Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

ICT suppliers in DORA – which contracts must be recorded?

Ariadnah Solutions DORA 10 Sep 2025 5 min read

Recording ICT supplier contracts is a fundamental DORA requirement. But there's significant confusion about which contracts are actually in scope. This guide cuts through the complexity to give you clear, actionable answers about what needs to be in your DORA information register.

01

1. Which contracts are in scope?

The simple answer: Every contract with a supplier that provides ICT services to your organization.

This includes contracts with:

  • External ICT third-party service providers, any outside company (whether legal or natural persons) providing ICT services
  • ICT intra-group service providers, entities within your group that predominantly provide ICT services to other group entities

The key question: Does the supplier provide ICT services? If yes, the contract must be recorded.

There's no minimum contract value, no exceptions for "small" suppliers, and no carve-outs for "non-critical" services. If it's an ICT service contract, it's in scope.

02

2. What counts as an ICT service?

DORA deliberately uses a broad definition of ICT services. According to Article 3(21), ICT services are:

"Digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis"

Simple test: If the service involves technology, data, or digital delivery on an ongoing basis, it's likely an ICT service.

Important exception: Regulated financial services provided by regulated financial entities (like banking, insurance, etc.) are NOT considered ICT services, even if they have a technology component.

03

3. Recording at the service level

Here's where many organizations get it wrong: You don't just record contracts, you must record each ICT service provided under those contracts.

For every contract, you must:

  1. Identify all ICT services delivered
  2. Classify each service using one of 19 predefined types (S01-S19)
  3. Record all service types delivered under a contract

Example: Your Microsoft Enterprise Agreement might include: • Office 365 (S19, Cloud services: SaaS) • Azure cloud infrastructure (S17, Cloud services: IaaS) • Microsoft security services (S04, ICT security management services)

This single contract requires three separate records for your Microsoft contract, one for each service type.

04

4. The 19 service types you must use

Every ICT service must be classified into one of these categories:

S01 ICT project management Provision of services related to Project Management Officer (PMO).

S02 ICT Development Provision of services related to: business analysis, software design and development, testing.

S03 ICT help desk and first level support Provision of services related to: helpdesk support and first level support on ICT incidents.

S04 ICT security management services Provision of services related to: ICT security (protection, detection, response and recovery), including security incident handling and forensics.

S05 Provision of data Subscription to the services of data providers (digital data service).

S06 Data analysis Provision of services related to the support for data analysis (digital data service).

S07 ICT, facilities and hosting services (excluding Cloud services) Provision of ICT infrastructure, facilities and hosting services, including the provision of utilities (energy, heat management etc.), telecom access and physical security (excluding cloud services), payment-processing activities, or operating payment infrastructures.

S08 Computation Provision of digital processing capabilities (including data computation), excluding the computation services performed in the context of a cloud environment.

S09 Non-Cloud Data storage Provision of data storage platform (excluding cloud services).

S10 Telecom carrier Operations for telecommunication systems and flow management. Traditional analogue telephone services are explicitly excluded pursuant to Article 3, point (21), of Regulation (EU) 2022/2554.

S11 Network infrastructure Provision of network infrastructure.

S12 Hardware and physical devices Provision of workstations, phones, servers, data storage devices, appliances, etc. in a form of a service.

S13 Software licencing (excluding SaaS) Provision of software run on premises.

S14 ICT operation management (including maintenance) Provision of services related to: infrastructure (systems and hardware except network) configuration, maintenance, installing, capacity management, business continuity management, etc. Including Managed Service Providers (MSP).

S15 ICT Consulting Provision of intellectual / ICT expertise services.

S16 ICT Risk management Verification of compliance with ICT risk management requirements in accordance with Article 6(10) of Regulation (EU) 2022/2554.

S17 Cloud services: IaaS Infrastructure-as-a-Service.

S18 Cloud services: PaaS Platform-as-a-Service.

S19 Cloud services: SaaS Software-as-a-Service.

You can't create your own categories or use generic descriptions. Pick the closest match from the official list.

05

5. Common pitfalls to avoid

Don't make these mistakes:

  • Recording only "important" contracts, ALL ICT service contracts are in scope.
  • One entry (schema 02.02) per contract, you need one entry per SERVICE TYPE within each contract.
  • Using your own service categories, you must use the official S01-S19 classifications
  • Excluding intra-group providers, internal ICT service providers count too
  • Forgetting embedded ICT services, even if ICT isn't the main purpose, ICT components must be recorded

06

6. Why this comprehensive approach?

Recording all ICT suppliers isn't bureaucracy, it's essential risk management:

  • Complete visibility, you can't manage risks in contracts you haven't identified
  • Concentration risk, understanding your full supplier landscape reveals dangerous dependencies
  • Regulatory compliance, supervisors need the complete picture, not just the "important" parts

07

7. Practical next steps

Start with these actions:

  1. Inventory all contracts, gather a list of all your contracted suppliers
  2. Apply the ICT service test, does this supplier provide digital or data services?
  3. Identify service types, break down each contract into its component ICT services
  4. Classify using S01-S19, assign the appropriate category to each service
  5. Build your DORA-proof inventory

Remember: When in doubt, include it. The regulatory expectation is comprehensive coverage. It's better to over-include initially and refine later than to miss contracts that should be in scope.

The DORA supplier inventory isn't just about compliance, it's about knowing exactly who provides your technology services and understanding your complete ICT supply chain. That visibility is fundamental to managing digital operational resilience.

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the supplier and contract approach Related analysis The Risk You Didn’t Sign Related analysis DORA Supply-Chain Reporting: When Granularity Creates Noise
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.