Loading…
Loading…
DORA Art. 28–30 set the framework for ICT third-party risk management but delegated the granular subcontracting standards to the ESAs. This Delegated Regulation is the second-batch instrument that operationalises those articles for outsourcing chains.
The core obligations:
1. Subcontracting policy (Art. 2–3): Financial entities must define and maintain a written ICT subcontracting policy covering: which functions may be subcontracted, what approval processes apply, how to assess subcontractor risk, and how concentration is monitored.
2. Due diligence at each tier (Art. 4–6): Before entering or renewing a subcontracting arrangement supporting a critical or important function, the financial entity must assess the subcontractor's financial soundness, operational resilience, security standards, and concentration exposure — mirroring the Art. 28 obligations that apply at the first-tier ICT third-party level.
3. Nth-party chain mapping (Art. 7): Financial entities must obtain information on material sub-sub-contractors (nth-party chain) from their first-tier ICT providers and include these in their ICT risk registers. This directly targets the hyperscaler sub-layer (e.g., AWS subcontracting Oracle database services; system integrators subcontracting hyperscaler compute).
4. Equivalent standards for sub-ICT-providers (Art. 8): Contractual terms with first-tier providers must flow down DORA-equivalent resilience requirements to sub-contractors where the subcontracted service is critical or important. No more hollow contractual chains.
5. Concentration-risk assessment (Art. 9): Explicitly requires financial entities to assess whether the subcontracting arrangement creates or worsens ICT concentration risk — both at entity level and, by implication, at system level (the regulator can aggregate across entities to spot sector-wide dependencies).
6. Information rights and termination (Art. 10–11): Contracts with first-tier ICT providers must include enforceable rights to audit subcontractors and to terminate if subcontracting changes materially increase risk.
| Date | Instrument | Content |
|---|---|---|
| 2022-12-14 | DORA Regulation (EU) 2022/2554 | Framework: Art. 28–30 third-party risk + Art. 31 CTPP |
| 2024-06-25 | First-batch CDRs | ICT risk management, incident classification, TLPT — NOT subcontracting |
| 2025-07-02 | This instrument — CDR (EU) 2025/532 | Subcontracting RTS — binding nth-party chain obligations |
| 2025-11-18 | CTPP designation decision | 19 CTPPs named; JET oversight commences |
The first-batch CDRs (filed as 2024-06-25-eu-dora-cdrs-ict-risk-third-party) covered Art. 25–27 (ICT risk management, incident classification, TLPT) but explicitly did NOT include the Art. 28–30 subcontracting standards — those were reserved for a second batch due to the complexity of nth-party chain governance. CDR 2025/532 closes that gap.
trading venues, payment institutions, e-money institutions) must update their ICT subcontracting policies and contractual frameworks by 22 July 2025 (entry into force = immediate applicability for ongoing arrangements at next review cycle). Concentration-risk registers must now trace to nth parties.
face escalating contractual demands: audit rights, resilience documentation, and flow-down clauses. The compliance cost falls partially on providers whose enterprise contracts will require renegotiation.
Art. 29 ICT concentration obligation. The platform's concentration-risk scoring for FIs must account for nth-party concentration (not just first-tier CTPP exposure) to reflect the full regulatory perimeter now in force.
for failing to implement the subcontracting policy. The CTPP oversight (Art. 31–44) runs in parallel for first-tier named providers.
obligation in practice — i.e., what depth of sub-chain mapping is supervisory expectation vs. best effort?
(EBA Work Programme Q4 2025)?
a single hyperscaler's share of critical EU FI workloads — or is it entity-level only?