The EU Regulation on Digital Operational Resilience (DORA) will apply from 17 January 2025 to most financial entities in the EU. DORA's increased focus on third-party risk management includes detailed requirements for provisions that must be included in existing and new ICT contracts. This briefing concentrates on the contractual requirements imposed by DORA. Firms have a substantial "to do" list to prepare for DORA over the coming months and, to be ready in time, they should be identifying and triaging their ICT contracts, reviewing them against those requirements and negotiating with service providers any contract amendments necessary to comply.
From Monday 2nd March 2026 we will have moved offices. Our new address is 3 Stonecutter Street, London, EC4A 4AW.