Your cloud provider runs on a data centre operator. Your core SaaS depends on a hyperscaler, a security firm and a payments gateway. Somewhere down that chain sits a company you have never heard of. Under DORA, the risk it creates is still yours.
That is the problem the subcontracting rules in Commission Delegated Regulation (EU) 2025/532 were written to solve. They have applied since 22 July 2025. One year later they matter more than ever: subcontractor data is the most common defect in Register of Information submissions, and the ESAs' recent statement on frontier AI points to subcontracting chains as an area supervisors will look at more closely.
Why one article is missing, and why that helps you
Article 30(5) of DORA asked the ESAs to spell out what firms must assess when ICT services supporting critical or important functions are subcontracted. The Commission rejected the first draft in 2025. The reason was the draft's Article 5, which required monitoring across the whole chain. The Commission found that this went beyond the mandate, so it was removed from the final text.
That history tells you where the line goes:
- You must understand the chain: how long it is, who is in it, and where the risk sits.
- You do not have to list the whole chain in the contract, monitor every single link, or collect the contracts between your provider and its subcontractors.
Supervisors have put it this way: know how the tree works as a whole. You do not need to audit every branch.
Two things still trip firms up. First, whether a subcontracted part of a service is "material" is your call, and it must be documented. Second, subcontracting inside the provider's own group follows the same rules as external subcontracting. No discount.
The three pillars
1. Due diligence before you sign. Before you enter or change a contract that allows subcontracting, find out which parts of the service will be subcontracted and to whom. Check that each subcontractor has the people, money, security and controls to deliver. Look at where they deliver from, how long the chain is, and whether any of them link back to a designated CTPP. And ask the exit question: could you still move the service somewhere else? If your vendor form asks "do you use subcontractors, yes or no", it is not enough. You need who, where, what and how critical, per component. This is what a structured questionnaire is for. 2. Contract terms. The contract with your direct provider must make clear that the provider stays fully responsible for the whole service, including the parts it subcontracts. The service must keep running even if a subcontractor fails. And security, continuity and audit requirements must flow down to the subcontractors behind the critical function. If your contract updates in 2024 and 2025 were based on the draft rules, check the clauses against the final text. 3. Changes: notice, objection, exit. When your provider wants to make a material change, for example a new subcontractor or a move to another country, it must notify you within an agreed notice period. The provider can only make the change after you approve it, or after the period runs out without objection. If the change goes beyond your risk tolerance, you object. The contract must also give you the right to terminate in defined cases.The Register of Information connection
The register must include the subcontractors that actually underpin ICT services supporting critical or important functions. Reviews of the 2026 submission cycle show that missing subcontractor data is among the most common errors.
The fix is simple to describe: identify subcontractors once, and let that one process feed three outputs. The due diligence file, the contract schedule, and the register templates. Firms that run these as three separate exercises end up with three different answers to the same question, and that is exactly what validation rules catch.
A 30-day plan
- Week 1: Map. For each critical ICT service, list known subcontractors, where they are, and what they deliver. Gaps become questionnaire items.
- Week 2: Assess. Score chain length, location, concentration and exit options. Document your materiality calls.
- Week 3: Fix contracts. Check notice periods, objection and termination rights, and flow-down clauses against the final text.
- Week 4: Close the loop. Set up the intake for change notices and match your subcontractor map against the register.
How DORA GRC helps
DORA GRC treats subcontractors as first-class objects. Chains are mapped per provider and per service, linked to the functions they support, and flow straight into the register templates. That way the due diligence file, the contract schedule and the register always show the same data. Change notices are logged with tasks and deadlines, and the 360° Intelligence Hub shows concentration across the whole chain, not just your direct providers.
Sources: Commission Delegated Regulation (EU) 2025/532 of 24 March 2025, in force 22 July 2025. ESAs joint final report on the draft RTS, July 2024, and Opinion of 7 March 2025. Regulation (EU) 2022/2554, Articles 4, 28 and 30. ESAs JC statement on frontier AI models, 31 July 2026.