Free tool · No account needed

DORA Article 30 contract clause checker

Every ICT services contract needs nine clauses. Contracts supporting a critical or important function need six more, and one of those has four separate limbs. Work through a contract here and get back a gap list you can take to the provider — or to your board.

DORA Art. 30 · 9 + 6 clauses · microenterprise derogation · nothing stored

Check a contract

Runs in your browser · nothing uploaded

Answer for one contract at a time. Do not paste contract text anywhere — this tool takes no document, only your assessment of each clause. Mark anything you would have to go and look up as Unsure; those become verification items rather than gaps.

Form of the arrangement

Article 30(1)

Before the clause list, two requirements about the contract itself.

Art. 30(1) Rights and obligations clearly allocated in writing The respective rights and obligations of your firm and the provider are clearly allocated and set out in writing.
Art. 30(1) One written document, including the SLAs The full contract includes the service level agreements and is documented in a single written document, available to both parties on paper or in another downloadable, durable and accessible format. A contract scattered across an order form, a web page and an unversioned PDF does not meet this.

Required in every ICT contract

Article 30(2) · 9 clauses

These apply to every arrangement on the use of ICT services, whatever the function it supports.

Set all in this section:
Art. 30(2)(a) Description of functions and ICT services A clear and complete description of all functions and ICT services to be provided, stating whether subcontracting of an ICT service supporting a critical or important function is permitted and, if so, on what conditions.
Art. 30(2)(b) Locations of provision and data processing The regions or countries where the contracted or subcontracted services are provided and where data is processed, including the storage location, plus a requirement to notify you in advance of any envisaged change.
Art. 30(2)(c) Availability, authenticity, integrity and confidentiality Provisions protecting data, including personal data, across all four properties.
Art. 30(2)(d) Access, recovery and return of data Provisions ensuring access, recovery and return of personal and non-personal data in an easily accessible format on the provider’s insolvency, resolution or discontinuation of business, or on termination of the arrangement.
Art. 30(2)(e) Service level descriptions Service level descriptions, including how they are updated and revised.
Art. 30(2)(f) Incident assistance An obligation to assist you at no additional cost, or at a cost fixed in advance, when an ICT incident related to the service occurs.
Art. 30(2)(g) Cooperation with authorities An obligation to cooperate fully with your competent authorities and resolution authorities, including persons they appoint.
Art. 30(2)(h) Termination rights and notice periods Termination rights and related minimum notice periods, consistent with the expectations of competent and resolution authorities.
Art. 30(2)(i) Participation in security awareness and training The conditions on which the provider participates in your ICT security awareness programmes and digital operational resilience training under Article 13(6).

Additional for critical or important functions

Article 30(3) · 6 clauses

These are required in addition to the nine above, not instead of them.

Set all in this section:
Art. 30(3)(a) Full service levels with performance targets Full service level descriptions with precise quantitative and qualitative performance targets, so you can monitor effectively and take corrective action without undue delay when levels are missed.
Art. 30(3)(b) Notice periods and material-impact reporting Notice periods and reporting obligations, including notification of any development that might materially affect the provider’s ability to deliver at the agreed service levels.
Art. 30(3)(c) Contingency plans and security measures Requirements to implement and test business contingency plans, and to maintain ICT security measures, tools and policies appropriate to your regulatory framework.
Art. 30(3)(d) Participation in threat-led penetration testing An obligation to participate and cooperate fully in your TLPT under Articles 26 and 27.
Art. 30(3)(e) Ongoing monitoring, access, inspection and audit Unrestricted rights of access, inspection and audit by you, an appointed third party and the competent authority, with copies of documentation on-site; the right to agree alternative assurance levels where other clients are affected; full cooperation during inspections; and details of scope, procedure and frequency. Crucially, those rights must not be impeded or limited by other contractual arrangements or implementation policies.
Art. 30(3)(f) Exit strategy and transition period Exit strategies with a mandatory adequate transition period during which the provider keeps delivering, so you can migrate to another provider or bring the service in-house without disruption.
What this means: a checklist result based on your own assessment of the contract. Marking a clause present does not mean it is drafted adequately — Article 30 sets what must be addressed, not how well, and a clause that nominally covers a point can still fail in substance. Whether a function is critical or important is a determination you make and must be able to justify. This is not legal advice.

