What must a DORA ICT third-party contract include?
Every contract must clearly allocate rights and obligations in writing and include the service level agreements in one paper or downloadable, durable, and accessible document. Article 30 also requires a complete service and function description; subcontracting conditions where relevant; service, processing, and storage locations with advance notice of changes; data-protection terms; data access, recovery, and return; incident assistance at no extra cost or at a cost set in advance; cooperation with competent and resolution authorities; termination rights and notice periods; and conditions for relevant provider participation in security-awareness and resilience training.
Where the ICT service supports a , DORA adds a higher bar: full service level descriptions with quantitative and qualitative performance targets, provider reporting and notice obligations, business-contingency and ICT-security requirements, participation and cooperation in relevant resilience testing, ongoing monitoring rights, unrestricted access, inspection and audit rights for the financial entity or appointed third party and competent authority, and exit strategies with an adequate transition period.
- Do not treat a master services agreement as complete unless the linked service order, SLA, data-location terms, incident-assistance obligations, authority-cooperation clause, termination rights, and, where critical or important functions are supported, audit and exit terms together form the full accessible contract record.
- For critical or important functions, check whether the contract gives practical audit access and the right to take copies of relevant documentation where critical to provider operations.
- Map each required clause to the affected ICT service, supported function, provider legal entity, subcontracting condition, and register-of-information reference.
Does DORA require special clauses for all ICT third-party contracts?
DORA requires written contractual arrangements for and adds specific minimum content for all ICT service contracts. Contracts supporting critical or important functions need additional clauses on detailed service levels, material-change notices, contingency plans, ICT security, testing cooperation, monitoring, access, inspection, audit, and exit.
Article 30 sets the written contract requirements and the additional clauses for ICT services supporting critical or important functions.
Specifies the policy content for contractual arrangements supporting critical or important functions, including lifecycle phases, due diligence, contractual clauses, monitoring, audit, and exit.