DORA has two addressees, even though only one appears in the letter of the law. Regulation (EU) 2022/2554 formally obligates financial entities – yet its requirements land with full force on their IT providers: as clause catalogs, information requests, and audit rights. This article therefore addresses both sides: the mid-market financial entity that must keep its register of information current and sharpen its provider contracts – and the IT provider who has an Art. 30 clause sheet on the table for the first time.
Who is obligated
DORA has applied since January 17, 2025 – and specifically to roughly 20 categories of financial entities: banks and insurers as well as payment institutions, investment firms, asset management companies, or insurance intermediaries. Small entities are covered too; the regulation provides for proportionality (Art. 4) and, for certain small entities, a simplified risk management framework (Art. 16). “Too small for DORA” is therefore not a defensible self-assessment for most market participants – the question is not whether, but at what depth.
For smaller institutions, BaFin also concretized its administrative practice on proportionality in August 2025 – with reliefs relating, among others, to Art. 16 and 28 to 30 and, in part, transition periods until the end of 2026 (BaFin supervisory notice of August 21, 2025). Anyone wishing to rely on this should check the details with a view to their own institution.
The register of information: from premiere to routine
The centerpiece of third-party management is the register of information under Art. 28(3): every financial entity maintains a record of all contractual arrangements with ICT third-party service providers – not just the critical ones. The first Europe-wide collection has taken place: the national supervisory authorities forwarded the registers to the European Supervisory Authorities (ESAs) by April 30, 2025.
In Germany, the second round is already history too: BaFin set the window from March 9 to 30, 2026, for submission, with a reference date of December 31, 2025, submitted via the MVP portal. This makes clear what the register will be going forward: not a one-off exercise, but an annual routine – the national authorities forward the registers to the ESAs by March 31 each year. For the next round, a window around March 2027 with a reference date of December 31, 2026, is accordingly to be expected; this date has not yet been officially announced.
In practical terms, this means: the register must be maintained throughout the year. New contracts, contract changes, terminations, changes in the subcontracting chain – anyone who first pulls it all together in February produces errors under time pressure.
Art. 30: what the contracts must contain
For ICT services supporting critical or important functions, Art. 30(2) and (3) prescribe concrete contractual contents. The most important ones from both sides’ perspective – whereby support during incidents and cooperation with authorities (para. 2) apply to all ICT contracts, and audit, exit, and testing obligations (para. 3) additionally to critical or important functions:
- Audit, access, and inspection rights for the financial entity and its supervisor – right into the provider’s premises and systems.
- Exit strategies with appropriate transition periods, so that a change of provider or a bring-back does not become an operational risk.
- Support with ICT incidents – at no additional cost or on terms agreed in advance.
- Cooperation with the competent authorities.
- Participation in threat-led penetration testing (TLPT).
For the IT provider, the classification is decisive: these points are not bargaining material invented by a particularly bold buyer – they are prescribed by regulation. Anyone who rejects them across the board is simply no longer eligible to contract with financial customers. What is negotiable, by contrast, are the modalities: how audits are announced and conducted, what transition periods are realistic, how incident support is remunerated when it goes beyond the agreed scope. This is exactly where professional contract design separates itself from defensive reflexes.
The chain behind it: oversight and subcontractors
Two developments from 2025 show that regulation has by now arrived directly at the providers as well.
First, on November 18, 2025, the ESAs designated the first critical ICT third-party providers (CTPPs). These providers now stand under direct European oversight; the list is updated annually. For the majority of providers, this changes nothing immediately – but it marks the direction: oversight is thinking the supply chain through to the provider.
Second, since July 22, 2025, Delegated Regulation (EU) 2025/532 on subcontracting has been in force. On the prevailing reading, providers must thereby enable their financial customers to have transparency over the onward award of critical functions – anyone who gives parts of their service to subcontractors must be able to disclose and manage this chain. The “black box model,” in which the customer does not know who actually operates, is not compatible with DORA.
Reporting deadlines your provider must support
Delegated Regulation (EU) 2025/301 specifies the reporting deadlines for serious ICT incidents:
- Initial notification: within 4 hours of classification, at the latest 24 hours after detection.
- Intermediate report: within 72 hours of the initial notification.
- Final report: within one month of the last intermediate report.
No financial entity can meet these deadlines alone if the incident happens at the provider. The contract must therefore secure the fast data flow: defined reporting channels, points of contact, and information obligations of the provider that fit the entity’s own reporting deadlines. A provider without end-to-end monitoring and without a practiced incident process is, at this point, a documented weakness in your own reporting system.
What follows from this – for both sides
For the financial entity: maintain the register throughout the year, reconcile contracts for critical functions against Art. 30, inquire into subcontracting chains, and set up your own provider management as a process instead of an annual firefighting exercise.
For the IT provider: accept the Art. 30 requirements and negotiate the modalities professionally – or write off the financial sector as a customer group. Conversely, this holds for choosing a partner: a managed services provider that already works with 24/7 monitoring, defined incident processes, and audit readiness has to bend little for DORA – it documents what it does anyway. A provider for whom audit rights and exit plans are new territory, by contrast, itself becomes a compliance risk for its customer.
How sector7 helps
As an owner-led IT provider, we work structurally within the framework that DORA demands of providers: 24/7 monitoring by our NOC, defined incident processes, and a lived Veeam backup practice, complemented by compliance consulting on DORA, NIS-2, ISO 27001, and TISAX. Our certified infrastructure expertise (Juniper, Cisco, HPE, F5, Fortinet, Palo Alto Networks) covers the technical side without passing it on into opaque chains. All of this at predictable flat monthly rates – itself a piece of contractual clarity in the spirit of Art. 30.
This article is a professional assessment and does not replace legal advice in individual cases.
Sources
- https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32022R2554
- https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital
- https://www.bafin.de/DE/unternehmen-maerkte/aufsicht/alle-unternehmen/dora/Informationsregister_und_Anzeigepflichten/Informationsregister_und_Anzeigepflichten_node.html
- https://www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en
- https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32025R0532
- https://legaltree.nl/en/dora-rts-on-subcontracting-of-ict-services-applicable-from-22-july-2025/
- https://www.springlex.eu/en/packages/dora/rts-ir-regulation/article-5/
- https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32025R0301
- https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Aufsichtsmitteilung/2025/aufsichtsmitteilung_2025_08_21_hinweise_artikel_16_dora.html