When an ICT service supports a critical or important function, DORA expects stronger lifecycle control before and during the contract. The contract policy should define how the entity determines which ICT services support critical or important functions, when that assessment is reviewed, who approves and monitors the contract, what due diligence is required, what assurance is accepted, and when exit planning is tested.
Subcontracting needs its own control record. Before allowing a provider to subcontract ICT services supporting critical or important functions or material parts of them, assess whether the provider can identify and monitor relevant subcontractors, pass through access and inspection rights, maintain continuity through the subcontracting chain, notify material changes in time, and support termination where changes exceed the entity's risk tolerance.