{
  "node_id": "eu-dora-ict-third-party-cloud",
  "title": "EU DORA Subcontracting Chain Provisions - ICT Third-Party Risk for Cloud and Managed Service Providers in Financial Services",
  "domain": "Cloud & SaaS",
  "version": "1.0.0",
  "last_updated": "2026-04-17",
  "bluf": "Under Article 30(3) of EU DORA, financial entities must ensure their contractual arrangements with ICT third-party service providers, such as cloud providers, explicitly govern the entire subcontracting chain, requiring prior notification of any changes and granting the financial entity the right to object to or terminate the contract based on such changes.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "csa-ccm-v4-cloud-controls",
    "iso-27017-cloud-controls",
    "iso-22301-bcm-2019"
  ],
  "primary_citations_count": 7
}