Third-party risk: what NIS 2 and DORA require

Inventory, assess, govern by contract and be able to exit: what NIS 2, DORA and the GDPR expect from you regarding your providers, text by text.

· 13 min read
Illustration: three glass pillars, the middle one orange
NIS 2 Art. 21(2)(d)
DORA Art. 28 to 30
GDPR Art. 28

When it comes to third-party risk, NIS 2 and DORA require the same discipline: know your providers, assess them before signing, write security requirements into the contract, monitor them over time and prepare to replace them. NIS 2 sets the principle (Article 21), DORA spells it out for the financial sector (Articles 28 to 30, with a mandatory register of information), and the GDPR has governed processors of personal data since 2018 (Article 28). This article, which complements our guide to third-party risk management (TPRM), goes through these requirements text by text, then compares them.

01

Why regulators are targeting third-party risk

An organisation that has hardened its own information system is still exposed through those who access it or host its data: managed service provider, software vendor, hosting provider, payroll provider. Verizon's 2025 Data Breach Investigations Report states that third-party involvement in breaches doubled in one year, reaching 30% of the cases studied. In France, ANSSI notes in its 2025 cyber threat overview that data exfiltrations sometimes follow the compromise of a service provider.

European lawmakers drew a simple conclusion: you can outsource a service, not the responsibility. DORA says so explicitly: a financial entity remains “fully responsible” for complying with its obligations when it uses a provider. The major incidents described in our article on supply chain attacks (SolarWinds, Kaseya, MOVEit) weighed in this shift.

02

Third-party risk and NIS 2: supply chain security

Article 21(2)(d): a minimum measure

Article 21 of the NIS 2 Directive lists ten measures that essential and important entities must implement. Point (d) covers “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. Point (e) extends it to security in the acquisition, development and maintenance of systems. For a reminder of the directive's scope, see our article From NIS to NIS 2.

Article 21(3): assess each supplier

Paragraph 3 sets out what the entity must look at when choosing its measures:

  • the vulnerabilities specific to each direct supplier and service provider;
  • the overall quality of their products and cybersecurity practices, including their secure development procedures;
  • the results of coordinated risk assessments of critical supply chains carried out at EU level (Article 22), such as the one that led to the 5G toolbox.

The directive does not say how: no list of clauses, no register format. The principle of proportionality applies, under the responsibility of management: Article 20 requires management bodies to approve the measures and oversee their implementation, and failures can make them liable (see our article on NIS 2 penalties).

Implementing Regulation 2024/2690 for digital providers

For certain digital entities (cloud computing providers, data centres, managed and managed security service providers, online marketplaces, etc.), Implementing Regulation (EU) 2024/2690 details the measures. Its supply chain section requires a dedicated security policy, supplier selection criteria, security requirements built into contracts and an up-to-date directory of suppliers and service providers. It is the best available reading grid, even for entities it does not directly cover.

03

NIS 2 in France: where does transposition stand in 2026?

Member States had to transpose NIS 2 by 17 October 2024. In France, the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, which also transposes the critical entities resilience directive and the “directive” part of DORA, was adopted by the Senate on 12 March 2025. The National Assembly's special committee voted on its version on 10 September 2025, but the plenary debate has been postponed several times: on 6 October 2026, the Conference of Presidents again removed it from the agenda of 7 October.

Meanwhile, the European Commission referred France, Ireland, Spain and the Netherlands to the Court of Justice of the EU on 8 July 2026 for failing to notify transposition. And on 17 March 2026 ANSSI published the ReCyF (French cyber framework), the list of measures it recommends to meet the NIS 2 objectives, presented as a working document until the law is adopted.

Should you wait for the law before dealing with your third parties? No. The directive's requirements are known, the ReCyF shows how they are expected to be applied, and your large customers, already subject to DORA or to NIS 2 elsewhere in Europe, are sending you their questionnaires. Inventorying and assessing suppliers takes months: better to start before the obligation becomes enforceable.

