DORA
DORA Chapter V: ICT Third-Party Risk Management

DORA DORA-Art.30: Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • CA-3 Information Exchange
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-8 Notification Agreements (SR-8)

FedRAMP Moderate · 7 controls

  • CA-3 Information Exchange
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-8 Notification Agreements (SR-8)

C5 (Germany) · 6 controls

  • C5-COM-02 Policy for planning and conducting audits
  • C5-DEV-02 Outsourcing of the development
  • C5-PI-02 Contractual agreements for the provision of data
  • C5-PSS-12 Locations of Data Processing and Storage
  • C5-SSO-04 Monitoring of compliance with requirements
  • C5-SSO-05 Exit strategy for the receipt of benefits

NIST SP 800-161 Rev 1 · 5 controls

  • CPS230-45 APRA Access Provisions in Formal Agreements
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-50 Formal Agreement Content for Material Arrangements
  • CPS230-P48 Required Content of the Service Provider Management Policy
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures

CIS Controls v8 · 2 controls

  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.7 Securely Decommission Service Providers

ISO 27001:2022 · 2 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.23 Information security for use of cloud services

ISO 27002:2022 · 2 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.23 Information security for use of cloud services
  • CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective

EU AI Act · 1 control

  • PSD2-Art.19_20 Use of agents and outsourcing rules (PSD2 Articles 19 and 20)

GDPR · 1 control

NIS2 Directive · 1 control

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter V: ICT Third-Party Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.30 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.