All resources
Checklist12 min readLegal, procurement, compliance

DORA Contract Requirements Checklist

The contractual provisions DORA Article 30 expects in ICT arrangements, split between the baseline set and the additional requirements for services supporting critical or important functions.

Baseline provisions for every ICT arrangement

These apply regardless of criticality. They are also the ones most often missing from older contracts signed before DORA applied.

  • Clear description of the ICT services supplied
  • Locations where services are provided and data is processed
  • Data protection, availability, integrity and confidentiality provisions
  • Assistance on ICT incidents at no additional cost or at agreed cost
  • Cooperation with competent authorities
  • Termination rights and notice periods

Additional provisions for critical or important functions

Where the service supports a critical or important function, the arrangement needs more: service levels with precise quantitative targets, full audit and inspection rights, participation in your testing programme, and exit arrangements that are genuinely executable.

  • Quantitative performance targets and remedies
  • Unrestricted audit, access and inspection rights
  • Cooperation with threat-led penetration testing
  • Notification obligations for material subcontracting changes
  • Exit strategy with transition support and data return

Reviewing at portfolio scale

Reviewing every contract manually against twenty clause topics is where legal teams lose months. Automated clause mapping narrows the work to the gaps: which arrangements lack audit rights, which have no exit provisions, which are silent on subcontracting.

Keep a lawyer in the loop on every conclusion. The value of automation here is triage, not judgement.

Remediating gaps

Gaps rarely close at once. Prioritise by criticality and renewal date: arrangements supporting critical functions that renew this year get addenda now; low-criticality gaps go into the renewal cycle.

Checklist

Work through it.

Print this, or use it as the acceptance criteria for your own programme.

Every arrangement

  • Service description and locations are specified
  • Data protection provisions are present
  • Incident assistance obligations are defined
  • Authority cooperation clause is present
  • Termination rights are workable

Critical or important functions

  • Quantitative service levels with remedies
  • Unrestricted audit and inspection rights
  • Testing cooperation clause
  • Subcontracting notification and objection rights
  • Documented, executable exit strategy

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.