DORA — Articles 28–30

DORA doesn't regulate you.
Your customers' compliance does.


Every financial-entity customer you have is now obliged to push Article 30 clauses down to you, register you in their Register of Information, and get visibility into your subcontractors.

Eight questions. Ninety seconds. Find out whether you are the reason their onboarding stalls.

How it reaches you

DORA applies directly to financial entities. It reaches you through their contracts. In practice that means Article 30 clauses arriving as non-negotiable addenda, Register of Information data requests in a format you have never produced, and — for services supporting a critical or important function — prior written authorisation before you can change your own subcontractors.

Vendors who have the artefact set ready turn a multi-month vendor review into a multi-week one. Vendors who assemble it per deal lose quarters.

If you hold a payment, e-money or other financial licence yourself, DORA applies to you directly rather than by flow-down. The first question routes you accordingly.

What your customers must obtain

The artefact set


  • Article 30 contractual provisions, in full, for critical functions
  • Register of Information fields they can submit to their supervisor
  • Your subcontracting chain, down to material subcontractors
  • Data locations for processing, storage, support and backup
  • A documented exit and data-return plan
  • Right-to-audit and resilience-testing participation terms

The assessment

Eight questions

Answer as your largest financial-entity customer would answer about you.