Skip to content
The rules

What the DORA regulation requires of your provider's providers

The register of information under the DORA regulation tells you who your providers are. Since the summer of 2025 knowing is not enough, because an answer from your provider does not move the responsibility for what sits underneath.

Andreas Olsson8 min read

A data centre hall built as two tiers of server racks, where the upper tier stands in grey and the tier beneath it glows in gold.

Key insights


  • The DORA regulation has applied since 17 January 2025. The rules governing what happens when your provider in turn engages someone else have applied since 22 July 2025.
  • The contract must state whether the provider may subcontract a service supporting a critical or important function, or material parts of it, and on what conditions. That follows from Article 30(2)(a).
  • On a material change in the subcontracting chain the contract must give a reasonable notice period to approve or object, and the change may only be implemented after that.
  • In November 2025 the ESAs designated nineteen ICT providers as critical. Competent authorities may as a last resort require a financial entity to stop using such a service.
  • Relying on your provider's own risk assessment of its subcontractors does not, under the rules, limit the financial entity's final responsibility.

The register of information under the DORA regulation tells you who your providers are, and that question is answered. The harder question comes immediately after it: what applies to the ones your provider in turn engages?

The DORA regulation, Regulation (EU) 2022/2554, is Union law and applies directly in every member state. It has applied since 17 January 2025. But the layer that decides how far your responsibility reaches got its own rules only in the summer of 2025, and they have applied for a little over a year.

The contract requirement in the DORA regulation, and the rule that followed

The starting point is the regulation's own Article 30(2)(a). Contractual arrangements on the use of ICT services shall include at least a clear and complete description of all functions and ICT services to be provided by the provider, indicating whether subcontracting of an ICT service supporting a critical or important function, or material parts thereof, is permitted and, when that is the case, the conditions applying to it.

That is a contract term, not a rule of conduct. What the financial entity actually has to assess and require is specified in Commission Delegated Regulation (EU) 2025/532, adopted on 24 March 2025, published in the Official Journal on 2 July and applicable since 22 July 2025.

The sequence that produced the current position

  1. The DORA regulation begins to apply
  2. The subcontracting rules begin to apply
    Delegated Regulation (EU) 2025/532.
  3. First list of critical ICT providers
  4. First report on major ICT-related incidents

Source: Delegated Regulation (EU) 2025/532, the ESAs' designation of 18 November 2025 and their first incident report of 3 June 2026

The rules list what the entity has to weigh before the arrangement is entered into, scaled to its size, risk profile and complexity. Among the items are the length and complexity of the subcontracting chain, the kind of data that is shared, where the service is delivered and where it is processed and stored, the provider's authorisation and supervisory status, whether an authority in a third country supervises it, concentration on one or a few subcontractors, and what a disruption would mean for continuity.

The assessment also has to be redone periodically, against changing threats, against concentration risk and against geopolitical developments. That last word is unusual in a technical standard and it is there on purpose.

You may object, and you may terminate

Two provisions move this from documentation to authority.

On a material change in the subcontracting chain the provider has to inform the financial entity well in time for the entity to assess what the change means for the risks it is exposed to and for the provider's ability to meet its contractual obligations. Under Article 5(2) the contract shall contain "a reasonable notice period by which the financial entity is to approve or object to the changes". The change may only be implemented once the entity has approved it or has let the period pass without objecting.

And where the change exceeds the entity's risk tolerance, the entity is to object and request modifications, before the period ends.

The right of termination follows in the next article. The financial entity may terminate the contract when the provider implements a change the entity has objected to, when it implements the change before the notice period has ended, and when it subcontracts services that were not expressly permitted.

The third case is the one that matters most in practice. A provider that swaps out infrastructure underneath you without asking has handed you a ground for termination, whether the swap was good or bad on the merits.

The sentence that makes the chain yours

Here is the provision this whole article rests on, and it is drafted so that it cannot be misread. Article 3(3) of the same delegated regulation, verbatim:

"Reliance on the results of the risk assessment carried out by their ICT third-party service providers on their subcontractors in complying with the obligations set out in this article shall not limit the final responsibility of financial entities to comply with their legal and regulatory obligations under Regulation (EU) 2022/2554."

Relying on the provider's own risk assessment of its subcontractors does not, in other words, limit the financial entity's final responsibility.

An answer from your provider is information, not a transfer of responsibility.

That sentence is what settles the worth of a provider questionnaire. A completed questionnaire from the provider, however thorough, is material for your assessment. It does not replace it and it does not move it. The rules also require the subcontractor to grant the same rights of access, inspection and audit as the provider itself has granted, which is hard to obtain after the fact and easy to write in beforehand.

Nineteen names in the layer below

On 18 November 2025 the three European Supervisory Authorities designated ICT providers as critical for the first time. The list, which the authorities publish under Article 31(9), runs to nineteen names, and anyone reading it recognises them: the cloud platforms, the large systems integrators, the market data houses and the telecoms operators.

The designation is made, according to the authorities' own description, jointly and annually, against criteria set out in a delegated regulation adopted by the Commission. Their oversight guide, published in July 2025, states that six of the criteria are quantitative and five qualitative.

The same guide contains the sentence that makes the designation your question and not only the provider's. As a measure of last resort, competent authorities may require a financial entity to suspend, or even terminate, the use of a service provided by a designated provider. The guide is not legally binding and says so itself, but it describes what supervisors consider themselves able to do.

