Most financial entities ran their big contract remediation in 2024 and early 2025, often against draft technical standards and template addenda from law firms. Then the final rules landed, the subcontracting RTS took effect, and supervisors moved from asking whether you remediated to reading what the clauses actually say.
That makes Article 30 worth a second pass. It is the article that decides what every ICT contract must contain, and it works in two tiers: a base layer for all ICT services, and a stricter layer for services supporting critical or important functions. Here is the full checklist.
Tier 1: Every ICT contract, Article 30(2)
These provisions apply to contracts for all ICT services, however small the service is.
- A clear and complete description of all functions and services. Vague scope descriptions fail this on day one.
- Locations. The regions or countries where the services are provided and where data is processed and stored, plus an obligation on the provider to notify you before changing them. This clause is what makes a quiet migration to another jurisdiction a contractual event instead of a surprise.
- Data protections. Provisions ensuring availability, authenticity, integrity and confidentiality of data, including personal data.
- Data access on the way out. Access, recovery and return of your data in an easily accessible format if the provider becomes insolvent, is resolved, discontinues operations, or the contract ends. This is the clause people discover too late.
- Service level descriptions, including how updates and revisions are handled.
- Incident assistance. The provider must assist when an ICT incident relates to their service, either at no additional cost or at a cost fixed in advance. Negotiate that number now, not during the incident.
- Cooperation with authorities. Full cooperation with your competent and resolution authorities.
- Termination rights and minimum notice periods, in line with what supervisors expect. DORA also defines when you must be able to terminate, including significant breach, weaknesses in the provider's ICT risk management, and circumstances that impair the supervisor's ability to supervise you.
- Training participation. Conditions for the provider's participation in your security awareness programmes and resilience training where relevant.
Tier 2: Critical or important functions, Article 30(3)
If the service supports a critical or important function, everything above applies plus a stricter layer.
- Full service levels with numbers. Precise quantitative and qualitative performance targets, so you can monitor and act without delay when they slip. "Best effort" is not a service level.
- Provider notice and reporting duties, including developments that may affect their ability to deliver against the agreed levels.
- Contingency obligations. The provider must implement and test business contingency plans and maintain ICT security measures and policies appropriate to your regulatory environment.
- TLPT participation. The provider must participate and fully cooperate in your threat-led penetration testing.
- Audit and access rights. Unrestricted rights of access, inspection and audit, including on-site, with agreed details on scope, procedures and frequency, and an obligation on the provider to cooperate fully. Where audits affect other clients, alternative assurance levels can be agreed, but the right itself is not optional.
- Exit support. A mandatory transition period during which the provider keeps delivering while you migrate to another provider or in-house. This clause is what makes your exit strategy executable instead of aspirational.
- Subcontracting terms. Whether subcontracting of the critical service is permitted and on what conditions, now specified in detail by the subcontracting RTS: due diligence, flow-down of requirements, and your notice-and-objection rights on material changes.
💡 Turn the checklist into an inventory. Take every ICT contract that supports a critical or important function and score it clause by clause against the two tiers above. The result is a gap list with three columns: contract, missing clause, remediation owner. That single spreadsheet answers the supervisor's next contract question, drives your renegotiation queue, and tells you which providers to escalate. Most firms that do this find the gaps cluster in three places: audit rights, transition assistance, and the subcontracting terms written against the 2024 drafts.
The gaps supervisors keep finding
One year into supervision, the pattern is consistent. Addenda that reference draft technical standards rather than the adopted texts. Audit clauses that grant a right in principle but no scope, frequency or on-site access in practice. Incident assistance without a pre-agreed cost, which becomes a negotiation at the worst possible moment. Exit clauses without a defined transition period. And subcontracting sections that predate the RTS, missing the notice period and the objection right entirely.
None of these are hard to fix in a renewal. All of them are uncomfortable to explain in an inspection.
How DORA GRC helps
In DORA GRC, contracts live in the same register as the providers, services and functions they cover, so the Article 30 scope is never a guess: the platform knows which contracts support critical functions and holds them to the stricter tier. The contract review workflow checks agreements against the Article 30 clause set and flags the gaps with owner and deadline, and the results feed the same third-party picture as your Register of Information, vendor assessments and exit plans.
Sources: Regulation (EU) 2022/2554 (DORA), Articles 28 and 30. Commission Delegated Regulation (EU) 2025/532 on subcontracting. ESAs and NCA supervisory communications on ICT third-party risk, 2025 to 2026.