Banque & financeVérifiée par Kopik: Sources officielles relues et réponses testées par Kopik

DORA Article 30 contracts and ICT subcontracting: mandatory clauses

DORA sets minimum contents for every contract on the use of ICT services, with extra requirements when the service supports critical or important functions. Delegated Regulation (EU) 2025/532 adds rules on subcontracting those services.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

Clauses required in every ICT contract

The contract must be in writing, in one document including the service level agreements. It must describe all functions and services and state whether subcontracting of a service supporting a critical or important function is permitted.

It must also cover: the regions or countries where services are provided and data processed, with advance notice of any change; data protection; access to and return of data if the provider becomes insolvent or stops operating; assistance during ICT incidents at no additional cost or at a cost set ex ante; cooperation with competent and resolution authorities; and termination rights with minimum notice periods.

Extra clauses for critical or important functions

Contracts for services supporting critical or important functions must add full service level descriptions with precise performance targets, business contingency plans, participation in the entity's TLPT, unrestricted rights of access, inspection and audit, and exit strategies with a mandatory transition period.

A microenterprise and its provider may agree to delegate access, inspection and audit rights to an independent third party.

Material changes to subcontracting

The provider must inform the financial entity of intended material changes to its subcontracting well in time for an assessment. The contract must set a reasonable notice period during which the entity approves or objects.

The provider may implement the changes only after approval or once the notice period ends without objection. If the changes exceed its risk tolerance, the entity objects and requests modifications before implementation.

Questions fréquentes

When can the financial entity terminate the contract over subcontracting?

The contract may provide for termination if the provider implements material changes despite an objection, implements them before the end of the notice period without approval, or subcontracts a critical service not explicitly permitted by the contract.

Are standard contractual clauses mandatory?

No, but Article 30(4) requires both parties to consider using standard contractual clauses developed by public authorities for specific services when negotiating.

Must the provider train with our staff?

The contract must set the conditions for the provider's participation in the entity's ICT security awareness programmes and digital operational resilience training, under Article 30(2)(i).

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=eu-dora-ict-resilience
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-eu-dora-ict-resilience": {
      "url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.