Question ID: 3556 - DORA 293
Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Topic: Other DORA topics
Article: 30
Status: Rejected
Date of submission: 27 Apr 2026
Question
In your published answer on the register of information, you clarified that in cases where no direct contract exists with the effective ICT third-party service provider, the financial entity should record the agreement with the reseller and complement it with any available information on the effective ICT third-party service provider as subcontractor.
Does this mean that, in a reseller constellation, the Art. 30 DORA contractual requirements must be fulfilled in the agreement with the reseller – given that the effective ICT third-party service provider is treated as a subcontractor and the reseller is therefore considered the contractually responsible party towards the financial entity?
Or is the financial entity additionally expected to seek direct contractual arrangements with the effective ICT third-party service provider, even where no direct contractual relationship exists?
EIOPA answer
This question is rejected because Q&A215 already addresses it.