DORA Article 30 checklist: check an ICT third-party contractBETA
Since 17 January 2025, banks, insurers, investment firms and other financial entities must include the clauses of DORA Article 30 in their ICT provider contracts. The list checks the baseline requirements (para. 2) and the additional ones for critical or important functions (para. 3). Useful for reviewing a vendor contract portfolio and DORA addenda.
Up to 20 pages a month free. Files are not stored.
Legal source
Regulation (EU) 2022/2554 (DORA), Article 30Law as of
2025-01-17
Compared with Art. 30 as applicable from 17 January 2025, without the technical standards (RTS) on subcontracting. Implementing acts may change.
Our measurement
Precision 79–87%, recall 85–89% (2 blind rounds, 8 addenda)
What we check (15 provisions)
Description of functions/ICT services and subcontracting conditions
art. 30 ust. 2 lit. a
Locations of services and data processing, with advance notice of changes
art. 30 ust. 2 lit. b
Availability, authenticity, integrity and confidentiality of data
art. 30 ust. 2 lit. c
Access, recovery and return of data on insolvency or termination
art. 30 ust. 2 lit. d
Service level descriptions incl. updates
art. 30 ust. 2 lit. e
Incident assistance at no extra cost or at a cost set ex ante
art. 30 ust. 2 lit. f
Full cooperation with competent and resolution authorities
art. 30 ust. 2 lit. g
Termination rights and minimum notice periods
art. 30 ust. 2 lit. h
Provider participation in ICT security awareness and resilience training
art. 30 ust. 2 lit. i
Precise quantitative and qualitative performance targets (critical functions)
art. 30 ust. 3 lit. a · applies to: critical or important functions
Notice periods and provider reporting obligations
art. 30 ust. 3 lit. b · applies to: critical or important functions
Business continuity plans and their testing; ICT security measures
art. 30 ust. 3 lit. c · applies to: critical or important functions
Participation in threat-led penetration testing (TLPT)
art. 30 ust. 3 lit. d · applies to: critical or important functions
Unrestricted access, inspection and audit rights (incl. authorities)
art. 30 ust. 3 lit. e · applies to: critical or important functions
Exit strategy and mandatory transition period
art. 30 ust. 3 lit. f · applies to: critical or important functions
What the result looks like
For each provision you get "found" with a verbatim quote and the file name, or "not found in the documents". The quote is cut from the document character for character, so you can verify it in the original in seconds.
The engine is deterministic: no generative model, the same document always gives the same result. It does not judge whether a provision is adequate; that is the lawyer's call.
Frequently asked questions
What must an ICT third-party service contract contain?
Under Regulation (EU) 2022/2554 (DORA), Article 30: description of functions/ICT services and subcontracting conditions; locations of services and data processing, with advance notice of changes; availability, authenticity, integrity and confidentiality of data; access, recovery and return of data on insolvency or termination; service level descriptions incl. updates; incident assistance at no extra cost or at a cost set ex ante; full cooperation with competent and resolution authorities; termination rights and minimum notice periods; provider participation in ICT security awareness and resilience training; precise quantitative and qualitative performance targets (critical functions); notice periods and provider reporting obligations; business continuity plans and their testing; ICT security measures; participation in threat-led penetration testing (TLPT); unrestricted access, inspection and audit rights (incl. authorities); exit strategy and mandatory transition period. KROTKA checks each of these provisions separately.
Does KROTKA use AI to check the contract?
Not generative AI. The list runs on deterministic rules: the same document always gives the same result, and every provision found is shown as a verbatim quote you can verify. The engine does not invent or paraphrase anything.
Which version of the law do you compare with?
The law as of 17 January 2025. Compared with Art. 30 as applicable from 17 January 2025, without the technical standards (RTS) on subcontracting. Implementing acts may change.
How accurate is the list?
Our measurement: Precision 79–87%, recall 85–89% (2 blind rounds, 8 addenda). The list is in beta. We measure on agreements the engine has not seen before, against independently prepared annotations.
Does KROTKA judge whether a clause is adequate?
No. It shows whether and where the provision appears. Judging its content is the lawyer's job. "Not found" means the engine found no such provision in the uploaded documents. KROTKA does not provide legal advice.
Does the list cover the RTS on subcontracting?
No. We compare with the text of Article 30 of the regulation. Implementing acts and technical standards may change, which is why we state the law-as-of date. The list is in beta.
Are my documents stored?
No. Files are analysed in memory and not stored on our servers. They are never used to train models.
How much does a check cost?
Up to 20 pages a month free. A single matter up to 150 pages is €24, the Professional plan €59 a month for 2,000 pages. Every list runs on every analysis.
Other checklists
- GDPR Art. 28(3): data processing agreement
- UK Construction Act (HGCRA 1996): payment and adjudication
- HIPAA: business associate agreement (BAA)
- UK Employment Rights Act s.1: written statement of particulars
- Polish Public Procurement Law: mandatory contract terms
Up to 20 pages a month free. Files are not stored.