DORA Article 30 checklist: check an ICT third-party contractBETA

Since 17 January 2025, banks, insurers, investment firms and other financial entities must include the clauses of DORA Article 30 in their ICT provider contracts. The list checks the baseline requirements (para. 2) and the additional ones for critical or important functions (para. 3). Useful for reviewing a vendor contract portfolio and DORA addenda.

Check your contract

Up to 20 pages a month free. Files are not stored.

Law as of

2025-01-17

Compared with Art. 30 as applicable from 17 January 2025, without the technical standards (RTS) on subcontracting. Implementing acts may change.

Our measurement

Precision 79–87%, recall 85–89% (2 blind rounds, 8 addenda)

What we check (15 provisions)

  • Description of functions/ICT services and subcontracting conditions

    art. 30 ust. 2 lit. a

  • Locations of services and data processing, with advance notice of changes

    art. 30 ust. 2 lit. b

  • Availability, authenticity, integrity and confidentiality of data

    art. 30 ust. 2 lit. c

  • Access, recovery and return of data on insolvency or termination

    art. 30 ust. 2 lit. d

  • Service level descriptions incl. updates

    art. 30 ust. 2 lit. e

  • Incident assistance at no extra cost or at a cost set ex ante

    art. 30 ust. 2 lit. f

  • Full cooperation with competent and resolution authorities

    art. 30 ust. 2 lit. g

  • Termination rights and minimum notice periods

    art. 30 ust. 2 lit. h

  • Provider participation in ICT security awareness and resilience training

    art. 30 ust. 2 lit. i

  • Precise quantitative and qualitative performance targets (critical functions)

    art. 30 ust. 3 lit. a · applies to: critical or important functions

  • Notice periods and provider reporting obligations

    art. 30 ust. 3 lit. b · applies to: critical or important functions

  • Business continuity plans and their testing; ICT security measures

    art. 30 ust. 3 lit. c · applies to: critical or important functions

  • Participation in threat-led penetration testing (TLPT)

    art. 30 ust. 3 lit. d · applies to: critical or important functions

  • Unrestricted access, inspection and audit rights (incl. authorities)

    art. 30 ust. 3 lit. e · applies to: critical or important functions

  • Exit strategy and mandatory transition period

    art. 30 ust. 3 lit. f · applies to: critical or important functions

What the result looks like

For each provision you get "found" with a verbatim quote and the file name, or "not found in the documents". The quote is cut from the document character for character, so you can verify it in the original in seconds.

The engine is deterministic: no generative model, the same document always gives the same result. It does not judge whether a provision is adequate; that is the lawyer's call.

Frequently asked questions

What must an ICT third-party service contract contain?

Under Regulation (EU) 2022/2554 (DORA), Article 30: description of functions/ICT services and subcontracting conditions; locations of services and data processing, with advance notice of changes; availability, authenticity, integrity and confidentiality of data; access, recovery and return of data on insolvency or termination; service level descriptions incl. updates; incident assistance at no extra cost or at a cost set ex ante; full cooperation with competent and resolution authorities; termination rights and minimum notice periods; provider participation in ICT security awareness and resilience training; precise quantitative and qualitative performance targets (critical functions); notice periods and provider reporting obligations; business continuity plans and their testing; ICT security measures; participation in threat-led penetration testing (TLPT); unrestricted access, inspection and audit rights (incl. authorities); exit strategy and mandatory transition period. KROTKA checks each of these provisions separately.

Does KROTKA use AI to check the contract?

Not generative AI. The list runs on deterministic rules: the same document always gives the same result, and every provision found is shown as a verbatim quote you can verify. The engine does not invent or paraphrase anything.

Which version of the law do you compare with?

The law as of 17 January 2025. Compared with Art. 30 as applicable from 17 January 2025, without the technical standards (RTS) on subcontracting. Implementing acts may change.

How accurate is the list?

Our measurement: Precision 79–87%, recall 85–89% (2 blind rounds, 8 addenda). The list is in beta. We measure on agreements the engine has not seen before, against independently prepared annotations.

Does KROTKA judge whether a clause is adequate?

No. It shows whether and where the provision appears. Judging its content is the lawyer's job. "Not found" means the engine found no such provision in the uploaded documents. KROTKA does not provide legal advice.

Does the list cover the RTS on subcontracting?

No. We compare with the text of Article 30 of the regulation. Implementing acts and technical standards may change, which is why we state the law-as-of date. The list is in beta.

Are my documents stored?

No. Files are analysed in memory and not stored on our servers. They are never used to train models.

How much does a check cost?

Up to 20 pages a month free. A single matter up to 150 pages is €24, the Professional plan €59 a month for 2,000 pages. Every list runs on every analysis.

Other checklists

Check your contract

Up to 20 pages a month free. Files are not stored.