Klavius
DORA · Free tool

DORA ICT contract clause checker

Check an ICT third-party contract against the clauses DORA Article 30 requires. Answer for each element, get a coverage view, and take a checklist to your provider or your lawyer.

Answer for each clause DORA Article 30 asks for. Nothing you enter leaves this page.

01A clear, complete description of the ICT services, stating whether subcontracting is allowed and on what conditions.Art. 30(2)(a)
02The regions or countries where the service runs and where your data is processed and stored, with advance notice before any change.Art. 30(2)(b)
03Provisions protecting the availability, authenticity, integrity and confidentiality of data, including personal data.Art. 30(2)(c)
04Rights to access, recover and return your data, in an easily usable format, if the provider fails or the contract ends.Art. 30(2)(d)
05Service level descriptions, kept updated and revised.Art. 30(2)(e)
06The provider's duty to assist you during an ICT incident, at no extra cost or at a cost agreed in advance.Art. 30(2)(f)
07The provider's duty to cooperate fully with your competent authorities and resolution authorities.Art. 30(2)(g)
08Termination rights and minimum notice periods, in line with supervisory expectations.Art. 30(2)(h)
09Conditions for the provider to take part in your ICT security awareness and digital operational resilience training.Art. 30(2)(i)

Not legal advice. This is a self-assessment against the text of Article 30, not a review of your actual contract. Private by design: it runs entirely in your browser, and nothing you enter is sent anywhere.

How this checker works

You answer one question for each element DORA Article 30 requires in a contract for ICT services. The tool groups what you can confirm and what you still need to check, gives each item its article reference, and lets you print a checklist to take to your provider or your lawyer. It runs entirely in your browser, so you can use it on a real contract: nothing you enter is sent anywhere.

Article 30 works in two tiers. Nine clauses belong in every ICT contract. Six more apply when the ICT service supports a critical or important function. Turn on the toggle above to add the second set.

What DORA Article 30 requires

Article 30 sets the minimum content of the written contract between a financial entity and an ICT third-party service provider. The rights and obligations have to be set out clearly, in a single documented contract that includes the service level agreements and stays available in a durable form (Article 30(1)).

In every ICT contract, Article 30(2)

  • A clear and complete description of the functions and ICT services, stating whether subcontracting of a service that supports a critical or important function is allowed and on what conditions (a).
  • The locations, by region or country, where the services are provided and where data is processed and stored, with advance notice before the provider changes them (b).
  • Provisions on the availability, authenticity, integrity and confidentiality of data, including personal data (c).
  • Access to, recovery of and return of your data in an easily accessible format on the provider's insolvency, resolution or wind-down, or on termination (d).
  • Service level descriptions, including updates and revisions (e).
  • Assistance from the provider when an ICT incident occurs, at no additional cost or at a cost set in advance (f).
  • Full cooperation with your competent authorities and resolution authorities (g).
  • Termination rights and minimum notice periods, in line with the expectations of the authorities (h).
  • Conditions for the provider to take part in your ICT security awareness programmes and digital operational resilience training (i).

Additional clauses for critical or important functions, Article 30(3)

  • Full service level descriptions with precise quantitative and qualitative performance targets, so you can monitor them and require corrective action without undue delay (a).
  • Notice periods and reporting obligations, including notice of any development that could materially affect the service (b).
  • Requirements to implement and test business contingency plans and to keep appropriate ICT security measures, tools and policies (c).
  • Participation and full cooperation in your threat-led penetration testing, as referred to in Articles 26 and 27 (d).
  • The right to monitor performance on an ongoing basis, with unrestricted rights of access, inspection and audit for you or an appointed third party and for the competent authority (e).
  • An exit strategy, in particular a mandatory adequate transition period during which the provider keeps delivering the service while you migrate to another provider or bring it in-house (f).

Article 30(4) also asks both parties to consider using the standard contractual clauses that public authorities develop for particular services.

The clauses firms most often miss

Four recur when a contract is checked against Article 30.

  • Subcontracting conditions. The description clause in Article 30(2)(a) has to say whether subcontracting of a critical or important service is allowed and on what conditions, not only what the service is.
  • The training clause. Article 30(2) has nine points, not eight. The ninth, point (i), on the provider taking part in your security awareness and resilience training, is the one most checklists drop.
  • Audit and access rights. For critical or important functions, access, inspection and audit rights have to be unrestricted, and the same rights extend to your competent authority.
  • The exit strategy. An exit clause is not enough on its own. Article 30(3)(f) requires a mandatory transition period long enough to move without disruption.

When do these clauses apply?

DORA has applied since 17 January 2025, and in-scope ICT contracts are expected to carry the Article 30 clauses. A contract that predates the Regulation and does not meet it should be remediated. The Article 30(3) clauses apply where the ICT service supports a critical or important function, which is a separate assessment each entity makes for itself.

Frequently asked questions

Is this checker legal advice?

No. It is a self-assessment against the text of Article 30. It reflects only what you enter and does not read your actual contract. Confirm the result against the Regulation and with your own advisers.

Does DORA apply to my AIFM or ManCo?

DORA applies to a broad set of financial entities, alternative investment fund managers and UCITS management companies included, with a simplified ICT risk management framework for certain smaller entities. Scope is assessed per entity.

What counts as a critical or important function?

A function is critical or important where a disruption would materially impair the entity's financial performance, or the soundness or continuity of its services. It is assessed per entity, and it triggers the additional clauses in Article 30(3).

Do I need to renegotiate existing contracts?

DORA has applied since 17 January 2025, so in-scope contracts are expected to meet Article 30. Contracts that predate it and fall short should be remediated on a risk basis.

Where does the data I enter go?

Nowhere. The checker runs entirely in your browser. It makes no network call, and no analytics event carries your answers.

Sources

Where Klavius fits

The clauses on this page live in one connected record inside Klavius. The ICT third-party register, the contract-clause coverage, the critical or important function assessment and the exit strategies sit together, so a provider that is also a delegate is one file across DORA and Delegate Oversight. Officers review, adjust and sign off; nothing is filed on its own.

See how Klavius handles DORA → ← All tools