Timeline · Key dates
  1. 25 May 2018 GDPR
    The GDPR applies Article 28 sets the mandatory content of the contract with each processor.
  2. 16 Jan 2023 NIS 2
    NIS 2 and DORA enter into force Both texts, published on 27 December 2022, then give Member States and entities two years.
  3. 17 Oct 2024 NIS 2
    NIS 2 transposition deadline The same day, the Commission adopts Implementing Regulation 2024/2690 for digital providers.
  4. 17 Jan 2025 DORA
    DORA applies Third-party risk strategy, register, Article 30 clauses: everything becomes enforceable.
  5. 30 Apr 2025 DORA
    First registers of information sent National authorities hand the registers over to the European Supervisory Authorities (ESAs).
  6. 2 Jul 2025 DORA
    Subcontracting RTS published in the OJ Delegated Regulation (EU) 2025/532 on subcontracting of critical or important functions.
  7. 18 Nov 2025 DORA
    19 critical ICT providers designated The ESAs publish the first list of providers under their direct oversight.
  8. 17 Mar 2026 France
    ANSSI publishes the ReCyF A framework of measures for NIS 2, presented as a working document pending the law.
  9. 31 Mar 2026 DORA
    Annual register filing with the ACPR Data as at 31 December 2025, submitted on the OneGate platform.
  10. 8 Jul 2026 NIS 2
    France referred to the CJEU The Commission takes France to the Court of Justice for failing to notify NIS 2 transposition.
  11. 6 Oct 2026 France
    Résilience bill postponed again Adopted by the Senate on 12 March 2025, the bill is still awaiting its plenary debate in the National Assembly.
  12. Today: October 2026
Dates checked against the official sources cited in the article (EUR-Lex, ESAs, ACPR, ANSSI, European Commission, French National Assembly); status as of 8 October 2026.
04

DORA and ICT third-party providers: Chapter V

Applicable since 17 January 2025, the DORA Regulation devotes its Chapter V to managing ICT third-party risk. For a bank, insurer, asset manager or payment institution, it takes precedence over NIS 2 and goes much further. Here are the essentials for third parties.

Article 28: strategy, due diligence, audit, termination, exit

  • Strategy: the entity adopts a strategy on ICT third-party risk, with a policy on the use of services supporting critical or important functions, reviewed by the management body.
  • Before signing: determine whether the function is critical or important, identify the risks, including the contribution to concentration risk, carry out due diligence and identify conflicts of interest.
  • Security standards: only contract with providers that comply with appropriate information security standards.
  • Audit: a risk-based audit frequency and scope.
  • Termination: the contract must be terminable in the event of a serious breach, proven weaknesses at the provider or an obstacle to supervision.
  • Exit: for critical or important functions, documented, tested and reviewed exit strategies, with transition plans.

Article 29: concentration risk

Before entrusting a critical function, the entity assesses whether it is becoming dependent on a provider that is hard to replace, or on several closely connected providers, and examines subcontracting chains, particularly outside the Union.

Article 30: mandatory contract clauses

Every ICT services contract must include at least: a full description of the services and the subcontracting conditions, the countries where the service is provided and data is processed, provisions on data availability, integrity and confidentiality, return of data if the provider fails, service levels, incident assistance, cooperation with authorities, termination rights and participation in the entity's training.

For critical or important functions, the contract must add quantified service levels, notification duties, tested continuity plans, participation in threat-led penetration testing (TLPT), unrestricted rights of access, inspection and audit and an exit strategy with a mandatory transition period. These clauses naturally fit into a security assurance plan annexed to the contract.

Implementing texts you should know

05

The DORA register of information: content and filing

The DORA register of information lists all contractual arrangements with ICT providers, at entity level and, where relevant, group level, distinguishing those that support critical or important functions. It describes providers, contracts, services, supported functions, processing locations and subcontracting chains. Its format, a set of linked tables, is laid down by Regulation 2024/2956.

It serves two purposes: managing your dependencies, and feeding supervision. National authorities sent the first registers to the European Supervisory Authorities (ESAs) by 30 April 2025, to identify critical providers. In France, filing takes place on the Banque de France's OneGate platform: for the 2026 campaign, the ACPR set a deadline of 31 March 2026, for data as at 31 December 2025.

The first campaign showed how hard the exercise is: according to the review presented by the ACPR in January 2026, 84% of entities had filed, but only 39% of filings could be processed at European level. Rejections mostly came from format issues (dates, file structure, encoding). The practical lesson: a register is kept up to date continuously, from reliable supplier data, not rushed before a deadline.

06

Critical ICT third-party providers: direct EU oversight

DORA creates an unprecedented framework: the ESAs (EBA, EIOPA, ESMA) directly oversee ICT providers deemed critical to the financial sector. On 18 November 2025 they published the first list, which includes 19 providers: large cloud providers, data centres, infrastructure and network providers, and financial-sector-specific technology. The list is updated every year.

