Skip to main content
Contract adjustments under DORA
Back to all Insights

Insights · IT security

Contract adjustments under DORA: what financial undertakings need to consider now

Published
8 July 2025
Reading time
5 min read

Share this article

With the introduction of the Digital Operational Resilience Act (DORA), financial undertakings are required to improve their digital and operational resilience comprehensively. While many companies are already implementing technical measures, a crucial aspect often recedes into the background: contractual adaptation to the new regulatory requirements. DORA covers not only financial undertakings, but also their external ICT service providers that supply critical IT services. These companies must ensure that their contracts with third-party providers meet the new requirements.

Which companies are affected?

The DORA regulation extends to a broad spectrum of actors in the financial sector. In addition to banks and insurers, payment service providers, investment firms, crypto-asset service providers and rating agencies are also required to strengthen their ICT resilience. Particularly affected are companies that obtain ICT services from third-party providers, for example cloud services or cybersecurity solutions. Because external providers can pose a potential security risk, DORA places particular emphasis on clear and secure contractual structures.

DORA and NIS-2: a complementary regulation

DORA can be understood as a complement to the Directive on the security of network and information systems (NIS-2). While NIS-2 focuses on the general cybersecurity of critical infrastructure and covers a broad range of sectors, DORA specifically addresses the IT security requirements of the financial sector. Financial undertakings should therefore ensure that their contractual arrangements take into account both the requirements of DORA and those of NIS-2, in order to ensure holistic digital resilience.

Central contractual elements under DORA

A decisive element of the DORA requirements is precisely formulated contract clauses between financial undertakings and their IT service providers. The regulation provides that companies adapt existing contracts and design new agreements so that they are compliant from the outset.

The following points are particularly relevant here:

  1. Responsibilities and liability
    Contracts must clearly define what responsibility the IT service provider bears. Particularly in the event of cyber attacks or IT outages, it must be regulated who is liable for damage and what measures are taken to reduce risk.
  2. Notification duties and incident management
    DORA requires IT service providers to report serious incidents without delay to the financial undertaking and, where applicable, to the competent authorities. Contracts must regulate this clearly in order to avoid legal uncertainty.
  3. Audit and inspection rights
    Financial undertakings must reserve the right to audit IT service providers regularly. This includes on-site inspections as well as external security audits.
  4. Subcontractors and chain contracts
    Many IT service providers work with subcontractors. DORA requires that the responsibilities and duties of these subcontractors are also clearly regulated. In particular, a critical dependence must not arise without the financial undertaking being aware of it and consenting.
  5. Termination and exit strategies
    If a contract ends or is terminated, companies must ensure that the switch to another provider proceeds smoothly and that no security gaps arise. Data migration, deletion concepts and transitional periods are to be specified here.

Challenges in implementing the contracts

Adapting existing contracts to DORA is not trivial. Many companies face the challenge of reviewing and adapting hundreds or even thousands of contracts. In addition, coordination with the IT service providers often requires lengthy negotiations. To make this process easier, companies can draw on modern document generators. These tools help to adapt contract templates to new regulatory requirements quickly and efficiently, thereby significantly reducing the effort of manual processing. Existing contracts can be analysed automatically and transferred into standardised, DORA-compliant templates. It is advisable here to develop standardised contract templates that comply with the DORA requirements and make future adjustments easier.

What financial undertakings should do now

Implementing the DORA requirements calls for a structured and strategic approach. Financial undertakings should therefore develop a systematic roadmap that takes all relevant processes, contracts and responsibilities into account.

  • Comprehensive inventory of all relevant contracts:
    Companies should analyse all existing contracts with ICT service providers to determine which agreements need to be revised or renegotiated. Structured contract management helps to identify gaps or outdated clauses.
  • Development of standardised contract clauses:
    Uniform templates and standard contracts ensure that new agreements comply with the DORA requirements from the outset. These should in particular contain provisions on security standards, liability, audit duties and notification processes.
  • Active negotiation with IT service providers:
    Close cooperation with external providers is necessary in order to implement the new requirements efficiently. Clear expectations as to security measures, audit procedures and emergency plans should be communicated in the process.
  • Targeted training of internal teams:
    Staff in the IT, legal and compliance functions must be made familiar with the new requirements. Regular training and workshops help to put regulatory provisions into practice and to define responsibilities clearly.
  • Regular review of new and existing contracts:
    A one-off adjustment is not enough. Companies should continuously review whether existing contracts are still compliant and make adjustments where necessary. A dynamic monitoring process helps to ensure long-term compliance.

How can companies adapt their contracts efficiently and thereby minimise risks?

The requirements of DORA go far beyond technical protective measures. Clear and precise contract drafting is decisive in order to minimise legal and operational risks. Implementing these adjustments, however, requires considerable resources and can for many companies be a time-consuming challenge.

By using legal tech and external experts, contract reviews and adjustments can be designed efficiently and regulatory requirements implemented more quickly. Companies that act at an early stage not only avoid regulatory sanctions, but also secure a stronger position in contract negotiations with IT service providers.

We support companies in adapting contracts efficiently. In doing so we can review your existing contracts, develop wording proposals or negotiate contracts on your behalf – entirely as you need. We also stand by you in implementing legal tech solutions so that you meet the DORA requirements optimally. A solid contractual foundation creates transparency, reduces risks and ensures that financial undertakings can also strengthen their digital resilience in the long term.

Find out more

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email