{"id":9298,"date":"2026-08-06T10:03:38","date_gmt":"2026-08-06T10:03:38","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9298"},"modified":"2026-08-06T11:22:09","modified_gmt":"2026-08-06T11:22:09","slug":"dora-ict-third-party-risk","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/dora-ict-third-party-risk\/","title":{"rendered":"Third-Party ICT Risk Under DORA: Obligations and Implementation"},"content":{"rendered":"<h1 class=\"wp-block-heading\">Third-Party ICT Risk Under DORA: Obligations and Implementation<\/h1>\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n\n<p>Regulation (EU) 2022\/2554, known as DORA for short, has been directly applicable in all EU member states since January 17, 2025. For IT leaders, CISOs, and CEOs of financial institutions, managing third-party ICT risk is one of the most resource-intensive obligations under the regulation. DORA requires a continuously updated information register of ICT contracts, documented risk assessments prior to contract conclusion, tailored contract clauses, ongoing monitoring, and tested exit strategies. This article explains what Articles 28 through 30 specifically require and how you can practically implement these requirements using automated ratings and vendor risk management. Information current as of August 2026.<\/p>\n<p>The following terms are also relevant to the management of risks associated with external ICT service providers: <strong>ICT Third-Party Risk<\/strong>, <strong>ICT Third-Party Risk Management<\/strong> and <strong>ICT Third-Party Risk Management<\/strong> common. <strong>ICT Outsourcing Management<\/strong> is closely related to it, but has a narrower scope: DORA also covers ICT services that are not classified as traditional outsourcing.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>DORA has been directly applicable since January 17, 2025. Articles 28 through 30 govern the management of third-party ICT risk.<\/li><li>Financial institutions maintain a registry of all ICT contractual relationships. BaFin first collected this information in April 2025; since 2026, companies have been submitting it annually in March.<\/li><li>Before any contract is concluded, a risk assessment, due diligence, and an analysis of concentration risk are required.<\/li><li>Contracts covering critical or key functions require additional provisions, including audit rights, key performance indicators, and exit support.<\/li><li>On November 18, 2025, the EU regulatory authorities identified the first 19 critical third-party ICT service providers and placed them under direct oversight.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What DORA Requires Regarding Third-Party ICT Risk<\/h2>\n\n\n\n<p>According to the European Securities and Markets Authority (ESMA), DORA covers 21 types of financial firms, including banks, insurers, payment and e-money institutions, securities firms, and asset management companies. Chapter V of the Regulation governs the management of third-party ICT risk. Article 28 sets out the general principles, Article 29 addresses the assessment of concentration risk, and Article 30 specifies the minimum contractual requirements.<\/p>\n\n\n\n<p>The central principle is set forth in Article 28, paragraph 1: Financial firms remain fully responsible for compliance with the Regulation at all times, even if they outsource ICT services to third parties. Outsourcing transfers work, but not responsibility. The requirements are applied proportionately. The scope and depth of the measures depend on the size and risk profile of the firm, as well as on the criticality of the services received.<\/p>\n\n\n\n<p>In addition, the regulation requires a strategy for third-party ICT risk, for which the management body is responsible and which it reviews regularly. Our article on <a href=\"\/en\/know\/dora-regulation-overview\/\">DORA Regulation<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Information Registry: The Foundation of Oversight<\/h2>\n\n\n\n<p>Article 28(3) requires financial firms to maintain a register of all contractual agreements with third-party ICT service providers, at the individual, subconsolidated, and consolidated levels. The register indicates whether an agreement supports critical or important functions.<\/p>\n\n\n\n<p>Implementing Regulation (EU) 2024\/2956 of November 29, 2024, specifies how the registry must be structured. It defines mandatory standard templates with linked reporting forms that also account for subcontracting to third parties. In Germany, according to its own announcement, BaFin accepted the registers for the first time between April 14 and 28, 2025, via its Reporting and Publication Platform (MVP), with data as of March 31, 2025. According to BaFin, since 2026, financial institutions have been submitting the register annually between March 9 and 30, with data as of December 31 of the previous year.<\/p>\n\n\n\n<p>In addition, there are reporting requirements. Financial firms must report the number of new ICT agreements to the competent authority at least once a year and notify the authority in advance of planned contracts that involve critical or important functions. Those who maintain the registry manually in spreadsheets often underestimate the effort involved. The templates require consistent information across multiple linked reporting forms, extending all the way down to the subcontractor chain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Risk Assessment Prior to Entering into a Contract<\/h2>\n\n\n\n<p>Before a financial institution enters into an ICT contract, Article 28(4) requires a documented assessment. This assessment determines whether the contract supports a critical or important function, whether regulatory requirements are met, and what risks the agreement entails. This explicitly includes the concentration risk referred to in Article 29: Can the provider be replaced? Are there already multiple contracts with the same service provider? And what risks arise from chains of subcontracting, including to third countries?