A “Lead Overseer” can review their risk management, carry out inspections and issue recommendations. If a provider refuses to cooperate, it can impose periodic penalty payments of up to 1% of the provider's average daily worldwide turnover, for up to six months, and, as a last resort, lead national authorities to require financial entities to suspend or terminate the contract. For you as a customer, this changes nothing: your obligations under Articles 28 to 30 remain in full, including towards these large players.

07

GDPR: Article 28, the long-standing basis for processors

Long before NIS 2 and DORA, Article 28 of the GDPR imposed a third-party risk approach for personal data. The controller may only use processors providing “sufficient guarantees”, and must sign a contract with each one that provides at least for:

  • processing only on documented instructions, and confidentiality of authorised persons;
  • the security measures of Article 32;
  • prior authorisation of any sub-processing, with the same obligations for the second-tier processor;
  • assistance to the controller with data subject rights, breaches and impact assessments;
  • deletion or return of data at the end of the contract;
  • making information available and allowing audits, including inspections.

The French data protection authority, the CNIL, details these points in its guide for processors. It also fines providers themselves: in April 2022, the software vendor Dedalus Biologie was fined €1.5 million after a leak affecting more than 500,000 people, in particular for breaching Articles 28, 29 and 32. To keep your record and processor contracts in order, see our GDPR compliance module.

08

NIS 2, DORA and GDPR compared for third-party risk

The three texts overlap widely. The comparison below puts them side by side, requirement by requirement, with the reference of the relevant article.

Comparison · Third-party risk Pick a requirement

Third-party inventory

NIS 2 Art. 21 · Reg. 2024/2690
Required

The directive itself imposes no register, but you cannot assess your direct suppliers without listing them. Implementing Regulation 2024/2690 requires an up-to-date register from the digital providers it covers.

DORA Art. 28(3) · ITS 2024/2956
Detailed

A register of information on all ICT arrangements, in a set format, kept at entity and group level and reported every year to the authority.

GDPR Art. 30
Implicit

The record of processing lists the recipients of data; processors appear there indirectly.

Pre-contract assessment

NIS 2 Art. 21(3)
Required

Take into account the vulnerabilities specific to each direct supplier, the quality of its products and its cybersecurity practices, including secure development.

DORA Art. 28(4) and (5)
Detailed

Before signing: qualify the function (critical or important), identify risks including concentration, perform due diligence, assess conflicts of interest.

GDPR Art. 28(1)
Required

Only use processors providing “sufficient guarantees” as to technical and organisational measures.

Contract clauses

NIS 2 Art. 21(2)(d)
Implicit

The directive covers supplier relationships without listing clauses. In practice, security requirements go into the contract.

DORA Art. 30
Detailed

A list of mandatory clauses: service description, processing locations, service levels, incident assistance, cooperation with the authority, termination; more for critical functions.

GDPR Art. 28(3)
Detailed

A mandatory contract with minimum content: documented instructions, confidentiality, security, sub-processing, assistance, return or deletion of data, audits.

Audit and oversight

NIS 2 Art. 21
Implicit

No audit right as such; it follows from the duty to take appropriate and proportionate measures.

DORA Art. 28(6) · Art. 30(3)(e)
Detailed

Risk-based audit frequency; for critical functions, unrestricted rights of access, inspection and audit, including for the authority.

GDPR Art. 28(3)(h)
Required

The processor makes the necessary information available and allows audits, including inspections.

Subcontracting chains

NIS 2 Art. 21(2)(d)
Implicit

The text refers to “direct” suppliers. Further tiers come in through the overall quality of the supplier's practices.

DORA Art. 30(2)(a) · RTS 2025/532
Detailed

The contract states whether subcontracting is allowed and on what terms; a delegated regulation governs subcontracting of critical functions.

GDPR Art. 28(2) and (4)
Detailed

Prior written authorisation from the controller, and the same obligations imposed on the sub-processor.

Incident at the third party

NIS 2 Art. 23
Required

The entity must still report its significant incidents, even when they originate at a supplier.

DORA Art. 30(2)(f) · (3)(b)
Detailed

Provider assistance during incidents, at no cost or at a cost set in advance; duty to report anything that threatens service levels.

GDPR Art. 33(2)
Required

The processor notifies the controller of any breach without undue delay.

Exit and reversibility

NIS 2 Art. 21(2)(c)
Implicit

Nothing specific; business continuity, required elsewhere, implies being able to change supplier.

DORA Art. 28(8) · Art. 30(3)(f)
Detailed

Documented, tested exit strategies for critical functions, with a mandatory transition period.

