Back to blog

DORA contractual clauses: the checklist of mandatory provisions (Article 30)

DORA Article 30: mandatory clauses for all ICT contracts, and enhanced clauses for critical functions. The checklist explained.

By Arthur Chédeville··Read time : 8 min·For Procurement, risk, compliance, legal
Mandatory DORA contractual clauses

Among the ACPR's control priorities for 2026 is, explicitly, the compliance of financial entities' contracts with their IT providers. In other words, your ICT contracts are going to be examined. And the reference text is Article 30 of the DORA regulation, which lists the clauses that must appear in these agreements.

Article 30 works on two levels: a common base applicable to all ICT contracts (paragraph 2), and a set of enhanced clauses that are added for contracts supporting critical or important functions (paragraph 3). Here is the checklist, explained.

The common base: mandatory clauses for all ICT contracts (Art. 30.2)

These provisions apply to all agreements, regardless of the service's criticality:

  1. Clear and complete description of services. Nature, scope, service levels, with enough detail to allow effective monitoring of performance. The conditions applicable to subcontracting must also be specified.
  2. Location of data and processing. The places where services are provided and where data is processed, with prior notification of any change.
  3. Data protection. Guarantees on the availability, authenticity, integrity and confidentiality of data processed on the entity's behalf.
  4. Access, recovery and return of data. Guarantees allowing data to be recovered and returned in the event of the provider's insolvency, resolution or business interruption.
  5. Service level descriptions (SLAs).
  6. Assistance in the event of an ICT incident. The provider must provide assistance in the event of an incident related to the services, at no additional cost or at a cost determined in advance.
  7. Cooperation with authorities. Obligation for the provider to fully cooperate with the competent and resolution authorities.
  8. Termination rights. With minimum notice periods.
  9. Participation in awareness programmes on the entity's ICT security.

The enhanced clauses: critical or important functions (Art. 30.3)

When the service supports a critical or important function, these provisions are added to the base:

  1. Precise performance objectives. Quantitative and qualitative targets, enhanced SLAs, allowing measurable monitoring.
  2. Enhanced audit rights. Unlimited rights of access, inspection and audit by the financial entity (or a designated third party) and by the competent authority. Crucial point: these rights cannot be hindered by other arrangements or practical limitations.
  3. Tested business continuity plans. The provider must have continuity and recovery plans, and test them.
  4. Participation in resilience testing. Obligation to take part in the entity's penetration tests (TLPT) where required.
  5. Exit strategies. With an adequate transition period ensuring continuity in the event of disengagement.
  6. Subcontracting framework. Notification of material subcontracting, prior approval for subcontractors supporting critical functions, cascading application of equivalent requirements, and maintenance of visibility over the whole chain.

The non-negotiable point: the right to audit

A frequent confusion deserves to be cleared up: the right to audit is not a negotiation option. It is a regulatory requirement. If a provider refuses to grant the rights of access, inspection and audit, the financial entity cannot conclude the contract — or must terminate an existing one. Facing large technology players sometimes reluctant, DORA precisely rebalances the power dynamic.

Interaction with GDPR

DORA clauses and GDPR clauses complement each other without substituting. The contract must satisfy both frameworks. If the provider is outside the EU or transfers data to third countries, GDPR transfer mechanisms apply, and DORA adds its own requirements on data location and risks linked to foreign legislation.

The compliance method, step by step

Reviewing all your ICT contracts is a considerable undertaking, especially for a largely cloud-based architecture. The effective approach:

  1. Inventory all active ICT contracts (this is also the prerequisite for the register of information).
  2. Qualify the services supporting critical or important functions, and document this qualification.
  3. Audit the gaps between each contract and the 30.2 / 30.3 requirements, prioritising critical contracts.
  4. Remediate by amendment where possible, or by renegotiation. When a provider refuses, document the risk assessment and compensating controls.
  5. Standardise by integrating DORA standard clauses into contract templates and tender documents.

A point of vigilance: contracting with a critical third-party provider (CTPP) designated at European level does not remove any contractual obligation. Responsibility remains the financial entity's — you can outsource a service, never the responsibility.

Where Axenia fits in. Axenia analyses your ICT contracts clause by clause against the 30.2 and 30.3 requirements, flags missing or insufficient provisions, distinguishes critical contracts, and links each contract to its provider and the functions it supports — turning contractual audit from a manual undertaking into a continuous diagnostic.


This article is educational in purpose and does not constitute legal advice. Drafting and reviewing contractual clauses is a matter for qualified legal counsel. Refer to the official text of Article 30 and the applicable RTS.

See how Axenia analyses your ICT contracts. Book a demo →