DORA legal services for financial entities and their ICT providers

The Digital Operational Resilience Act has applied since January 2025. We help financial entities and the technology companies serving them get the contracts, the register and the governance into a state that holds up to supervision.

DORA is not primarily a technology problem. The parts that fail supervision are legal: contracts that do not contain the clauses Article 30 requires, a register of information that does not reconcile with the contracts behind it, and a governance chain where nobody can point to who owns ICT risk. Those are the parts we work on.

First hour’s on us. No commitment.

What you get

  • A contract remediation plan — which of your ICT agreements meet the Article 30 requirements, which do not, and what to renegotiate first based on how critical the function is
  • A register of information that reconciles with your actual contracts and entity structure, in the format your supervisor expects
  • Clarity on which arrangements support critical or important functions, which is the classification that drives most of the substantive obligations
  • Incident classification and reporting procedures aligned to the regulatory thresholds and timelines
  • Board-level documentation showing that the management body has taken and can evidence its responsibility

How it works

  1. Intake, 45 minutes. Where you are, what your supervisor has asked for, what worries you. Free.
  2. Review, two to four weeks. Contracts, register, policies and governance, against the requirements as they actually read.
  3. The remediation plan. Prioritised, with drafting support for the contracts that need it.

Who you’ll work with

Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

What DORA requires, in the order it bites

DORA has applied since 17 January 2025 and covers a wide range of financial entities — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, fund managers and more — as well as, indirectly, the ICT providers serving them.

It rests on five pillars: ICT risk management under the responsibility of the management body; incident management, classification and reporting; digital operational resilience testing, including threat-led penetration testing for the entities designated for it; management of ICT third-party risk; and information sharing on cyber threats.

In practice, the third-party pillar is where most of the legal work sits, and where supervisors have asked the most questions.

The contract requirements are specific, and most agreements predate them

Article 30 sets out what every ICT contract must contain, with a longer list for arrangements supporting critical or important functions. Among them: a clear description of the services and the locations where data is processed, service level descriptions with quantitative targets, notification and assistance obligations for incidents, access, inspection and audit rights for the entity and its supervisor, exit strategies and transition periods, and termination rights in defined circumstances.

Standard vendor terms rarely contain these. Hyperscaler terms have improved but often need addenda. The work is to identify which agreements support critical or important functions, since those carry the full list, and to renegotiate in an order that matches actual exposure rather than contract renewal dates.

The register of information

Financial entities must maintain a register of all contractual arrangements for ICT services, and submit it to their competent authority — in Sweden, Finansinspektionen — which passes it on to the European Supervisory Authorities. The register feeds the designation of critical ICT third-party providers, who then come under direct EU oversight.

The register is deceptively hard. It is not one list but a set of linked tables covering entities, arrangements, providers, functions and the chains of subcontracting behind them, using prescribed identifiers. Submissions get rejected for structural reasons far more often than for substantive ones. The most common failure is that the register says one thing and the underlying contract says another — which is a legal problem, not a reporting problem.

If you are the ICT provider rather than the financial entity

DORA does not apply to you directly unless you are designated as a critical provider. But your financial-sector customers must have DORA-compliant terms, which means the requirements arrive through your contracts, all at once, from every client, often as unilateral addenda.

The commercially sensible response is a DORA-ready contractual position of your own — one you have thought through, rather than one negotiated separately with each customer under time pressure. We build these.

Frequently asked questions

Does DORA apply to us?

It applies to a broad list of regulated financial entities in the EU. If you hold a licence from Finansinspektionen or another EU supervisor, start from the assumption that it does and check the scope carefully. Some smaller entities benefit from a simplified framework.

We already comply with the EBA outsourcing guidelines. Is that enough?

It is a good starting position and much of the governance carries over, but it is not equivalent. DORA covers all ICT services rather than outsourcing arrangements only, and the contractual requirements are more prescriptive.

How do we decide what counts as a critical or important function?

It is an assessment of what a disruption would do to your regulatory obligations and to continuity of service. It needs documented reasoning, because it drives which contracts carry the heavier requirements — and it is one of the first things a supervisor asks about.

Our register submission was rejected. Can you help?

Yes. Rejections usually trace back to structure, identifiers or inconsistencies between the register and the contracts. We work through both sides.

Can you help with the contract negotiations themselves?

Yes — drafting, the renegotiation pack and the negotiations with providers, alongside your procurement team.

What does a readiness review cost?

The first conversation is free. After that we scope against your contract volume and entity structure, and you get a fixed price before we start.

Where to start

Whether you are closing gaps or preparing for your first supervisory dialogue, the first step is a clear picture of what is stable and what needs attention.

Related