DORA for ICT providers: what your financial sector clients now require

Compliance9 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

The Digital Operational Resilience Act has applied since 17 January 2025. As an ICT provider you are not on the list of entities that Regulation (EU) 2022/2554 binds directly, and yet you meet it at every contract renewal with a bank, insurer or payment institution. The requirements your client has to meet largely end up with you.

Two routes by which DORA reaches you

The first route is the contract. Financial entities must include a fixed set of clauses in their agreements for ICT services, and that set grows heavier as soon as the service supports a critical or important function. Your client cannot negotiate those away, not even when your standard terms fit them badly.

The second route applies to a small group. The European Supervisory Authorities designate providers as critical ICT third-party providers when a large part of the financial sector depends on them. A designated provider is assigned a Lead Overseer, comes under direct European oversight and can expect inspections and recommendations. That mainly affects the large cloud and infrastructure providers. For everyone else, DORA arrives entirely through the contract.

What ends up in the contract

Article 30 of the regulation sets out what every agreement for ICT services must contain: a clear description of the service, the locations where data is processed and stored, provisions on availability and data protection, support during incidents, and the conditions under which the agreement ends.

Where the service supports a critical or important function, a second layer follows: measurable performance targets rather than best-efforts language, notification deadlines for incidents that affect your client, access, inspection and audit rights for your client and for its supervisor, conditions for subcontracting including whether you may replace a subcontractor without consent, and an exit strategy with a transition period.

Two of these produce most of the discussion at the negotiating table: the audit right and subcontracting. Neither can be drafted away, because your client has to be able to show them to its supervisor.

The register of information: what your client will ask you for

Every financial entity maintains a register of information covering all contractual arrangements for ICT services and submits it periodically to its supervisor. The register is a structured file with fixed fields, and some of those fields can only be filled in with data from you.

Expect questions about your identification code, usually the LEI, your country of establishment, the countries where the service is provided and where data is stored, the type of service, and the chain of subcontractors involved in delivering it. That last question goes further than providers expect: it is not only about the party you engage, but about the chain below it as far as it touches the service.

Providers who assemble this once and maintain it as a living document can answer such a request straight away. Those who work it out again for every request hold up their client's submission. It is also the same information you need for your own supplier management, so none of the work is wasted.

Notification deadlines that flow into your SLA

For a major incident your client reports to its supervisor in three steps: an initial notification no later than four hours after classifying the incident as major and in any case within 24 hours of becoming aware of it, an intermediate report within 72 hours and a final report within one month.

That clock formally applies to your client, not to you. In practice it means your client needs a notification from you well before its own first deadline expires, with enough information to judge the severity. A message stating only that there is an outage does not help. What does help is a fixed notification format with the start time, the service affected, the suspected cause, the number of clients or transactions affected as far as known, and the current status. Put it in your incident response plan and rehearse it once, because an escalation path that exists only on paper does not work on a Sunday evening.

Audit rights, and why an assurance report works out cheaper

The audit right is the clause that costs providers the most. If several financial sector clients each run their own audit, a significant part of the year goes into questionnaires and site visits, usually involving the same few people in your organisation.

DORA explicitly leaves room for alternatives. Clients may conduct pooled audits and may rely on third-party audit reports, as long as those reports cover the service delivered and the relevant controls. That is why an ISAE 3402 report or a SOC 2 report is worth so much in this market: one examination a year by an independent auditor, and a report you can hand to every client.

Watch the scope. A report covering security only does not answer the questions on availability and processing integrity. For financial sector clients, availability, continuity, change management and subcontracting are precisely the subjects under examination. We guide that process from our ISAE 3402 practice.

The exit clause that often stays theoretical

DORA asks for an exit strategy that can actually be executed, not for a clause containing the word exit. The questions that need answering are concrete: in what format does the client get its data back, within what period, at what cost, and how long does the service keep running during the migration.

This is where your client most often gets stuck during its own assessment, and where you as a provider can make the most difference at the lowest cost. An export format that is documented and has been tested once, plus a transition period written into the contract, removes most of that conversation.

Where it goes wrong in practice

Four patterns keep recurring. The standard SLA is written in best-efforts language and contains no measurable targets, so the client has nothing to demonstrate. The subcontracting chain has never been mapped, so the register request sits unanswered. The audit right is negotiated away, after which the client still has to explain to its supervisor why it has no visibility into a critical service. And continuity is described but never tested, so there is no test result to share.

All four can be fixed before a client asks, and it is worth doing. Financial institutions have to account for their supplier base to their supervisor, which turns demonstrability into a selection criterion rather than a formality after the fact. What your client has to put in place itself is covered in DORA: what the regulation requires of financial institutions.

Frequently asked questions

Does DORA apply to me directly as an ICT provider?+

Usually not. The obligations in DORA are addressed to financial entities. You encounter the regulation through the contractual clauses your client is required to include. Only providers designated by the European Supervisory Authorities as critical ICT third-party providers come under direct European oversight, with a Lead Overseer assigned to them.

What is a critical ICT third-party provider?+

A provider designated by the European Supervisory Authorities because a large part of the financial sector depends on its services. The designation considers the systemic importance of the entities served, the criticality of the functions supported and how substitutable the service is. In practice this concerns large cloud and infrastructure providers.

Which clauses must my client include in the contract?+

For every ICT service: a description of the service, the locations where data is processed and stored, provisions on availability and data protection, incident support and the conditions for termination. Where the service supports a critical or important function, add measurable performance targets, incident notification deadlines, access, inspection and audit rights, conditions for subcontracting, and an exit strategy with a transition period.

Does an ISAE 3402 or SOC 2 report satisfy the audit rights under DORA?+

It does not replace the audit right, but it is how clients exercise that right in practice. DORA allows financial entities to rely on third-party audit reports provided those reports cover the service delivered and the relevant controls. Watch the scope: a report covering security only does not answer the questions on availability, continuity and subcontracting.

How quickly do I have to report an incident to my financial sector client?+

DORA imposes no deadline on you, but your contract will. Your client must submit an initial notification to its supervisor no later than four hours after classifying the incident as major and in any case within 24 hours of becoming aware of it, followed by an intermediate report within 72 hours and a final report within one month. Clients translate that into notification windows of a few hours, with enough detail to classify the incident.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us
DORA for ICT providers: contract clauses, deadlines and audit rights · Secure Audit