DORA: dates, tool and articles

Regulation (EU) 2022/2554 · Article 30

The DORA contract clauses, Article 30: nine or fifteen, a status for each

Since 17 January 2025 a financial entity may only contract for ICT services on terms that carry the clauses of Article 30: nine for every service, fifteen where the service supports a critical or important function. One question decides which set; then each clause follows in the Regulation's words with the ISO 27001 records that answer it, a status and a note, and the page writes the checklist. Nothing you type leaves this page.

Does the service support a critical or important function of the customer?

The customer decides under Article 28(4)(a), by Article 3(22): a function whose disruption would materially impair its financial performance, the soundness or continuity of its services, or its continued compliance with its authorisation. A vendor that could be one prepares the fifteen.

Answer the question and the clauses are listed here.

Thirteen of the fifteen clauses ask for a record an ISO 27001 system keeps

StandardOS runs the ISO/IEC 27001 management system whose records answer the due diligence behind the clauses: the supplier register, the backup and restore tests, the incident process, the continuity plan, the internal audit programme, in six languages. This checklist goes in as the first record.

DORA for a software vendor: the clauses, the register, the actsThe ISO 27001 controls, one page each