{
  "node_id": "eu-dora-rts-subcontracting-ict-2025-532",
  "title": "Commission Delegated Regulation (EU) 2025/532 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the elements a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-28",
  "bluf": "This DORA regulatory technical standard sets the elements a financial entity must determine and assess before and during the subcontracting of ICT services that support critical or important functions, including due diligence on the ICT provider's ability to oversee subcontractors, risk assessment of the subcontracting chain, equivalent access and audit rights down the chain, and termination rights where unapproved material changes occur; it supplements DORA Article 30(5).",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-dora-2022-2554-article-28-ict-third-party-risk-management",
    "dora-ict-risk-management-articles-5-16",
    "dora-regulation-article-13-learning-evolving"
  ],
  "primary_citations_count": 8
}