Digital Operational Resilience Act

DORA ICT Third-Party Provider Pack

If you sell technology to a bank, insurer or investment firm in the EU, the Digital Operational Resilience Act reaches you — through your customer. They must carry you in their Register of Information in a prescribed format, your contract with them must contain the Articles 28–30 terms.

And if your service is significant enough, they’ll expect you to handle incident notifications and penetration testing on their timetable. Most suppliers discover all of this the day a customer’s compliance team sends the questionnaire. This pack gets you ahead of it.

Built for technology companies — SaaS, cloud, infrastructure, data services — that supply EU financial entities and keep getting pulled into their DORA obligations. Six documents, written entirely from your side of the relationship.

Cyber Resilience Act CRA template pack

Why the supplier side is different

Every DORA product on the market is written for the financial entity. This one is written for the supplier. The obligations that land on you are a specific, narrow slice of DORA — being carried in the register, carrying the right contract terms, disclosing your chain, notifying incidents on your customer’s clock — and reading them out of an entity-facing guide means wading through hundreds of pages of obligations that aren’t yours.

This pack covers exactly your slice, from your point of view, so you can answer the questionnaire with a folder rather than a scramble.

What you get:

Six documents, each an explanatory notice (what the obligation is and why it reaches you) paired with a ready-to-complete template:

  • Criticality Self-Assessment — where you stand against the Article 31 designation criteria, the Article 31(8) carve-outs, and the twelve-month EU-subsidiary requirement for third-country providers. Start here; it tells you what the rest of the pack must cover. Free to download — see below.
  • Register of Information Data Pack — the provider-side fields your customer needs to populate its register, in the prescribed ITS format: your identification and LEI, the contract inputs, the service classification, and the subcontracting chain. Hand this over instead of filling in each customer’s spreadsheet from scratch.
  • Articles 28–30 Contractual Terms Checklist — the DORA clauses your contract must contain, in two tiers (baseline, and the heavier set for critical or important functions), with the access, audit and exit-strategy pinch points flagged.
  • Subcontracting Disclosure Record — the chain behind your service, the material-change notification process, and your customer’s right to object — the single most under-populated part of every register.
  • Incident Notification Procedure — aligned to your customer’s DORA reporting clocks, so when your service has an incident, your customer can still meet its deadline.
  • Threat-Led Penetration Testing Participation Record — how you take part when a customer’s TLPT includes your systems, with multi-tenant safeguards and pooled-testing arrangements.

Who needs these DORA ICT templates

  • SaaS, cloud, infrastructure and data-services companies that supply EU banks, insurers, investment firms or other financial entities.
  • Vendors whose sales cycle keeps stalling on a DORA addendum or a register questionnaire.
  • Third-country (non-EU) providers who need to understand the subsidiary question before it’s urgent.
  • Providers who support what their customers call a “critical or important function” and are being pulled into audit rights and penetration testing.
  • The person at a supplier who owns “our customers’ compliance questionnaires” and wants to stop answering them from a blank page.

One thing this pack makes clear, so you don’t get it wrong

Being designated a critical ICT third-party provider is a determination the European Supervisory Authorities make — not something you declare, and not something that happens to most suppliers.

As of the first official list, only nineteen providers were designated, all hyperscale cloud and core-platform businesses.

For almost every supplier, the valuable output of the self-assessment is a documented, defensible conclusion that you are not critical — together with a clear view of the ordinary register and contract obligations that do apply to you. The pack is built to give you both.

Start with the self-assessment

Download the Criticality Self-Assessment free. Work through it and you’ll know your real exposure, whether designation is even a question for you, and which of the other documents you need before your next customer’s procurement cycle.

Download the free assessment document

What the price covers

€700 includes twelve months of updates as the DORA delegated and implementing acts and ESA guidance develop.

A law firm assembling this from scratch — criticality analysis, register data, the Articles 28–30 clause review, subcontracting and incident procedures — will typically run €6,000–15,000. The pack is the same readiness at a fraction of the cost, and it turns a recurring procurement scramble into a folder you hand over.

What this pack is not (Important)

This is not legal advice, and it’s not a designation or a certification. The criticality self-assessment helps you understand your position under Article 31 — it does not designate you, and only the European Supervisory Authorities can. The contract checklist helps you prepare for the Articles 28–30 terms, but the terms themselves should be settled with counsel.

Every document is a draft to be reviewed against your circumstances and the current text of DORA and its delegated acts before you rely on it.