<\/p>\n\n\n\n<p>Part of the review involves conducting due diligence on the provider. Financial institutions assess whether the service provider is suitable and adheres to appropriate information security standards. In practice, this assessment is often based solely on self-reported information and certificates. A <a href=\"\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> It supplements these documents with an objective, externally measurable data point. It shows the status of the provider\u2019s publicly accessible IT infrastructure, ranging from open services to certificate and mail server configurations to exposed software. This assessment of the provider\u2019s financial situation, certificates, and contract compliance does not replace a credit rating. However, it makes the provider selection process more robust and facilitates faster comparisons.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Contractual Requirements Under Article 30<\/h2>\n\n\n\n<p>Article 30 defines the minimum content requirements for every ICT contract. Additional, stricter requirements apply to agreements that support critical or important functions. The following table summarizes the key points (selection, as of August 2026):<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Contract Requirement<\/th><th>Legal Basis<\/th><th>Scope of Application<\/th><\/tr><\/thead><tbody><tr><td>Clear description of the agreed-upon functions and ICT services<\/td><td>Art. 30, para. 2, DORA<\/td><td>All ICT Contracts<\/td><\/tr><tr><td>Specification of the locations where services are provided and data is processed, including notification of changes<\/td><td>Art. 30, para. 2, DORA<\/td><td>All ICT Contracts<\/td><\/tr><tr><td>Policies Regarding Data Availability, Authenticity, Integrity, and Confidentiality<\/td><td>Art. 30, para. 2, DORA<\/td><td>All ICT Contracts<\/td><\/tr><tr><td>Access, Return, and Recovery of Data in the Event of Insolvency or Contract Termination<\/td><td>Art. 30, para. 2, DORA<\/td><td>All ICT Contracts<\/td><\/tr><tr><td>Support for ICT incidents at no additional cost or at a predetermined cost<\/td><td>Art. 30, para. 2, DORA<\/td><td>All ICT Contracts<\/td><\/tr><tr><td>Termination Rights and Minimum Notice Periods<\/td><td>Art. 30, para. 2, DORA<\/td><td>All ICT Contracts<\/td><\/tr><tr><td>Statement of Work with Quantitative and Qualitative Targets<\/td><td>Art. 30, para. 3, DORA<\/td><td>Critical or important functions<\/td><\/tr><tr><td>Service Provider's Reporting Obligations in the Event of Developments with Significant Impact<\/td><td>Art. 30, para. 3, DORA<\/td><td>Critical or important functions<\/td><\/tr><tr><td>Contingency plans and ICT security measures, including testing<\/td><td>Art. 30, para. 3, DORA<\/td><td>Critical or important functions<\/td><\/tr><tr><td>Participation in threat-based penetration tests (TLPT)<\/td><td>Art. 30, para. 3, DORA<\/td><td>Critical or important functions<\/td><\/tr><tr><td>Unrestricted rights of access, inspection, and audit<\/td><td>Art. 30, para. 3, DORA<\/td><td>Critical or important functions<\/td><\/tr><tr><td>Exit support with an appropriate transition period<\/td><td>Art. 30, para. 3, DORA<\/td><td>Critical or important functions<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>For many existing contracts, this means renegotiation. It makes sense to conduct a gap analysis of all current contracts against the requirements of Article 30, prioritizing them based on the criticality of the supported function.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ongoing Monitoring and Exit Strategies<\/h2>\n\n\n\n<p>The real work begins once the contract is signed. DORA requires that the performance and risk profile of third-party ICT service providers be continuously monitored and that the information register be kept up to date. Article 28(7) also lists circumstances under which financial firms must be able to terminate contracts, such as in the event of significant legal violations by the provider, proven weaknesses in the provider\u2019s ICT risk management, or if the regulatory authority can no longer effectively supervise the firm due to the agreement.<\/p>\n\n\n\n<p>For critical or important functions, Article 28, paragraph 8, requires documented exit strategies. These include transition plans, evaluated alternatives, and a realistic plan for recovering or transferring data and functions without interrupting business operations.<\/p>\n\n\n\n<p>For ongoing monitoring, a combination of two perspectives has proven effective. Questionnaires and supporting documentation provide the service provider\u2019s internal perspective, while continuous technical measurements provide the external perspective. <a href=\"\/en\/know\/what-is-easm\/\">External Attack Surface Management<\/a> It monitors a service provider\u2019s publicly accessible systems without installing agents and without the provider\u2019s involvement. If a provider\u2019s rating deteriorates, this provides a documented basis for follow-up inquiries long before the next annual questionnaire is due.