Last updated: 5 August 2026.
Quick answer. Contracts governed by the DORA Regulation must guarantee the continuity of critical ICT services even in resolution scenarios. Agreements with third-party ICT providers must include exit strategies that minimise the impact of changing provider or of a service interruption: mandatory transitional periods, real flexibility to switch providers according to the complexity of the service, and mechanisms to internalise the service where the entity so decides. For financial entities within the scope of the BRRD Directive (2014/59/EU), contracts must additionally remain valid and enforceable during resolution, with non-termination, non-suspension and non-modification clauses that prevent the provider from interrupting the service while the entity meets its payment obligations, aligned with the expectations of resolution authorities.
Contracts drafted under the framework of the DORA Regulation, beyond establishing the minimum requirements for the digital operational resilience of financial entities, must necessarily address the need to ensure the continuity of critical services, even in resolution scenarios. In this context, exit strategies and contractual resilience acquire particular relevance.
Below, we provide the collaboration in video format should it be of interest to you:
Exit Strategies: A Buffer Against Changes and Contingencies
Contractual agreements with third-party providers of ICT services must include specific exit strategies designed to minimize the impact of a potential change of provider or service interruption. These strategies should encompass:
- Mandatory Transitional Periods: These periods allow the financial entity to manage the transition to a new provider or an internal solution in an orderly manner, minimizing the risk of disruptions to its operations.
- Flexibility to Change Providers: Contractual clauses must enable the financial entity to effectively change providers, considering the complexity of the ICT service in question.
- Adaptation to Internal Solutions: In some cases, the financial entity may opt to internalize certain services. Exit strategies should facilitate this transition.
Contractual Resilience in Resolution Scenarios
For financial entities within the scope of the BRRD Directive (2014/59/EU), contractual resilience takes on an additional dimension. ICT service contracts must be robust enough to withstand a resolution process. This entails:
- Applicability in Case of Resolution: Contracts must remain fully valid and enforceable, even in a resolution scenario.
- Non-Termination, Non-Suspension, and Non-Modification Clauses: These clauses ensure that the ICT service provider cannot interrupt or modify the service due to reasons related to the restructuring or resolution of the financial entity, provided the latter fulfills its payment obligations.
- Alignment with Resolution Authorities’ Expectations: Contractual clauses must be designed to facilitate the intervention of resolution authorities and minimize the impact of such intervention on the continuity of critical services.

Si te ha interesado este artículo no dudes en leer:
DORA: Contract Clauses. Beyond the Basics: Deepening Contractual Requirements for Robust Digital Resilience
Why Are These Provisions Important?
- Continuity of Services: They ensure that critical services remain operational, even in crisis situations, thereby protecting clients’ interests and contributing to the stability of the financial system.
- Protection of the Financial Entity: They minimize the risk of financial and reputational losses associated with ICT service interruptions.
- Facilitation of Resolution: They contribute to a more orderly and efficient resolution process.
In conclusion, the DORA Regulation underscores the importance of exit strategies and contractual resilience in agreements with third-party providers of ICT services. By incorporating these provisions into their contracts, financial entities can strengthen their operational resilience and contribute to the stability of the financial system.
If you enjoyed this article, you may also find the following reading interesting:
DORA: key contractual clauses for access, inspection and audit of ICT providers
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.
Frequently asked questions
They are specific contractual provisions agreed with third-party ICT service providers, designed to minimise the impact of a potential change of provider or a service interruption and to ensure the continuity of the financial entity’s critical services.
Mandatory transitional periods that allow an orderly migration to a new provider or an internal solution, contractual flexibility to change providers effectively considering the complexity of the ICT service in question, and adaptation mechanisms for cases where the financial entity opts to internalise certain services.
For financial entities within the scope of the BRRD Directive (2014/59/EU), ICT service contracts must be robust enough to withstand a resolution process, remaining fully valid and enforceable even in a resolution scenario.
Clauses ensuring that the ICT service provider cannot interrupt or modify the service for reasons related to the restructuring or resolution of the financial entity, provided the latter fulfils its payment obligations.
Because contractual clauses must be designed to facilitate the intervention of resolution authorities and to minimise the impact of such intervention on the continuity of the entity’s critical services.
Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.
Related tool, free to use: the financial regulation tools.

