VVendorDORAEarly access

Free resource · 9 areas

The DORA Article 30 checklist for ICT vendors

Since 17 January 2025, every EU bank, insurer and fintech must run due diligence on the ICT providers it uses. The questionnaire lands on your desk whether or not you knew the rule existed. These are the nine areas it covers, what to prepare for each, and which evidence closes the answer.

Regulation (EU) 2022/2554 · Art. 28–30 + RTS on ICT risk management · Operational checklist, not legal advice

Your readiness0/9 · 0%

The services a customer actually consumes

Describe the services provided, their type, duration and the contracting entity.

Prepare

  • One row per product or service a financial customer uses
  • Which contract covers it, and which support tier applies
  • The legal entity that signs — not the brand name on the site

Attach

  • Signed order form or MSA
  • One-page service description in plain language

Where data is processed and stored

List every location where customer data is processed, stored or backed up.

Prepare

  • Cloud regions in use, per environment
  • Backup and replica locations, including disaster-recovery sites
  • Any support access that originates from another country

Attach

  • Architecture diagram with data flows
  • Region list with a reason for each location

Access rights, data return and deletion

What can you access, under what controls, and how does data leave at the end?

Prepare

  • Roles that can read customer data, and how access is granted and revoked
  • Export format and the time it realistically takes
  • What is deleted, when, and who confirms it

Attach

  • Data export procedure with a measured duration
  • Deletion attestation template you can sign

Service levels that survive an audit

What is committed, how it is measured, and how it is reported back.

Prepare

  • Uptime figure, measurement window and what is excluded
  • How a customer is told the number was missed
  • Whether the commitment is contractual or best-effort

Attach

  • SLA text as signed
  • Uptime report for the last 12 months
  • Public status page history, if you run one

Incident notification and support

How fast you tell us, who tells the regulator, and how escalation works.

Prepare

  • Severity classes with a one-line definition each
  • Notification window for each class, in hours
  • Named escalation contact and out-of-hours route
  • Who notifies the competent authority — you or the customer

Attach

  • Incident response one-pager
  • Customer notification template
  • Most recent post-mortem, redacted

Audit rights and authority access

Who may audit you, how often, on what notice, and what they may request.

Prepare

  • Your position on on-site audits versus document review
  • Audit frequency you will accept without charging for it
  • The clause that lets the customer's competent authorities access your services

Attach

  • Audit policy and prior audit responses
  • ISO 27001 or SOC 2 scope statement, or an honest gap note

Your own subcontractors

Which ICT providers sit underneath you, and which of them touch our data.

Prepare

  • Every ICT subcontractor, its role and its country
  • Which ones process customer data or keep it available
  • The concentration risk: one provider whose failure breaks your service
  • How you approve changes and how the customer is told

Attach

  • Subcontractor register, updated this quarter
  • Concentration note in two sentences

Register-of-information readiness

The fields your customer's compliance team must file about you.

Prepare

  • Level 1: identity, service classification, locations and criticality for every ICT provider
  • Level 2: extra detail where you support a critical or important function
  • Level 3: your subcontractors behind those critical functions
  • One machine-readable row per customer, kept current

Attach

  • A single spreadsheet your team maintains, not a per-customer fork
  • Legal entity identifiers where you hold them

Continuity and a runnable exit

How fast you recover, when you last proved it, and how we leave.

Prepare

  • Recovery time and recovery point objectives, per service
  • Date and result of the last continuity test
  • An exit plan the customer could actually run without you

Attach

  • Continuity plan summary
  • Last disaster-recovery test report
  • Exit checklist with owners

Where vendors lose time

Three gaps behind almost every slow answer

REWRITTEN

Answers rebuilt per customer

Every institution sends its own format, so the same security answer gets written again from scratch.

UNINDEXED

Evidence nobody can find

The certificate exists, in someone's inbox. Two weeks of asking is what the questionnaire actually costs.

UNMAPPED

A subcontractor chain nobody drew

Examiners ask about the provider behind your provider. Small vendors rarely have that list written down.

Next step

Turn this checklist into answers you reuse

The DORA Vendor Toolkit is the pre-written answer library, register template and evidence index behind these nine areas. Join the list for launch and founding-member pricing — no charge today.

No spam. One launch email, plus early-bird pricing. Unsubscribe anytime.

VendorDORA is an operational toolkit built by engineers. It prepares your answers and evidence; your legal counsel reviews the contractual commitments.