<\/p>\n<p>From a technical external perspective, it is also important how quickly new vulnerability reports are addressed. LocateRisk uses <a href=\"\/en\/landing\/preemptive-intelligence-identifying-cyber-risks-before-they-become-apparent\/\">Preemptive Intelligence<\/a>, in order to cross-reference reports from multiple sources with an ICT service provider\u2019s attack surface even before a final NVD assessment. This provides an additional, documentable basis for making a risk-based inquiry with the provider.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Critical Third-Party ICT Service Providers Under EU Oversight<\/h2>\n\n\n\n<p>A new feature of DORA is the supervisory framework for critical third-party ICT service providers. The three EU financial supervisory authorities\u2014the EBA, EIOPA, and ESMA\u2014identify providers whose failure would have serious consequences for the financial sector and place them under the direct supervision of a lead overseer. On November 18, 2025, the authorities published the first list of 19 designated providers, including major cloud providers, data center and network operators, and providers of software for the financial sector.<\/p>\n\n\n\n<p>The Lead Overseer may request information, conduct investigations and inspections, and issue recommendations. If a critical third-party ICT service provider fails to comply with its obligations to cooperate, Article 35 of the Regulation provides for penalty payments of up to 1 percent of the average global daily revenue in the preceding fiscal year, imposed on a daily basis for a maximum of six months.<\/p>\n\n\n\n<p>Important for financial institutions: Designating a provider as \u201ccritical\u201d does not transfer any obligations. Risk assessment, contractual provisions, record-keeping, and monitoring remain the responsibility of each individual financial institution, even with respect to designated providers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Implementation in Five Steps<\/h2>\n\n\n\n<p>The following five steps have proven effective in establishing a DORA-compliant management system for third-party ICT risk:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Step 1: Take inventory.<\/strong> Take inventory of all ICT contracts, assign critical or important functions, and establish the information register in accordance with the templates provided in Implementing Regulation (EU) 2024\/2956.<\/li><li><strong>Step 2: Define the evaluation process.<\/strong> Establish due diligence, concentration review, and risk assessment as a standard process prior to contract execution, including an external rating for each provider as a basis for comparison.<\/li><li><strong>Step 3: Update the contracts.<\/strong> Review existing contracts against Article 30 and prioritize renegotiations based on criticality.<\/li><li><strong>Step 4: Automate monitoring.<\/strong> Consolidate questionnaires, supporting documentation, and ongoing ratings into a single vendor risk management system, complete with reminders, escalations, and audit-compliant documentation.<\/li><li><strong>Step 5: Test exit strategies.<\/strong> Document contingency plans for critical functions, conduct regular drills, and keep the registry up to date.<\/li><\/ul>\n\n\n\n<p>With the <a href=\"\/en\/landing\/third-party-risk-management\/\">Third-Party Risk Management by LocateRisk<\/a> It largely automates steps 2 and 4. The platform generates KPI-based security ratings for your service providers without requiring agent installation; an initial analysis is available within 48 hours. Questionnaire processes, invitations, and supporting documentation are all managed within the same system, hosted in certified German data centers. To put this in context: The analysis makes exposure and the software in use visible from the outside. However, it is not always possible to conclusively determine from the outside whether a specifically vulnerable version is in use. The registry itself and any contract amendments remain the responsibility of your legal and outsourcing departments; the platform provides the risk data and related documentation.<\/p>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">To whom do the DORA requirements regarding third-party ICT risk apply?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">For all financial firms within the scope of the regulation. ESMA lists 21 types, ranging from banks to insurers to asset management companies. The obligations are proportionate to the firm\u2019s size and risk profile, but they do not apply in all cases.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Do in-house IT service providers also have to be listed in the information registry?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Yes. The registry records all contractual agreements regarding ICT services, regardless of whether the service provider is part of the company\u2019s own group. The evaluation and contractual requirements also apply to providers within the group.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What distinguishes critical functions from critical third-party ICT service providers?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Each financial institution assesses which functions are critical or important on its own. This classification determines which stricter contractual and exit requirements apply. Critical third-party ICT service providers, on the other hand, are designated centrally by the EU supervisory authorities. These providers are subject to direct EU oversight, beginning with 19 providers in November 2025.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is an ISO 27001 certificate from the service provider sufficient as proof?