Joint RTS on Subcontracting
The Joint RTS on Subcontracting is a set of European regulatory technical standards that spell out the conditions financial firms must meet when the ICT services they rely on are handed off, in whole or in part, to subcontractors. It focuses specifically on subcontracted ICT services that support the firm's critical or important functions, rather than all outsourcing generally. It also sets out contractual terms and assessment steps firms are expected to apply before and during such arrangements.
The Joint RTS on Subcontracting are Regulatory Technical Standards developed under the EU's Digital Operational Resilience Act (DORA) that set out requirements and conditions for the use of subcontracted ICT services supporting critical or important functions. Adopted as part of a broader package of DORA RTS (with a public consultation running until 4 March 2024), they specify the elements financial entities must assess when ICT services provided by a direct third-party provider are further subcontracted, and prescribe mandatory contractual provisions governing such subcontracting chains. Scope is limited to ICT services underpinning critical or important functions and to the subcontracting dimension; the RTS build on, and should be read alongside, the separate DORA Policy on the use of ICT services, and do not by themselves constitute a complete third-party risk framework covering financial, ESG, or non-ICT operational risk. Reporting indicates the finally adopted version reflected a narrowed approach to monitoring obligations across the subcontracting chain relative to earlier drafts; practitioners should confirm the specific in-scope elements, contractual provisions, and monitoring expectations against the enacted text, as these evolved through the consultation and adoption process. Applicability is jurisdictionally bounded to EU financial entities within DORA's remit.
Why it matters
Financial firms rarely consume ICT services in isolation from a broader supply chain. A cloud platform, managed security service, or core banking application delivered by a direct third-party provider is frequently built upon further layers of subcontractors, whose failures, outages, or control gaps can propagate back to the firm even though the firm has no direct contract with them. The Joint RTS on Subcontracting matters because it brings this fourth-party and Nth-party dimension into DORA's regulatory scope, requiring EU financial entities to assess and contractually govern how ICT services supporting critical or important functions are handed off down the chain, rather than treating the direct provider relationship as the boundary of accountability.
The RTS is also significant for what it deliberately narrows. Reporting on the European Commission's adopted version describes a partial retreat on monitoring obligations across the subcontracting chain relative to earlier drafts. For practitioners, this means the enacted text may impose lighter continuous-monitoring expectations than some firms had prepared for during consultation, which changes the calibration of program design. Because these elements evolved through the consultation period that ran until 4 March 2024 and the subsequent adoption, practitioners should confirm the specific in-scope elements, mandatory contractual provisions, and monitoring expectations against the enacted text rather than relying on earlier draft assumptions.
Finally, the RTS should not be mistaken for a complete third-party risk framework. Its scope is bounded to ICT services underpinning critical or important functions and to the subcontracting dimension specifically. It does not address financial, ESG, or non-ICT operational risk, and it builds on, rather than replaces, the separate DORA Policy on the use of ICT services. Firms treating the Subcontracting RTS as their whole approach to Nth-party risk would leave material gaps.
Who it's relevant to
Inside Joint RTS on Subcontracting
Common questions
Answers to the questions practitioners most commonly ask about Joint RTS on Subcontracting.