Get Demo
↑

DORA ICT Third-Party Risk: Contractual Requirements (Article 30) and Critical Providers

Article 30 key contractual provisions for ICT services supporting critical or important functions.

Published: September 2026 Compliance · DORA 8–12 min read

Article 30 lists key contractual provisions financial entities must address when ICT services support critical or important functions. It sits inside a broader third-party risk chapter that also covers strategy, register of information, and CTPP oversight.

Related: DORA hub · Register of information · For ICT providers.

Article 30 focus: Contracts for ICT services supporting critical or important functions must include a set of key provisions (service descriptions, locations, data protection, access/audit/inspection rights, subcontracting conditions, cooperation with authorities, termination assistance, and related resilience terms). Exact drafting should track the Regulation text and RTS — not a vendor checklist alone.

Programme Layers

Critical ICT Third-Party Providers

Certain providers may be designated as Critical ICT Third-Party Providers and brought under ESA oversight. Financial entities still remain responsible for their own contractual and operational resilience duties even when a provider is designated.

Non-EU Vendors

Location outside the EU does not remove contractual or register obligations when services support in-scope financial entities. See DORA for ICT service providers.

How CyberSilo Helps

Align Contracts and the Register

Map Article 30 themes to contract playbooks and keep the register current in CSA.

Frequently Asked Questions

Does Article 30 apply to every SaaS tool?

Article 30 key provisions target ICT services that support critical or important functions. Lower-criticality tools still need proportionate third-party risk handling and may appear in the register.

What is a CTPP?

A Critical ICT Third-Party Provider designated for Union-level oversight. Designation does not replace the financial entity’s own third-party risk duties.

Do we need audit rights in every contract?

Access, inspection, and audit themes are central Article 30 expectations for critical/important-function ICT services — negotiate them before signature, not after an examination letter.

Hub · Pillars · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!