GDPR Art. 28(3)(g)
Required

At the end of the contract, deletion or return of personal data, at the controller's choice.

Data location

NIS 2 Art. 21(3)
Implicit

No direct requirement; location weighs in the supplier assessment and in coordinated EU risk assessments.

DORA Art. 30(2)(b)
Detailed

The contract states the countries or regions where the service is provided and data is processed and stored, with notice of any change.

GDPR Chapter V
Detailed

Transfers outside the European Economic Area are regulated (adequacy decision, standard clauses, appropriate safeguards).

Simplified reading of the texts, to be checked against the official text and national transposition. “Implicit”: the obligation follows from general measures without being described; “Required”: the text imposes it in general terms; “Detailed”: the text sets out its content.
The three texts at a glance
CriterionNIS 2DORAGDPR
Who is coveredEssential and important entities in 18 sectorsFinancial entities (and critical ICT providers)Any data controller
Third parties concernedDirect suppliers and service providersICT service providers and their subcontractingProcessors of personal data
Level of detailPrinciple, specified by implementing acts and national lawsVery detailed, with RTS and ITSContract content set by Article 28
Key deliverableSupply chain security policyRegister of informationData processing agreement (DPA)
Authority in FranceANSSIACPR and AMFCNIL
09

Bringing supplier relationships into compliance: one setup for three texts

Rather than three parallel projects, build a single process from which each text takes what it requires:

  1. Inventory all third parties, with the service provided, the data entrusted, the access granted and the location. For a financial entity, this is the basis of the register of information.
  2. Rank by criticality: critical or important function, data sensitivity, substitutability.
  3. Assess before signing, with a proportionate supplier security questionnaire and supporting evidence.
  4. Contract the requirements: DORA Article 30 clauses, GDPR Article 28 contract, security assurance plan.
  5. Monitor and audit over time, at a pace set by criticality, and reassess after every change.
  6. Prepare the exit: reversibility, transition plan, alternative solutions.

This is what Phinasoft supports with its third-party risk management module: you create questionnaires based on your requirements, your providers answer them on a dedicated portal, you give them feedback (accepted or rejected non-conformities, requests for more information) and track indicators, then export the requirements to include in your security assurance plans. The same requirements feed your internal compliance campaigns. To see it on your own cases, you can request a demo.

Summary

01

Three texts, one logic

NIS 2, DORA and the GDPR make you accountable for the security your third parties provide: you must know them, assess them, govern them by contract and be able to replace them.

02

DORA is the most precise

A register of information in a set format, the mandatory clauses of Article 30, tested exit strategies and EU oversight of critical ICT providers.

03

Don't wait for French law

NIS 2 is not yet transposed in France as of October 2026, but the directive, ANSSI's ReCyF and your customers already set the expected level.

Frequently asked questions

What does NIS 2 say about suppliers and subcontractors?

Article 21 of NIS 2 lists supply chain security among the minimum measures. The entity must address risks arising from its relationships with its direct suppliers and service providers, taking into account each one's specific vulnerabilities, the quality of their products and their cybersecurity practices, including secure development.

What is the DORA register of information?

It is the structured list of all contractual arrangements a financial entity has with ICT third-party service providers, required by Article 28 of DORA. Its format is set by Implementing Regulation 2024/2956. It is kept at entity and group level and reported every year to the competent authority, such as the ACPR or AMF in France.

Which clauses does DORA require in contracts with ICT providers?

Article 30 requires, among other things, a full description of services, data processing locations, service levels, incident assistance, cooperation with authorities and termination rights. For critical or important functions, it adds quantified service levels, tested continuity plans, unrestricted audit rights and an exit strategy.

Has France transposed NIS 2 in 2026?

No, not as of 8 October 2026. The bill on critical infrastructure resilience and cybersecurity was adopted by the Senate on 12 March 2025, but its plenary debate in the National Assembly has been postponed several times, most recently on 6 October 2026.

Is a subcontractor itself subject to NIS 2?

It can be, if its sector and size bring it within the directive's scope, for example as a managed service provider or cloud computing provider. Otherwise it has no direct obligation, but customers subject to NIS 2 pass their requirements on to it through contracts and questionnaires.

What is the difference between DORA and NIS 2 for providers?

For financial entities, DORA takes precedence as the specific law. It goes further than NIS 2: a register in a set format, listed contract clauses, tested exit strategies and direct oversight of critical ICT providers by the European authorities. NIS 2 sets a general principle without a list of clauses.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.