DORA Article 30 specifies the minimum contractual provisions that financial entities must include in contracts with ICT third-party service providers. If you sell to banks, payment institutions, or other financial entities, your customers are required to have these provisions in your contract. Companies that are not ready for DORA contract negotiations will face delays, renegotiation demands, and potential lost deals.
This article covers every Article 30 provision and how to handle them.
Why These Clauses Are Now Standard
DORA has been in force since January 2025. Every major bank is auditing their ICT vendor contracts for Article 30 compliance. Contracts that were signed before DORA are being reviewed and renegotiated. New vendor contracts must include these provisions from the outset.
A SaaS vendor that receives a DORA contract addendum from a bank customer and has never seen it before is behind. A vendor with a pre-prepared DORA addendum can turn this from a friction point into a selling point.
The Full Article 30 Checklist
1. Full Description of ICT Services and SLAs
What it requires: A clear, complete description of the services provided, including:
- Specific services covered by the agreement
- Service levels — uptime commitments, response times, processing times
- Update/maintenance windows and advance notice requirements
How to handle it: Your standard order form or service schedule typically covers this. Ensure SLAs are specific and measurable — "best efforts" language will not satisfy DORA requirements.
2. Locations Where ICT Services Are Provided and Data Is Processed
What it requires: The contract must identify:
- Where data centres are located
- Where data is stored and processed
- Any planned changes to data locations (with advance notification obligation)
How to handle it: Add a Data Location Schedule to your standard agreement. Include primary and backup data centre locations, cloud provider regions, and any DR site locations.
3. Full Description of ICT Services Including Sub-Contractors
What it requires: Disclosure of all sub-contractors involved in delivering the service, particularly those that handle the financial entity's data.
How to handle it: Maintain a sub-processor list and make it available to customers. Include an obligation to notify customers before making material changes to sub-contractors.
4. Data Accessibility, Availability, Integrity, and Security
What it requires: Provisions covering:
- The vendor's data protection standards
- Encryption and access control requirements
- Data integrity measures
- Notification if security standards change
How to handle it: Reference your ISO 27001 certification or SOC 2 Type II report. Include a clause confirming minimum security standards and a process for updating security documentation.
5. Provisions Ensuring Accessibility, Availability, Integrity, Confidentiality, and Safety
What it requires: Performance guarantees linked to the financial entity's own operational resilience requirements.
How to handle it: Include uptime SLAs with service credits. Include provisions on maximum allowable downtime for different service tiers.
6. Rights to Full Access, Inspection, and Audit
What it requires: The financial entity (and their supervisory authority) must have the right to:
- Audit the vendor's security practices
- Access security audit reports (SOC 2, ISO 27001, pen test results)
- Conduct on-site inspections with reasonable notice
How to handle it: Include an audit rights clause. Offer a report exchange (provide your SOC 2/ISO 27001 report as an alternative to on-site audit for standard annual reviews). Reserve on-site audit rights for when reports are insufficient or an incident has occurred.
7. Implementation and Testing of Business Continuity Plans
What it requires: The vendor must implement and periodically test a BCP relevant to the services provided. The financial entity should receive evidence of testing.
How to handle it: Include a provision confirming your BCP covers the services and that test results will be made available on request (or summarised annually).
8. Cooperation with Competent Authorities
What it requires: The vendor must cooperate with the financial entity's supervisory authorities when requested.
How to handle it: Include a clause confirming cooperation with regulatory inquiries — this is standard in financial services contracts.
9. Termination Rights and Minimum Notice Periods
What it requires: The financial entity must have the right to terminate for:
- Material breach of the contract
- Major security incident
- Regulator direction
- Financial entity's own insolvency/licence revocation
How to handle it: Include termination-for-cause provisions, including security incidents as a termination trigger. Set minimum notice periods for ordinary termination that allow adequate data migration time.
10. Conditions for Sub-Contracting
What it requires: Rules on when and how sub-contractors can be used, with notification rights for the financial entity.
How to handle it: Include a general authorisation for existing sub-contractors with a notification obligation for changes. Match this to your GDPR sub-processor notification approach.
Building a DORA-Ready Contract
The most efficient approach: create a DORA Contract Addendum that can be attached to your standard terms. The addendum:
- Incorporates all Article 30 provisions
- References your existing security certifications
- Includes the data location schedule
- Covers audit rights and report sharing
Having this ready before customer requests removes friction from enterprise sales cycles.