The hosting provider under your product is a subcontractor in the sense of DORA, and if your product supports a critical or important function of a bank, an insurer or a payment institution, your customer had to decide whether to allow that subcontracting before it signed, on conditions the European Supervisory Authorities drafted and the Commission adopted as Delegated Regulation (EU) 2025/532 of 24 March 2025, published on 2 July 2025 and in force since 22 July 2025. It is the third of the delegated acts under Regulation (EU) 2022/2554 that reach a vendor through the contract, made under Article 30(5), and it is short: seven articles. This article reads them from the Official Journal on CELLAR on 12 September 2026, from the vendor's side. It is not legal advice.

What counts as subcontracting, and which subcontractors matter

Point (a) of Article 30(2) of DORA makes every ICT service contract say whether subcontracting of a service supporting a critical or important function is permitted and under which conditions. The Delegated Regulation fills in "which conditions". Its first recital names the problem: the provision of ICT services often depends on a complex chain of subcontractors, and the customer's ability to obtain information from those subcontractors is limited. Its second recital narrows the field: among the subcontractors of a service supporting a critical or important function, the customer focuses on those that effectively underpin it, including every subcontractor whose disruption would impair the security or continuity of the service, as laid down in the register of information. Recital 5 adds that intra-group subcontractors count, and the operative articles speak throughout of services that support critical or important functions "or material parts thereof".

For a SaaS vendor the chain is usually short and the underpinning obvious: the cloud provider the product runs on, the provider of the database or the object storage if it is not the same company, the email or SMS gateway an authentication step depends on, a managed security operations centre. A payment gateway or a data feed that the product merely calls is a harder question, and the customer answers it, not the vendor; the register of information records the chain by rank, the vendor at rank 1 and each subcontractor below it with its own identifier, and template B_05.02 is where the answer ends up.

The ten conditions your customer assesses before signing, Article 3

Article 3(1) has the customer decide, before entering into the contract, whether you may subcontract a service supporting a critical or important function, and enter into it only if it has assessed that all of the following are met. Four are about you: (a) its due diligence on you shows that you are able to select and assess the operational and financial abilities of potential subcontractors, including by taking part, when it requires, in its digital operational resilience testing; (b) you are able to identify all subcontractors providing such services, to notify and inform the customer of them, and to provide all the information it needs for this assessment; (c) you ensure that your contracts with those subcontractors enable the customer to comply with its own obligations under DORA and applicable Union and national law; (e) you yourself have sufficient ability, expertise and adequate financial, human and technical resources to monitor the ICT risks at the level of your subcontractors, including by applying appropriate information security standards, an organisational structure, risk management and internal controls, and incident reporting and response.

One is about your subcontractor: (d) it grants the customer and the competent and resolution authorities the same contractual rights of access and inspection as you grant. Five are the customer's own homework, but written against your facts: (f) its own resources to monitor the subcontracted service; (g) the impact on its resilience and financial soundness of a possible failure of the subcontractor; (h) the risks of the subcontractor's location; (i) its ICT concentration risk under Article 29 of DORA; (j) whether anything obstructs the audit, inspection and access rights of the authorities or the customer. Article 3(2) makes the customer repeat points (f) to (j) periodically against changes in its business environment, including ICT threats, concentration and geopolitical risks, and Article 3(3) says that relying on your own risk assessment of your subcontractors does not limit the customer's final responsibility. Article 1 lists the elements that scale all of this to the customer's size and risk profile, among them the type of service you subcontract, the location of the subcontractor or of its parent, the length and complexity of the chain, the nature of the data shared with it, whether it is in a member state or a third country, whether it is supervised, whether the provision is concentrated on one subcontractor, and whether the subcontracting would affect the transferability of the service to another provider.

