What Commission Delegated Regulation (EU) 2025/532 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the elements a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions requires
This DORA regulatory technical standard sets the elements a financial entity must determine and assess before and during the subcontracting of ICT services that support critical or important functions, including due diligence on the ICT provider's ability to oversee subcontractors, risk assessment of the subcontracting chain, equivalent access and audit rights down the chain, and termination rights where unapproved material changes occur; it supplements DORA Article 30(5).
Pillar: Cybersecurity · Authority: European Commission · Version: 1.0.0 · Last updated:
Primary source: https://eur-lex.europa.eu/eli/reg_del/2025/532/oj/eng
SHA-256 integrity: 715e33c4a6b30157693f3e4665d5119334757bde7a69150e4ef09ad972ed1217
Primary Citations — 8 traced to source
- COMMISSION DELEGATED REGULATION (EU) 2025/532 of 24 March 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions
- Article 1: financial entities shall take into account their size and their overall risk profile
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eu-dora-rts-subcontracting-ict-2025-532.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eu-dora-rts-subcontracting-ict-2025-532.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eu-dora-rts-subcontracting-ict-2025-532
- Back to registry: Browse all 10,085 compliance nodes