+49 6151 6290246

Published: August 6, 2026

Third-Party ICT Risk Under DORA: Obligations and Implementation

This text was generated using artificial intelligence (AI).

Regulation (EU) 2022/2554, known as DORA for short, has been directly applicable in all EU member states since January 17, 2025. For IT leaders, CISOs, and CEOs of financial institutions, managing third-party ICT risk is one of the most resource-intensive obligations under the regulation. DORA requires a continuously updated information register of ICT contracts, documented risk assessments prior to contract conclusion, tailored contract clauses, ongoing monitoring, and tested exit strategies. This article explains what Articles 28 through 30 specifically require and how you can practically implement these requirements using automated ratings and vendor risk management. Information current as of August 2026.

The following terms are also commonly used: ICT Third-Party Risk, DORA Third-Party Risk Management and Third-Party ICT Management. This refers to risks arising from ICT services provided by external or intra-group providers that a financial institution obtains.

Key Points at a Glance

What DORA Requires Regarding Third-Party ICT Risk

According to the European Securities and Markets Authority (ESMA), DORA covers 21 types of financial firms, including banks, insurers, payment and e-money institutions, securities firms, and asset management companies. Chapter V of the Regulation governs the management of third-party ICT risk. Article 28 sets out the general principles, Article 29 addresses the assessment of concentration risk, and Article 30 specifies the minimum contractual requirements.

The central principle is set forth in Article 28, paragraph 1: Financial firms remain fully responsible for compliance with the Regulation at all times, even if they outsource ICT services to third parties. Outsourcing transfers work, but not responsibility. The requirements are applied proportionately. The scope and depth of the measures depend on the size and risk profile of the firm, as well as on the criticality of the services received.

In addition, the regulation requires a strategy for third-party ICT risk, for which the management body is responsible and which it reviews regularly. Our article on DORA Regulation.

The Information Registry: The Foundation of Oversight

Article 28(3) requires financial firms to maintain a register of all contractual agreements with third-party ICT service providers, at the individual, subconsolidated, and consolidated levels. The register indicates whether an agreement supports critical or important functions.

Implementing Regulation (EU) 2024/2956 of November 29, 2024, specifies how the registry must be structured. It defines mandatory standard templates with linked reporting forms that also account for subcontracting to third parties. In Germany, according to its own announcement, BaFin accepted the registers for the first time between April 14 and 28, 2025, via its Reporting and Publication Platform (MVP), with data as of March 31, 2025. According to BaFin, since 2026, financial institutions have been submitting the register annually between March 9 and 30, with data as of December 31 of the previous year.

In addition, there are reporting requirements. Financial firms must report the number of new ICT agreements to the competent authority at least once a year and notify the authority in advance of planned contracts that involve critical or important functions. Those who maintain the registry manually in spreadsheets often underestimate the effort involved. The templates require consistent information across multiple linked reporting forms, extending all the way down to the subcontractor chain.

Risk Assessment Prior to Entering into a Contract

Before a financial institution enters into an ICT contract, Article 28(4) requires a documented assessment. This assessment determines whether the contract supports a critical or important function, whether regulatory requirements are met, and what risks the agreement entails. This explicitly includes the concentration risk referred to in Article 29: Can the provider be replaced? Are there already multiple contracts with the same service provider? And what risks arise from chains of subcontracting, including to third countries?

Part of the review involves conducting due diligence on the provider. Financial institutions assess whether the service provider is suitable and adheres to appropriate information security standards. In practice, this assessment is often based solely on self-reported information and certificates. A Security Rating It supplements these documents with an objective, externally measurable data point. It shows the status of the provider’s publicly accessible IT infrastructure, ranging from open services to certificate and mail server configurations to exposed software. This assessment of the provider’s financial situation, certificates, and contract compliance does not replace a credit rating. However, it makes the provider selection process more robust and facilitates faster comparisons.

Contractual Requirements Under Article 30

Article 30 defines the minimum content requirements for every ICT contract. Additional, stricter requirements apply to agreements that support critical or important functions. The following table summarizes the key points (selection, as of August 2026):

Contract RequirementLegal BasisScope of Application
Clear description of the agreed-upon functions and ICT servicesArt. 30, para. 2, DORAAll ICT Contracts
Specification of the locations where services are provided and data is processed, including notification of changesArt. 30, para. 2, DORAAll ICT Contracts
Policies Regarding Data Availability, Authenticity, Integrity, and ConfidentialityArt. 30, para. 2, DORAAll ICT Contracts
Access, Return, and Recovery of Data in the Event of Insolvency or Contract TerminationArt. 30, para. 2, DORAAll ICT Contracts
Support for ICT incidents at no additional cost or at a predetermined costArt. 30, para. 2, DORAAll ICT Contracts
Termination Rights and Minimum Notice PeriodsArt. 30, para. 2, DORAAll ICT Contracts
Statement of Work with Quantitative and Qualitative TargetsArt. 30, para. 3, DORACritical or important functions
Service Provider's Reporting Obligations in the Event of Developments with Significant ImpactArt. 30, para. 3, DORACritical or important functions
Contingency plans and ICT security measures, including testingArt. 30, para. 3, DORACritical or important functions
Participation in threat-based penetration tests (TLPT)Art. 30, para. 3, DORACritical or important functions
Unrestricted rights of access, inspection, and auditArt. 30, para. 3, DORACritical or important functions
Exit support with an appropriate transition periodArt. 30, para. 3, DORACritical or important functions

For many existing contracts, this means renegotiation. It makes sense to conduct a gap analysis of all current contracts against the requirements of Article 30, prioritizing them based on the criticality of the supported function.

