implementation and digital operational resilience a supervisory priority.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2022\/2554 – DORA, particularly Articles 28–30\u003c\/li\u003e\n\n\u003cli\u003eCommission Delegated Regulation (EU) 2024\/1773\u003c\/li\u003e\n\n\u003cli\u003eCommission Implementing Regulation (EU) 2024\/2956\u003c\/li\u003e\n\n\u003cli\u003eCommission Delegated Regulation (EU) 2025\/532\u003c\/li\u003e\n\n\u003cli\u003eFFFS 2024:20, where applicable\u003c\/li\u003e\n\n\u003cli\u003eGDPR and other sector-specific regulation when relevant\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho is the package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ebanks and credit institutions\u003c\/li\u003e\n\n\u003cli\u003epayment institutions and electronic money institutions\u003c\/li\u003e\n\n\u003cli\u003einsurance and reinsurance undertakings\u003c\/li\u003e\n\n\u003cli\u003einvestment firms and market participants\u003c\/li\u003e\n\n\u003cli\u003efund management companies and other DORA-regulated financial entities\u003c\/li\u003e\n\n\u003cli\u003ecompliance, risk, legal, procurement, and IT security functions\u003c\/li\u003e\n\n\u003cli\u003eICT providers that need to negotiate DORA addenda with financial clients\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eNote\u003c\/h3\u003e\n\u003cp\u003eDORA's application and proportionality depend on the type of financial entity, service, function, and risk profile involved. The templates are general professional documents and must be adapted to main agreements, sector rules, regulatory status, the technical architecture of the service, and the financial entity's risk appetite. They do not replace individual legal advice.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55582028628310,"sku":"DORA-IKT-2026","price":299.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/dora-ikt-leverantorsavtal-compliance-mallpaket-2026.png?v=1790979372","url":"https:\/\/mallbutiken.se\/en\/products\/dora-ikt-leverantorsavtal-compliance-mallpaket-2026","provider":"Mallbutiken","version":"1.0","type":"link"}