Last updated: 5 August 2026.
Quick answer. The DORA Regulation (Digital Operational Resilience Act) requires financial entities to include specific contractual clauses in agreements with third-party ICT service providers. The mandatory minimum content includes: a comprehensive description of all functions and services; the locations where services are delivered and data is processed, inside or outside the European Union; service level agreements defining availability, performance and response times; clauses allowing continuous monitoring of ICT-related risks; guarantees of the security and protection of personal data; mechanisms for data access, recovery and restoration if the provider becomes insolvent or is disrupted; full cooperation with competent authorities; and termination rights. These clauses aim to ensure business continuity, data protection and an effective response to security incidents.
The Digital Operational Resilience Act (DORA) Regulation imposes new requirements on financial entities regarding cybersecurity and digital operational resilience. One of the key tools to comply with these demands is the inclusion of specific contractual clauses in agreements with third-party ICT service providers. These clauses are crucial to ensure business continuity, data protection, and the ability to respond to security incidents.
Below, we leave you the video of the collaboration, in case it is of interest to you:
Typology of Fundamental Contractual Clauses and Their Requirements:
The DORA Regulation mandates that contracts with third-party ICT service providers include, at a minimum, the following clauses:
- Comprehensive Description of Functions and Services: It is necessary to precisely detail all functions and services that the provider will deliver to the financial entity, including, for example, the development and maintenance of applications, cloud storage, network management, cybersecurity services, etc.
- Service Delivery and Data Processing Locations: The contract must specify where the services will be provided and where data will be processed, both within and outside the European Union.
- Service Level Agreements (SLAs): The expected service levels must be clearly defined in terms of availability, performance, and response time.
- ICT Risk Monitoring: The contract must include clauses allowing the financial entity to continuously monitor ICT-related risks, such as periodic reports on security status and incidents.
- Security and Data Protection Guarantees: The provider must ensure the accessibility, availability, integrity, security, and protection of personal data processed under the contract, complying with applicable data protection regulations.
- Data Access and Recovery in Case of Insolvency: Mechanisms must be established to ensure that the financial entity can access, recover, and restore its data in the event of the provider’s insolvency, resolution, or operational disruption.
- Cooperation with Authorities: The provider must be obligated to fully cooperate with competent authorities and the financial entity’s resolution authorities in the event of security incidents or investigations.
- Contract Termination: The rights of termination and minimum notification periods for contract termination must be established, considering the expectations of competent authorities and resolution authorities.

Si te ha interesado este artículo no dudes en leer:
DORA and ICT Incident Notification: A Digital Big Brother for Banking?
By ensuring that contracts with third-party ICT service providers include these fundamental clauses, financial entities can take proactive measures to protect their technological infrastructure and minimize cybersecurity-related risks.
If you enjoyed this article, you might also find the following one interesting:
DORA and Digital Trust: The Value of Standard Contractual Clauses for Cloud Services
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.
Frequently asked questions
The DORA Regulation imposes cybersecurity and digital operational resilience requirements on financial entities. Including specific clauses in contracts with third-party ICT service providers is one of the key tools to comply with these demands, since such clauses ensure business continuity, the protection of data and the entity’s ability to respond to security incidents.
The contract must include a comprehensive description of all functions and services the provider will deliver to the financial entity, such as application development and maintenance, cloud storage, network management or cybersecurity services. It must also specify the locations where the services will be provided and where data will be processed, both within and outside the European Union.
Service level agreements form part of the minimum contractual content required by DORA. Expected service levels must be clearly defined in terms of availability, performance and response time. In addition, the contract must contain clauses allowing the financial entity to continuously monitor ICT-related risks, including periodic reports on security status and incidents.
Contracts must establish mechanisms ensuring that the financial entity can access, recover and restore its data in the event of the provider’s insolvency, resolution or operational disruption. This guarantees that critical information is not lost and that the entity can maintain business continuity even if the provider fails.
Providers must guarantee the accessibility, availability, integrity, security and protection of the personal data processed under the contract, complying with applicable data protection regulations. They must also be obligated to cooperate fully with the competent authorities and with the financial entity’s resolution authorities in the event of security incidents or investigations.
Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.
Related tool, free to use: the financial regulation tools.