Ongoing Monitoring and Exit Strategies

The real work begins once the contract is signed. DORA requires that the performance and risk profile of third-party ICT service providers be continuously monitored and that the information register be kept up to date. Article 28(7) also lists circumstances under which financial firms must be able to terminate contracts, such as in the event of significant legal violations by the provider, proven weaknesses in the provider’s ICT risk management, or if the regulatory authority can no longer effectively supervise the firm due to the agreement.

For critical or important functions, Article 28, paragraph 8, requires documented exit strategies. These include transition plans, evaluated alternatives, and a realistic plan for recovering or transferring data and functions without interrupting business operations.

For ongoing monitoring, a combination of two perspectives has proven effective. Questionnaires and supporting documentation provide the service provider’s internal perspective, while continuous technical measurements provide the external perspective. External Attack Surface Management It monitors a service provider’s publicly accessible systems without installing agents and without the provider’s involvement. If a provider’s rating deteriorates, this provides a documented basis for follow-up inquiries long before the next annual questionnaire is due.

From a technical external perspective, it is also important how quickly new vulnerability reports are addressed. LocateRisk uses Preemptive Intelligence, in order to cross-reference reports from multiple sources with an ICT service provider’s attack surface even before a final NVD assessment. This provides an additional, documentable basis for making a risk-based inquiry with the provider.

Critical Third-Party ICT Service Providers Under EU Oversight

A new feature of DORA is the supervisory framework for critical third-party ICT service providers. The three EU financial supervisory authorities—the EBA, EIOPA, and ESMA—identify providers whose failure would have serious consequences for the financial sector and place them under the direct supervision of a lead overseer. On November 18, 2025, the authorities published the first list of 19 designated providers, including major cloud providers, data center and network operators, and providers of software for the financial sector.

The Lead Overseer may request information, conduct investigations and inspections, and issue recommendations. If a critical third-party ICT service provider fails to comply with its obligations to cooperate, Article 35 of the Regulation provides for penalty payments of up to 1 percent of the average global daily revenue in the preceding fiscal year, imposed on a daily basis for a maximum of six months.

Important for financial institutions: Designating a provider as “critical” does not transfer any obligations. Risk assessment, contractual provisions, record-keeping, and monitoring remain the responsibility of each individual financial institution, even with respect to designated providers.

Implementation in Five Steps

The following five steps have proven effective in establishing a DORA-compliant management system for third-party ICT risk:

With the Third-Party Risk Management by LocateRisk It largely automates steps 2 and 4. The platform generates KPI-based security ratings for your service providers without requiring agent installation; an initial analysis is available within 48 hours. Questionnaire processes, invitations, and supporting documentation are all managed within the same system, hosted in certified German data centers. To put this in context: The analysis makes exposure and the software in use visible from the outside. However, it is not always possible to conclusively determine from the outside whether a specifically vulnerable version is in use. The registry itself and any contract amendments remain the responsibility of your legal and outsourcing departments; the platform provides the risk data and related documentation.

Frequently asked questions


For all financial firms within the scope of the regulation. ESMA lists 21 types, ranging from banks to insurers to asset management companies. The obligations are proportionate to the firm’s size and risk profile, but they do not apply in all cases.


Yes. The registry records all contractual agreements regarding ICT services, regardless of whether the service provider is part of the company’s own group. The evaluation and contractual requirements also apply to providers within the group.


Each financial institution assesses which functions are critical or important on its own. This classification determines which stricter contractual and exit requirements apply. Critical third-party ICT service providers, on the other hand, are designated centrally by the EU supervisory authorities. These providers are subject to direct EU oversight, beginning with 19 providers in November 2025.


No. A certificate is a useful component of due diligence. However, it does not replace the financial institution’s own risk assessment, the minimum contractual requirements, or ongoing monitoring. DORA requires the financial institution to conduct its own documented assessment.


Financial institutions keep the registry up to date on an ongoing basis. According to BaFin, it is submitted annually via the MVP platform; this was done for the first time in April 2025 with data as of March 31, 2025, and since 2026, it has been submitted between March 9 and March 30 with data as of December 31 of the previous year. Financial firms report the number of new ICT agreements to the authority at least once a year and provide advance notice of planned contracts involving critical or important functions.

Managing third-party ICT risk under DORA is an ongoing task, not a one-time exercise. By incorporating registers, assessments, and monitoring into structured processes early on, you can reduce both effort and audit risk. LocateRisk supports you in this effort with automated security ratings and a vendor risk management solution that consolidates questionnaires, supporting documentation, and a continuous external perspective on your service providers. To learn how to set up your service provider monitoring in compliance with DORA, visit our website Vendor Risk Management Made Easy.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish