Law / European Union

DORA, Articles 28-30 (ICT Third-Party Risk Management)

Regulation (EU) 2022/2554, Arts. 28-30

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 17 January 2025.

A sector security regimes rule binding private bodies.

As of 24 September 2026.

What it requires

  • This duty binds you as the financial entity contracting for an ICT service, not the ICT third-party service provider directly, though the provider's own obligations enter through the contract terms Article 30 requires you to include; it reaches you where you are a financial entity under Article 2(1), points (a) to (t), of Regulation (EU) 2022/2554.
  • Manage ICT third-party risk as an integral, proportionate component of your ICT risk management framework, and, unless you are a microenterprise or an entity covered by Article 16(1), adopt and regularly review a strategy on ICT third-party risk.
  • Maintain and update a register of all your ICT services contracts, distinguishing those supporting a critical or important function, report on it at least yearly to your competent authority, and produce it in full on the authority's request.
  • Before entering into an ICT services contract, assess whether it supports a critical or important function, whether supervisory conditions for contracting are met, and the concentration risk under Article 29, including whether the provider is easily substitutable and whether you already rely on it, or a closely connected provider, for other critical functions.
  • Put every ICT services contract in writing in one document, covering at minimum the functions and locations involved, data-protection and access-on-termination provisions, service levels, the provider's duty to assist you on an incident and to cooperate with your regulators, termination rights, and your security-awareness programme.
  • For a contract supporting a critical or important function, add quantitative service level targets, an unrestricted right to monitor, inspect and audit the provider, the provider's cooperation in your threat-led penetration testing, and an exit strategy with a mandatory transition period.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

The competent authority designated for each category of financial entity under Article 46 (for example the entity's banking, payments, investment-firm, or insurance supervisor), or the ECB for a credit institution classified as significant under Regulation (EU) No 1024/2013, exercising the administrative penalty and remedial powers of Articles 50 and 51. A critical ICT third-party service provider is overseen separately, by the Lead Overseer under Chapter V, Section II.

What it reaches

Obligation class

Governance, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 28 requires a financial entity to manage ICT third-party risk as an integral component of its ICT risk management framework, proportionate to the nature, scale, complexity and criticality of its ICT-related dependencies.

Article 28(2) requires the entity, other than a microenterprise or one covered by Article 16(1), to adopt and regularly review a strategy on ICT third-party risk, and Article 28(3) requires it to maintain and update a register of information on all its ICT services contracts, distinguishing those supporting a critical or important function, report on the register at least yearly to its competent authority, and produce it in full on request.

Article 28(4) requires the entity, before entering into a contractual arrangement, to assess whether it covers a critical or important function, whether supervisory conditions for contracting are met, the risks the arrangement poses including the concentration risk Article 29 describes, and to carry out due diligence and a conflicts-of-interest check on the prospective provider.

Article 29 is that preliminary assessment of ICT concentration risk: whether the provider is easily substitutable, whether the entity already has multiple critical-function contracts with the same or a closely connected provider, and, where subcontracting is possible, the risk a long or complex subcontracting chain poses to the entity's ability to monitor the function and to the competent authority's ability to supervise it, plus the insolvency-law and data-protection posture of a provider or subcontractor established in a third country.

Article 30(1) and (2) require every ICT services contract to be in writing, in a single document, and to cover at minimum a description of the functions and services provided, the locations where the service and any subcontracted part of it will run and where data will be processed, provisions on the availability, integrity and confidentiality of data including personal data, the entity's right to access, recover and return its data if the provider becomes insolvent or the contract ends, service level descriptions, the provider's duty to assist the entity on an ICT incident, the provider's duty to cooperate with the entity's competent and resolution authorities, termination rights and notice periods, and the provider's participation in the entity's security awareness and training programme.

Article 30(3) requires a contract supporting a critical or important function to add, on top of those elements, quantitative and qualitative service level targets, notice of anything that could materially affect the provider's ability to perform, business contingency and security-testing obligations, the provider's cooperation in the entity's threat-led penetration testing, the entity's unrestricted right to monitor, inspect and audit the provider on site, and an exit strategy with a mandatory transition period letting the entity move to another provider or bring the function in-house.

When LexLint raises it

  • provides_financial_services

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2022/2554

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app