Banking & financeVerified by Kopik: Official sources reviewed and answers tested by Kopik

DORA Article 30 contracts and ICT subcontracting: mandatory clauses

DORA sets minimum contents for every contract on the use of ICT services, with extra requirements when the service supports critical or important functions. Delegated Regulation (EU) 2025/532 adds rules on subcontracting those services.

Ask your question

Free account required

Each question stands alone Β· 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

Clauses required in every ICT contract

The contract must be in writing, in one document including the service level agreements. It must describe all functions and services and state whether subcontracting of a service supporting a critical or important function is permitted.

It must also cover: the regions or countries where services are provided and data processed, with advance notice of any change; data protection; access to and return of data if the provider becomes insolvent or stops operating; assistance during ICT incidents at no additional cost or at a cost set ex ante; cooperation with competent and resolution authorities; and termination rights with minimum notice periods.

Extra clauses for critical or important functions

Contracts for services supporting critical or important functions must add full service level descriptions with precise performance targets, business contingency plans, participation in the entity's TLPT, unrestricted rights of access, inspection and audit, and exit strategies with a mandatory transition period.

A microenterprise and its provider may agree to delegate access, inspection and audit rights to an independent third party.

Material changes to subcontracting

The provider must inform the financial entity of intended material changes to its subcontracting well in time for an assessment. The contract must set a reasonable notice period during which the entity approves or objects.

The provider may implement the changes only after approval or once the notice period ends without objection. If the changes exceed its risk tolerance, the entity objects and requests modifications before implementation.

Frequently asked questions

When can the financial entity terminate the contract over subcontracting?

The contract may provide for termination if the provider implements material changes despite an objection, implements them before the end of the notice period without approval, or subcontracts a critical service not explicitly permitted by the contract.

Are standard contractual clauses mandatory?

No, but Article 30(4) requires both parties to consider using standard contractual clauses developed by public authorities for specific services when negotiating.

Must the provider train with our staff?

The contract must set the conditions for the provider's participation in the entity's ICT security awareness programmes and digital operational resilience training, under Article 30(2)(i).

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=eu-dora-ict-resilience
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-eu-dora-ict-resilience": {
      "url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.