Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DORA subcontracting and the 2025 RTS

DORA Subcontracting: A Clear Guide to the 2025 RTS

DORA subcontracting stopped being a matter of judgement in 2025. Commission Delegated Regulation (EU) 2025/532 — adopted on 24 March 2025 and published in the Official Journal on 2 July 2025 — specifies what a financial entity has to determine and assess when ICT services supporting critical or important functions are subcontracted.

This guide covers what the RTS requires, why the chain rather than the contract is now the unit of analysis, and what has to change in agreements that were signed before it existed.

DORA subcontracting: what a financial entity must assess along the ICT subcontracting chain
The obligation follows the function, not the contract — and it reaches past your direct provider.

What the RTS actually requires

The DORA subcontracting RTS supplements the Regulation on the elements a financial entity must determine and assess when subcontracting ICT services that support critical or important functions. Three groups of obligation matter in practice:

  • Due diligence and risk assessment before subcontracting is permitted. You have to assess the risk introduced by the subcontracting chain — not merely accept the direct provider’s assurance that it manages its own suppliers.
  • Conditions on when subcontracting may happen at all, and the contractual terms between the financial entity and the ICT third-party service provider that give effect to them.
  • Material changes to subcontracting arrangements — the provider has to inform you, and you have to be able to object or exit where the change is unacceptable.

Proportionality runs through it, including how the requirements apply within groups, so a small entity is not held to the same depth of analysis as a systemic one. Proportionality is not an exemption, though: the assessment still has to exist and be evidenced.

DORA subcontracting makes the chain the unit of analysis

The change of frame is the point. Before the RTS, most third-party risk programmes stopped at the direct contract — you assessed your provider, and their suppliers were their problem. Under DORA the question is whether the function is resilient, and a function delivered through four tiers of subcontractor is only as resilient as the weakest tier you cannot see.

Practically, that means three things your register has to carry:

  1. Which functions are critical or important — because the whole regime keys off that determination, and an over-generous list makes the work unmanageable while a stingy one is a finding.
  2. The chain supporting each, to the depth where a failure would actually interrupt the function. Not every fourth-tier supplier matters; the ones in the delivery path do.
  3. Location and concentration. Where the subcontracted services are performed and processed, and whether several apparently independent chains converge on one provider.

That last one is the finding organizations dislike most: two providers, both diversified on paper, both ultimately hosted in the same region of the same hyperscaler. Our guide to ICT concentration risk covers how to test for it.

What DORA subcontracting changes in existing contracts

Most agreements in force predate the DORA subcontracting RTS. The clauses to look for, and add where missing:

  • Notification of intended subcontracting and of material changes to it, with enough lead time for you to assess and object rather than be informed after the fact.
  • A right to object, and a defined consequence if the change proceeds regardless — including termination without penalty where the risk is unacceptable.
  • Flow-down of the material obligations to subcontractors supporting the critical or important function: security, incident notification, audit and access rights, and location constraints.
  • Visibility of the chain — a maintained list of subcontractors in the delivery path, not a one-off annex that ages instantly.
  • Exit provisions that work when the chain fails, not only when the direct provider does. See our guide to the DORA exit strategy.

The practical sequencing problem

Renegotiating a hyperscaler’s standard terms is not realistic for most financial entities, and the RTS does not pretend otherwise. Where you cannot obtain a clause, the honest response is a documented risk acceptance at the right level, with compensating measures — enhanced monitoring, a tested alternative, tighter data placement — rather than a contract summary that implies you have rights you do not have.

How this fits the rest of DORA

Subcontracting sits inside the third-party risk pillar alongside three things you are already doing. The register of information is where the chain is recorded and reported. The critical ICT third-party provider regime supervises the largest providers directly, but does not transfer your accountability. And incident reporting obligations run regardless of which tier of the chain caused the disruption — a subcontractor’s outage that makes your function unavailable is your incident to classify and report.

Frequently asked questions

Which regulation sets the DORA subcontracting rules?
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplementing Regulation (EU) 2022/2554.

Does it apply to all subcontracting?
It addresses ICT services supporting critical or important functions. Subcontracting that does not touch those functions is outside its scope, which is why the criticality determination has to be defensible.

How deep into the chain do we have to look?
As deep as the function’s resilience actually depends on. That is a judgement you have to make and document, not a fixed number of tiers.

What if a provider will not accept the clauses?
Assess and document the residual risk, apply compensating measures, and take the acceptance decision at a level with the authority to make it. Recording rights you do not hold is the worse outcome.

Does it apply within a group?
Yes, with proportionality provisions covering how the requirements apply in group structures — intra-group provision is not automatically outside the regime.

Where this leaves you

Treat DORA subcontracting as a chain-mapping exercise rather than a contract review. Fix the critical-or-important determination first, map the delivery path for each of those functions to the depth that resilience actually depends on, and test for convergence between chains you believe are independent. Then close the contractual gaps where you can, document risk acceptances honestly where you cannot, and make sure the register reflects the chain as it is today rather than as it was at signature.

References

More on DORA third-party risk

Contractual clause sets, the register and the assessment templates are in the DORA Compliance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.