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. A certificate is a useful component of due diligence. However, it does not replace the financial institution\u2019s own risk assessment, the minimum contractual requirements, or ongoing monitoring. DORA requires the financial institution to conduct its own documented assessment.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How often does the information registry need to be updated?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Financial institutions keep the registry up to date on an ongoing basis. According to BaFin, it is submitted annually via the MVP platform; this was done for the first time in April 2025 with data as of March 31, 2025, and since 2026, it has been submitted between March 9 and March 30 with data as of December 31 of the previous year. Financial firms report the number of new ICT agreements to the authority at least once a year and provide advance notice of planned contracts involving critical or important functions.<\/p><\/div><\/div><\/div><\/div>\n\n\n\n<p>Managing third-party ICT risk under DORA is an ongoing task, not a one-time exercise. By incorporating registers, assessments, and monitoring into structured processes early on, you can reduce both effort and audit risk. LocateRisk supports you in this effort with automated security ratings and a vendor risk management solution that consolidates questionnaires, supporting documentation, and a continuous external perspective on your service providers. To learn how to set up your service provider monitoring in compliance with DORA, visit our website <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management Made Easy<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Information Registers, Contractual Clauses, Exit Strategies: What DORA Requires Regarding Third-Party ICT Risks and How to Implement These Obligations in Five Steps.<\/p>","protected":false},"author":0,"featured_media":0,"template":"","wissen_thema":[819],"class_list":["post-9298","wissen","type-wissen","status-publish","hentry","wissen_thema-regulatorik-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>IKT-Drittparteirisiko unter DORA: Pflichten \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"DORA regelt das IKT-Drittparteirisiko: Informationsregister, Vertragspflichten, Exit-Strategien. So setzen Finanzunternehmen die Anforderungen um.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/dora-ict-third-party-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IKT-Drittparteirisiko unter DORA: Pflichten \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"DORA regelt das IKT-Drittparteirisiko: Informationsregister, Vertragspflichten, Exit-Strategien. So setzen Finanzunternehmen die Anforderungen um.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/dora-ict-third-party-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T11:22:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-ikt-drittparteirisiko\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-ikt-drittparteirisiko\\\/\",\"name\":\"IKT-Drittparteirisiko unter DORA: Pflichten \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T10:03:38+00:00\",\"dateModified\":\"2026-08-06T11:22:09+00:00\",\"description\":\"DORA regelt das IKT-Drittparteirisiko: Informationsregister, Vertragspflichten, Exit-Strategien. So setzen Finanzunternehmen die Anforderungen um.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-ikt-drittparteirisiko\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-ikt-drittparteirisiko\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-ikt-drittparteirisiko\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"IKT-Drittparteirisiko unter DORA: Pflichten und Umsetzung\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Third-Party ICT Risk Under DORA: Obligations \u2013 LocateRisk","description":"DORA addresses third-party ICT risk: information registers, contractual obligations, and exit strategies. Here\u2019s how financial institutions are implementing the requirements.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/dora-ict-third-party-risk\/","og_locale":"en_US","og_type":"article","og_title":"IKT-Drittparteirisiko unter DORA: Pflichten \u2013 LocateRisk","og_description":"DORA regelt das IKT-Drittparteirisiko: Informationsregister, Vertragspflichten, Exit-Strategien. So setzen Finanzunternehmen die Anforderungen um.","og_url":"http:\/\/locaterisk.com\/en\/know\/dora-ict-third-party-risk\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T11:22:09+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/dora-ikt-drittparteirisiko\/","url":"http:\/\/locaterisk.com\/de\/wissen\/dora-ikt-drittparteirisiko\/","name":"Third-Party ICT Risk Under DORA: Obligations \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T10:03:38+00:00","dateModified":"2026-08-06T11:22:09+00:00","description":"DORA addresses third-party ICT risk: information registers, contractual obligations, and exit strategies. Here\u2019s how financial institutions are implementing the requirements.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/dora-ikt-drittparteirisiko\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/dora-ikt-drittparteirisiko\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/dora-ikt-drittparteirisiko\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"IKT-Drittparteirisiko unter DORA: Pflichten und Umsetzung"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"version-history":[{"count":5,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9298\/revisions"}],"predecessor-version":[{"id":9341,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9298\/revisions\/9341"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9298"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}