What a DORA contract addendum actually commits you to
The document arrives from procurement with a two-week deadline and a sentence explaining that it is required by regulation and therefore not negotiable. Half of that is true. This guide separates the parts of a DORA addendum that are fixed by law from the parts your counterparty simply drafted, and puts them in the order a supplier should argue them.
Why an addendum and not a new contract
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, applied from 17 January 2025. It did not invalidate the ICT contracts financial entities already held; it told them what those contracts have to contain. Recital 69 says the quiet part out loud: “When renegotiating contractual arrangements to seek alignment with the requirements of this Regulation, financial entities and ICT third-party service providers should ensure the coverage of the key contractual provisions as provided for in this Regulation.”
So instead of retendering, banks bolt the required elements onto existing paper. That is why the document is called an addendum, why it reads as a list rather than an agreement, and why it often contradicts terms elsewhere in your master services agreement. It was written to satisfy a checklist held by someone in the customer’s ICT third-party risk function, and it was probably sent to several hundred suppliers with the same wording.
It follows that the addendum is not a considered assessment of your service. Reading it as if it were, and conceding every clause because “DORA requires it”, is the most common and most expensive mistake a supplier makes at this stage.
The two clause sets, and why the distinction is the whole game
Article 30 has two operative paragraphs. Paragraph 2 lists nine elements that “the contractual arrangements on the use of ICT services shall include at least”. Paragraph 3 lists six more, and its opening words limit them: “The contractual arrangements on the use of ICT services supporting critical or important functions shall include, in addition to the elements referred to in paragraph 2, at least the following”.
Paragraph 3 is cumulative. A contract for a critical or important function carries fifteen mandatory elements; a contract that does not, carries nine. The nine are largely descriptive: say what you do, where you do it, what your service levels are, what happens to the data if you go under. The six are structural: quantitative performance targets, material-change notification, tested contingency plans, participation in a threat-led penetration test, unrestricted access and audit rights, and an exit strategy with a mandatory transition period you must keep serving through.
| Reference | Element | Applies to |
|---|---|---|
| Art. 30(2)(a) | Complete description of the services, and whether subcontracting is permitted | Every ICT contract |
| Art. 30(2)(b) | Regions and countries of provision, processing and storage, plus advance notice of change | Every ICT contract |
| Art. 30(2)(c) | Availability, authenticity, integrity and confidentiality of data | Every ICT contract |
| Art. 30(2)(d) | Access, recovery and return of data on insolvency, resolution, discontinuation or termination | Every ICT contract |
| Art. 30(2)(e) | Service level descriptions, including updates and revisions | Every ICT contract |
| Art. 30(2)(f) | Incident assistance at no additional cost, or at a cost determined ex ante | Every ICT contract |
| Art. 30(2)(g) | Full cooperation with competent and resolution authorities | Every ICT contract |
| Art. 30(2)(h) | Termination rights and minimum notice periods | Every ICT contract |
| Art. 30(2)(i) | Conditions for participating in the entity’s awareness and resilience training | Every ICT contract |
| Art. 30(3)(a) | Full service levels with precise quantitative and qualitative targets | Critical or important only |
| Art. 30(3)(b) | Notice periods and reporting of material developments | Critical or important only |
| Art. 30(3)(c) | Implemented and tested business contingency plans, security fitted to the entity’s framework | Critical or important only |
| Art. 30(3)(d) | Participation and full cooperation in the entity’s TLPT | Critical or important only |
| Art. 30(3)(e) | Unrestricted rights of access, inspection and audit | Critical or important only |
| Art. 30(3)(f) | Exit strategy with a mandatory adequate transition period | Critical or important only |
The first question to ask, before anything else
Ask your customer, in writing, whether it has assessed the contract as covering ICT services supporting a critical or important function. It is not an awkward question. Article 28(4)(a) obliges the financial entity to make exactly that assessment before entering the arrangement, so it either has the answer or has skipped a step in its own compliance.
The answer determines which paragraph you are negotiating under, and therefore whether six of the fifteen elements belong in the draft at all. It also tells you something about the commercial relationship: a critical-function classification means the customer cannot easily replace you, which is leverage nobody mentions in a procurement email.
What is genuinely fixed
The existence of each of the fifteen elements is fixed. You cannot strike out the audit clause on a critical-function contract, because your customer would then hold a contract that does not comply with Article 30 and would have to report that to its supervisor. Article 28(1)(a) makes the entity “fully responsible for compliance with, and the discharge of, all obligations under this Regulation”, and no amount of supplier goodwill transfers that risk back.
Three of the elements are more absolute than they look. Article 30(3)(e)(i) states that the effective exercise of the access, inspection and audit rights must not be “impeded or limited by other contractual arrangements or implementation policies”, which pre-empts confidentiality terms and internal security policies you might otherwise rely on. Article 30(2)(g) obliges you to cooperate directly with your customer’s authorities, including people they appoint. And Article 30(1) requires the whole arrangement, service levels included, to be “documented in one written document” available in a downloadable, durable and accessible format, which quietly kills the practice of scattering terms across a portal.
What is genuinely negotiable
Everything about implementation. The Regulation says an element must be addressed; with a handful of exceptions it does not say what the term must contain. That leaves a lot of room, and the room is where a supplier protects its margin.
- Definitions and thresholds. Article 30(3)(b) requires notification of “any development that might have a material impact” on your ability to deliver. Nothing defines material. Define it yourself, in the contract, before someone else defines it during an incident.
- Notice periods. Required to exist, unspecified in length, in both Article 30(2)(h) and Article 30(3)(b).
