DORA for ICT service providers — when the regulation reaches you through your customers

DORA regulates financial entities. If you sell software or infrastructure to them, it regulates you anyway — through every contract, all at once, usually as an addendum you did not draft.

First hour’s on us. No commitment.

Det här får du

  • A DORA-ready contractual position of your own — a standard addendum you offer, rather than a stack of customer papers you accept
  • A gap analysis of your current terms against what Article 30 actually requires
  • Clarity on the critical-or-important question, which decides how heavy the requirements are for each customer
  • An answer to the audit and access clause that is workable operationally rather than simply refused
  • Negotiation support when a customer’s addendum goes further than the regulation does

Hur det fungerar

  1. Intake, 45 minutes. What you sell, to which kinds of financial customers. Free.
  2. Review, two to three weeks. Your terms against the requirements, and against the addenda you have already received.
  3. The position. Your own DORA addendum, plus a negotiation guide for your commercial team.

Who you’ll work with

Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

Why this lands on you at all

DORA applies directly to financial entities — banks, insurers, investment firms, payment and e-money institutions, fund managers, crypto-asset service providers. It does not apply to their suppliers, with one exception: providers designated as critical ICT third-party providers come under direct EU oversight. That designation covers a small number of very large providers.

Everyone else is reached contractually. Article 30 requires financial entities to have specific terms in every ICT contract, with a longer list where the service supports a critical or important function. They cannot waive those terms. So they arrive in your inbox.

The practical consequence is that a supplier with fifty financial customers receives fifty versions of the same requirement, each drafted differently, each needing separate review. That is the problem worth solving once.

What your customers are obliged to obtain

For any ICT contract: a clear description of the services and functions, the locations where services are provided and data is processed, provisions on availability and data protection, notice periods and reporting obligations, and termination rights.

For services supporting critical or important functions, additionally: full service level descriptions with precise quantitative targets, notification and assistance obligations at no additional cost when an incident affects the service, cooperation with the entity’s own authorities, unrestricted rights of access, inspection and audit for the entity, its appointed third parties and its competent authority, exit strategies with a transition period, and conditions on subcontracting of the critical function.

These are not negotiable in substance for your customer. What is negotiable is how they are implemented — and that is where the commercial value sits.

The audit clause, and how to answer it well

The provision that causes the most friction is the unrestricted right of access, inspection and audit. Suppliers hear “any customer can walk into our data centre at any time” and refuse.

The better answer is structured rather than defensive: pooled audits where several customers examine together, third-party assurance reports and certifications that satisfy most of the enquiry, defined notice periods and scope, a documented process for supervisory access, and a genuine on-site right reserved for defined circumstances. That satisfies the requirement and is operationally survivable. A flat refusal simply loses the deal — or worse, gets signed and then breached.

The commercial case for getting ahead of this

A supplier who arrives at procurement with a DORA addendum already drafted, a subcontractor register maintained, and an assurance package ready is not just compliant-adjacent. They are easier to buy from, and their sales cycles are shorter.

The alternative is negotiating each set of terms under time pressure at the end of a deal, with legal review as the bottleneck, and accepting drafting that goes beyond what the regulation requires because no one has time to argue.

Vanliga frågor

Are we regulated under DORA?

Almost certainly not directly. Direct oversight applies to designated critical ICT third-party providers, which is a small group. Everything else reaches you through your customer contracts.

A customer sent an addendum that goes beyond the regulation. Do we have to accept it?

No. Some addenda are drafted conservatively and ask for more than Article 30 requires. Knowing which parts are mandatory and which are the customer’s own preference is exactly what makes the negotiation possible.

What is a critical or important function, and who decides?

Your customer decides, and documents the reasoning. It matters to you because it determines which of the heavier requirements apply to your contract. It is worth asking early rather than discovering it in a redline.

Do we need to give our subcontractor chain?

Your customers need it for their register of information, and DORA constrains subcontracting of critical functions. Maintaining that register on your side is far less work than assembling it repeatedly under deadline.

We also sell outside financial services. Does this change our standard terms for everyone?

Not necessarily. Most suppliers keep a base agreement and a financial-sector addendum. That is usually cleaner than pushing DORA terms onto customers who do not need them.

Where to start

With the addenda you have already received. They tell us what your market is asking for, and the first conversation about them is free.

Related