Every contract you assess here is a row in your Register of Information. The DORA module keeps the register, resolves the LEI chain, runs the validation checks and produces the XBRL-CSV package — with free record keeping and validation to start.

Create free account
Why it bites

Three things firms discover late

Article 30 is short. The remediation it triggers is not.

Not negotiable

These are obligations, not positions

The clauses are regulatory requirements on your firm. A provider declining to accept them does not remove your obligation — it makes the arrangement one you may not be able to keep.

Audit rights

“Unrestricted” means unrestricted

Article 30(3)(e) requires access, inspection and audit rights whose exercise is not impeded or limited by other contractual arrangements or implementation policies. A security policy that forbids on-site visits defeats the clause even where the clause exists.

Exit

A termination right is not an exit strategy

Article 30(2)(h) requires termination rights. Article 30(3)(f) separately requires a mandatory adequate transition period during which the provider keeps delivering. Contracts routinely have the first and not the second.

Rules reviewed 21 August 2026 · Regulation (EU) 2022/2554 Art. 30

Scope

What this checker does

It turns Article 30 into a structured list and records your answers against it. It cannot read your contract, and it does not judge drafting quality.

It doesStructure the requirement

  • Lists all nine Article 30(2) clauses and the six additional Article 30(3) clauses, each against its reference.
  • Applies the Article 30(3) set only where the contract supports a critical or important function.
  • Separates outright gaps from clauses you need to verify.
  • Notes the microenterprise derogation on audit rights where it applies.
  • Includes the two Article 30(1) form requirements, which checklists often omit.
  • Produces a gap list ordered so the hardest negotiations surface first.

It does notRead or assess the contract

  • Accept, parse or store any contract text. Nothing is uploaded.
  • Judge whether a clause is drafted adequately or would survive supervisory scrutiny.
  • Determine whether the function is critical or important — that is your assessment to make and defend.
  • Cover Article 28 register obligations, Article 29 concentration risk, or the subcontracting RTS.
  • Address the oversight regime for designated critical ICT third-party providers.
  • Constitute legal advice or a substitute for review by a qualified adviser.

The contracts you assess become your register

Article 28 requires a Register of Information covering every contractual arrangement for ICT services, submitted to your competent authority. The clauses here and the register are two views of the same population.

See DORA Register of Information

Nothing you enter here leaves your browser

This tool takes no document. Your answers are held in the page and discarded when you close or reload it. Nothing is sent to REGREP, written to a log, saved, or passed to any analytics tool.

That matters more here than on a calculator: contract positions with named providers are commercially sensitive, and we would rather not be able to see them.

Questions

About Article 30

Do these clauses apply to every supplier?

The nine clauses in Article 30(2) apply to every contractual arrangement on the use of ICT services, including those supporting functions that are not critical or important. The six in Article 30(3) apply additionally where the service supports a critical or important function.

What if the provider will not agree to the clauses?

The obligation sits on your firm, not on the provider, so a refusal does not remove it. Article 30(4) asks both sides to consider standard contractual clauses developed by public authorities. Where a provider will not meet the requirements for a critical or important function, the realistic outcomes are renegotiation, alternative assurance arrangements where the regulation permits them, or replacement.

We are a microenterprise. Do the audit rights still apply?

In modified form. By way of derogation from Article 30(3)(e), a microenterprise and its provider may agree that rights of access, inspection and audit are delegated to an independent third party appointed by the provider, provided the firm can request information and assurance about the provider’s performance at any time. The rights are redirected, not removed.

Our audit clause exists but their security policy blocks site visits.

Then the clause probably does not meet Article 30(3)(e)(i), which requires that the effective exercise of those rights is not impeded or limited by other contractual arrangements or implementation policies. This is one of the most common gaps in contracts that look compliant on a clause-by-clause read.

Is a termination right enough to satisfy the exit requirement?

No. Termination rights and minimum notice periods are required by Article 30(2)(h) for every contract. Article 30(3)(f) separately requires an exit strategy for critical or important functions, including a mandatory adequate transition period during which the provider continues to deliver while you migrate elsewhere or bring the service in-house.

Do you store my answers or read my contract?

No, on both counts. The tool takes no document and stores nothing. Everything is held in the page and discarded when you close or reload it.

The gap list is the easy part. The register is the deadline.

Create a free account and keep every ICT arrangement in one place — validated, LEI-resolved and ready to submit.

No card required · free record keeping and validation · nothing stored from this checker