The twelve terms the contract then carries, Article 4

Article 4(1) says the contract identifies which services supporting critical or important functions are eligible for subcontracting and under which conditions, and specifies: (a) that you are responsible for the services provided by the subcontractors; (b) that you must monitor all subcontracted services of that kind so that your obligations to the customer are continuously met; (c) your monitoring and reporting obligations to the customer regarding those subcontractors; (d) that you assess all risks associated with the location of current or potential subcontractors and of their parent company, and with the location the service is provided from; (e) the location of data processed or stored by the subcontractor, where relevant; (f) that you specify, in your contract with each subcontractor, its monitoring and reporting obligations towards you and, where agreed, towards the customer; (g) that you ensure the continuity of the service throughout the chain if a subcontractor fails to meet its obligations; (h) that your contract with the subcontractor contains the business contingency plan requirements of Article 30(3), point (c), of DORA and the service levels the subcontractor must meet in relation to those plans; (i) that it specifies the ICT security standards and any additional security requirements of the same point (c); (j) that the subcontractor grants the customer and the authorities the same rights of access, inspection and audit as Article 30(3), point (e), of DORA; (k) that you notify the customer of any material change to subcontracting arrangements; (l) that the customer may terminate when the conditions of Article 6 of the Delegated Regulation or of Article 28(7) of DORA are met.

Article 4(2) adds the transition rule: changes to existing contracts made necessary by the Delegated Regulation are implemented in a timely manner and as soon as possible, and the customer documents the planned timeline. That is why the addendum arrived after 22 July 2025 rather than with the original contract.

The notice period before you change a subcontractor, Article 5

Article 5 is the operational clause. The contract provides that you inform the customer of any intended material change to your subcontracting arrangements well in time for it to assess the impact on its risks and on your ability to meet your obligations; the contract contains a reasonable notice period by which the customer approves or objects; you implement the change only after the customer has approved it or has not objected by the end of the period; and where the customer thinks the change exceeds its risk tolerance, it informs you before the end of the period, objects, and asks for modifications before implementation. A migration from one cloud region or provider to another, a new managed-security subcontractor, or a change in where the subcontractor processes data is a material change on that reading, and point (b) of Article 30(2) of DORA already made a change of location a notice event on its own.

Article 6 lists the three cases in which the customer may provide that the contract terminates: you implemented a material change it objected to and asked to modify; you implemented a material change before the end of the notice period without approval; or you subcontracted a service supporting a critical or important function that the contract did not explicitly permit you to subcontract. Article 28(7) of DORA adds the general grounds, among them a significant breach and evidenced weaknesses in your ICT risk management.

What an ISO 27001 system already holds

The Delegated Regulation names no standard; point (e) of Article 3(1) asks for "appropriate information security standards" at the level of your subcontractors, and what follows is StandardOS's reading of where an ISO/IEC 27001:2022 system already holds the evidence, with no presumption of conformity. Of the vendor's four conditions, (b) is a supplier register with the subcontractors identified and their services described (Annex A controls A.5.19 to A.5.21), (c) and (e) are the supplier agreements and the monitoring of supplier services (A.5.20, A.5.22), and (a) is the selection record behind the register. Of the twelve terms, (b), (c) and (f) are the same monitoring record; (d) and (e) are the locations you already hold for the register's storage and processing columns; (g) and (h) are the continuity plan and its tests (A.5.29, A.5.30) extended to the subcontractor's service levels; (i) is the Statement of Applicability handed down the chain; (j) is the audit clause; (k) is the change management record (A.8.32). None of that satisfies the Delegated Regulation by itself; it is the evidence the customer's assessment under Article 3 asks to see.

What to do before the customer asks

Write the list of subcontractors that underpin each product, with rank, identifier and location, and keep it in the register data sheet. Put the twelve terms of Article 4(1) into your own subcontractor contracts where they belong, in particular the audit rights of (j) and the contingency requirements of (h), because the customer will check that they flow down. Decide the notice period you can live with for a subcontractor change and write it once, so that every addendum negotiates from your number rather than from the customer's. Then bring the supplier register and the continuity tests to the due diligence. The Article 30 clause checklist covers the clauses the subcontracting terms hang from, and the DORA hub holds the dates of the Regulation and its acts.