- The measurement method. Article 30(3)(a) requires precise quantitative and qualitative performance targets. Precise targets need a stated measurement window, a stated exclusion set and a stated source of truth, or you will be measured by whichever dashboard the customer prefers after the fact.
- Ex ante incident pricing. Article 30(2)(f) offers a genuine choice: assistance at no additional cost, or at a cost determined in advance. Suppliers routinely concede the first because they read the clause too quickly. Agree a rate card instead.
- The assurance route. Article 30(3)(e)(ii) permits the parties “to agree on alternative assurance levels if other clients’ rights are affected”. This is the textual basis for a pooled audit programme, a published assurance calendar and shared independent test reports.
- The transition period. Article 30(3)(f) requires a “mandatory adequate transition period”. The Regulation never says what adequate means. Price it as a service with a defined scope of migration support, not as an open obligation.
- Training participation. Article 30(2)(i) requires the contract to state the conditions of participation; Article 13(6) says entities include providers in their training schemes “where appropriate”. Which staff, how often, and whose platform are all yours to negotiate.
Article 30(4), the clause nobody uses
The fourth paragraph of Article 30 is one sentence long: “When negotiating contractual arrangements, financial entities and ICT third-party service providers shall consider the use of standard contractual clauses developed by public authorities for specific services.” It binds both parties to consider them, and it is the politest available way to move a negotiation off your counterparty’s in-house paper and onto a neutral text. Raise it in the first round, not the third.
The subcontracting trap
Article 30(2)(a) requires the contract to indicate “whether subcontracting of an ICT service supporting a critical or important function, or material parts thereof, is permitted and, when that is the case, the conditions applying to such subcontracting”. Many addenda simply prohibit it, which is fatal if your platform runs on a hyperscaler or your support desk is partly outsourced. Get your existing chain listed and permitted at signature. Retrofitting permission later is a change request you will not enjoy.
Delegated Regulation (EU) 2025/532 sets out what the permission looks like. Its Article 4(1) requires the contract to state that you are responsible for the services your subcontractors provide, that you monitor all subcontracted critical-function services, that you specify monitoring and reporting duties in your own subcontracts, that you ensure continuity through the chain if a subcontractor fails, and, at point (j), that the subcontractor grants the financial entity and the authorities the same rights of access, inspection and audit that you granted.
Article 5 of the same regulation adds a control most suppliers miss on first reading. You must inform the financial entity of intended material changes to your subcontracting arrangements “well in time”, and you “shall only implement the material changes … after the financial entity has either approved or not objected to the changes by the end of the notice period”. Changing a hosting region or replacing a downstream provider therefore becomes a scheduled event with a customer veto attached. Article 6 lets the entity terminate if you go ahead anyway.
The ICT third-party service provider shall only implement the material changes to its subcontracting arrangements after the financial entity has either approved or not objected to the changes by the end of the notice period.
What the customer is doing on its side
It helps to know which of the customer’s own obligations are driving the wording. Delegated Regulation (EU) 2024/1773 specifies the policy every financial entity must adopt for contracts covering critical or important functions, and reading it explains most of the odd questions in a supplier questionnaire.
- Article 5 requires an ex ante risk assessment covering operational, legal, ICT, reputational, data-protection, data-availability, data-location, provider-location and concentration risk. That is where the questions about your parent company and your data centre map come from.
- Article 6(1) sets the due-diligence checklist, including, at point (e), whether you consent to arrangements that make on-site audits effectively possible. Refusing audit access is a disqualifier before the contract exists, not a negotiating position inside it.
- Article 8(2) requires the contract to allow the entity to access information, carry out inspections and audits and perform tests, using its own audit, pooled audits and pooled ICT testing including threat-led penetration testing, third-party certifications, or your own audit reports.
- Article 9(2)(a) requires you to provide periodic reports, incident reports, service delivery reports, ICT security reports and business continuity testing reports. Agree the cadence and the format at signature, or you will be producing bespoke documents for every customer.
- Article 10 requires a documented exit plan per arrangement that is “realistic, feasible, based on plausible scenarios and reasonable assumptions” and is periodically reviewed and tested. Your transition obligations are the supplier half of that plan.
A redline order that works
Suppliers waste their leverage by negotiating the addendum top to bottom. Take it in this order instead.
- Get the critical-or-important-function determination in writing. If the answer is no, strike the six paragraph 3 clauses and say which article you are relying on.
- Get your existing subcontracting chain listed and permitted under Article 30(2)(a), with a workable material-change process under Delegated Regulation (EU) 2025/532, Article 5.
- Fix the definition of material impact and every notice period. These are free at signature and expensive later.
- Convert incident assistance to an ex ante rate card under Article 30(2)(f).
- Agree the assurance route: an audit calendar under Article 28(6), pooled audits under Article 30(3)(e)(ii), and which independent test report you will supply each year.
- Price the transition period under Article 30(3)(f) and define what migration support it includes.
- Only then argue about the service-level numbers, which is where everyone starts and where the least regulatory weight sits.
Two of those steps have a testing component. The independent test report your customer will rely on has to cover the systems and key controls it identified, not the ones your last scope happened to include, and the contingency plans in Article 30(3)(c) have to be tested rather than written. Both are easier to agree at signature than to retrofit in the first assurance cycle.
Once the addendum is signed, read the guide to audit rights and evidence for what the assurance cycle then looks like, and, if the answer to step one was yes, the guide to TLPT participation for the twelve weeks you have just agreed to.
Sources
- Regulation (EU) 2022/2554 (DORA), Articles 28 and 30 and recital 69
- Commission Delegated Regulation (EU) 2024/1773 on the policy for contractual arrangements covering critical or important functions
- Commission Delegated Regulation (EU) 2025/532 on subcontracting ICT services supporting critical or important functions