A financial entity that does not know which of its services rest on one of those nineteen names cannot know what such a decision would mean either.

What supervisors have actually seen

On 3 June 2026 the supervisory authorities published their first report on major ICT-related incidents under DORA. The report gives 3,383 reported major incidents and 0.18 incidents per entity subject to DORA, with around a third having cross-border impact and ten per cent related to cybersecurity.

The report covers the calendar year 2025. Its own methodology section limits the analysis to major incidents that occurred in 2025 and for which a final report was submitted by the cutoff date of 5 February 2026.

The conclusion, by contrast, is in plain language, and it points the same way the rules do: system failures and external events were the main drivers, which according to the authorities underlines the need for robust third-party risk management, effective oversight of outsourced services and close coordination with providers during incident response and remediation.

Two independent things are saying the same thing by different methods. The rules say what the contract has to contain. The measurement says what actually breaks.

The pull against our own conclusion

Here is the objection that carries weight, and it is a fair one.

The subcontracting rules have applied since July 2025. A year is ample time for an organisation with its contracts in order, and anyone who already runs a functioning third-party risk process has probably absorbed the provisions at the ordinary contract review. For them this is not news but a point already closed.

The objection holds as far as saying the requirements are not new. What works against it is where the problem shows up first.

A register that does not pass the quality check does not describe the chain below it either.

In March 2026 Finansinspektionen, the Swedish financial supervisory authority, published a notice of deficiencies in firms' reporting of the register of information, following feedback from the European Banking Authority. The majority of the deficiencies carried two specific error codes, according to the authority, and firms were given deadlines to get the reporting accepted and then corrected.

The register of information is the inventory of the contracts. The subcontracting rules govern the layer below that inventory. Where the first step does not pass a quality check it is hard to maintain that the second is done, and it is that order that makes the objection weaker than it sounds.

The question that decides where you stand

Two organisations can be subject to the same provisions and still have entirely different work ahead of them. The difference can be settled by opening a single contract and reading for three things.

Does it say whether the provider may subcontract the service or material parts of it at all, and on what conditions? If that provision is missing, the contract was written before these rules, and it makes no difference how good the description of the service itself is.

Is there a stated period within which you are to approve or object? A general duty on the provider to inform is not the same thing. Without a period there is no point at which something may or may not be implemented, and therefore no ground for termination to lean on.

Do the rights of access, inspection and audit run all the way down? They rarely apply to the subcontractor automatically, and they are considerably harder to negotiate in once the chain has been built.

If all three are there the work is done, and what remains is keeping the assessment alive against changing threats and concentration. If one of them is missing, contract work lies ahead of you, and that is when the closing sentence of Article 3(3) becomes expensive: the responsibility stays with you in the meantime.

What the DORA regulation and the EU AI Act each require of the same systems is set out on the page for financial services.


Common questions

The DORA regulation is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It has applied since 17 January 2025 and sets requirements for ICT risk management, reporting of ICT-related incidents, testing of digital operational resilience, and the management of ICT third-party risk. It is Union law and applies directly in every member state, with national supervision by the competent authority in each one.

Financial entities across the European Union, and the ICT third-party providers that serve them. The obligations described in this article apply to services supporting critical or important functions. In Sweden the regulation is supplemented by lag (2024:1278) and forordning (2024:1292), both in force since 17 January 2025, and by the regulations of Finansinspektionen, the Swedish financial supervisory authority.

For services supporting critical or important functions the contract must, among other things, state whether subcontracting of the service or material parts of it is permitted and on what conditions, make the provider responsible for the services delivered by its subcontractors, ensure service continuity through the whole chain, extend the same rights of access, inspection and audit down the chain, and provide a right of termination. The requirements are set out in Delegated Regulation (EU) 2025/532.

Yes. Article 30(2)(a) requires the contract to indicate whether subcontracting of an ICT service supporting a critical or important function, or material parts of it, is permitted and on what conditions. Since 22 July 2025 that layer is specified in detail by Commission Delegated Regulation (EU) 2025/532, which sets out what the financial entity has to determine and assess before and during the arrangement.

Before entering the arrangement the financial entity must satisfy itself that the provider is able to identify all subcontractors that provide ICT services supporting critical or important functions, or material parts of them, and to notify the entity of them, and that the subcontractor grants the same rights of access, inspection and audit as the provider itself. Article 3(3) of Delegated Regulation (EU) 2025/532 adds that relying on the provider's own risk assessment does not limit the entity's final responsibility.

On a material change in the subcontracting chain the provider has to give notice well in time for you to assess what the change means. Under Article 5(2) of Delegated Regulation (EU) 2025/532 the contract must contain a reasonable notice period by which you are to approve or object to the change, and the change may only be implemented after approval or after the period has passed without objection.

It gives you a ground for termination. Delegated Regulation (EU) 2025/532 entitles the financial entity to terminate the contract when the provider implements a change the entity has objected to, when it implements the change before the notice period has ended, and when it subcontracts services that the contract does not expressly permit.

It is the inventory of contractual arrangements on the use of ICT services that financial entities have to maintain and report. In Sweden the regulations of Finansinspektionen, FFFS 2024:20, require it to be reported annually by 28 February, covering the position at the end of the previous calendar year. It answers who your providers are, which is the step before the subcontracting rules described here.


If this lands on your desk, we should talk.

Ampliro Insights

New analysis, roughly weekly.

We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.

We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.