Skip to main content
Category: Regulatory Frameworks

Joint RTS on Subcontracting

Also known as: Subcontracting RTS, Joint Regulatory Technical Standards on subcontracting ICT services, DORA Subcontracting RTS, Joint draft RTS on subcontracting ICT services supporting critical or important functions
Simply put

The Joint RTS on Subcontracting is a set of European regulatory technical standards that spell out the conditions financial firms must meet when the ICT services they rely on are handed off, in whole or in part, to subcontractors. It focuses specifically on subcontracted ICT services that support the firm's critical or important functions, rather than all outsourcing generally. It also sets out contractual terms and assessment steps firms are expected to apply before and during such arrangements.

Formal definition

The Joint RTS on Subcontracting are Regulatory Technical Standards developed under the EU's Digital Operational Resilience Act (DORA) that set out requirements and conditions for the use of subcontracted ICT services supporting critical or important functions. Adopted as part of a broader package of DORA RTS (with a public consultation running until 4 March 2024), they specify the elements financial entities must assess when ICT services provided by a direct third-party provider are further subcontracted, and prescribe mandatory contractual provisions governing such subcontracting chains. Scope is limited to ICT services underpinning critical or important functions and to the subcontracting dimension; the RTS build on, and should be read alongside, the separate DORA Policy on the use of ICT services, and do not by themselves constitute a complete third-party risk framework covering financial, ESG, or non-ICT operational risk. Reporting indicates the finally adopted version reflected a narrowed approach to monitoring obligations across the subcontracting chain relative to earlier drafts; practitioners should confirm the specific in-scope elements, contractual provisions, and monitoring expectations against the enacted text, as these evolved through the consultation and adoption process. Applicability is jurisdictionally bounded to EU financial entities within DORA's remit.

Why it matters

Financial firms rarely consume ICT services in isolation from a broader supply chain. A cloud platform, managed security service, or core banking application delivered by a direct third-party provider is frequently built upon further layers of subcontractors, whose failures, outages, or control gaps can propagate back to the firm even though the firm has no direct contract with them. The Joint RTS on Subcontracting matters because it brings this fourth-party and Nth-party dimension into DORA's regulatory scope, requiring EU financial entities to assess and contractually govern how ICT services supporting critical or important functions are handed off down the chain, rather than treating the direct provider relationship as the boundary of accountability.

The RTS is also significant for what it deliberately narrows. Reporting on the European Commission's adopted version describes a partial retreat on monitoring obligations across the subcontracting chain relative to earlier drafts. For practitioners, this means the enacted text may impose lighter continuous-monitoring expectations than some firms had prepared for during consultation, which changes the calibration of program design. Because these elements evolved through the consultation period that ran until 4 March 2024 and the subsequent adoption, practitioners should confirm the specific in-scope elements, mandatory contractual provisions, and monitoring expectations against the enacted text rather than relying on earlier draft assumptions.

Finally, the RTS should not be mistaken for a complete third-party risk framework. Its scope is bounded to ICT services underpinning critical or important functions and to the subcontracting dimension specifically. It does not address financial, ESG, or non-ICT operational risk, and it builds on, rather than replaces, the separate DORA Policy on the use of ICT services. Firms treating the Subcontracting RTS as their whole approach to Nth-party risk would leave material gaps.

Who it's relevant to

Third-party and ICT risk teams at EU financial entities
Teams within DORA's remit are the primary audience, as the RTS directly governs how they assess subcontracted ICT services supporting critical or important functions and how far down the chain their oversight must extend. They will need to map subcontracting layers beyond the direct provider and calibrate monitoring to the enacted, and reportedly narrowed, obligations.
Procurement and vendor contracting functions
Because the RTS prescribes mandatory contractual provisions on subcontracting, procurement and legal teams responsible for ICT contracts must ensure those clauses are incorporated into agreements with direct providers and flow through to subcontracted arrangements. They should confirm the specific required provisions against the adopted text.
Compliance and regulatory affairs specialists
Compliance functions tracking DORA implementation need to distinguish the Subcontracting RTS from the broader DORA RTS package and from the separate Policy on the use of ICT services, and to account for the changes between draft and adopted versions, particularly the reported partial retreat on chain-wide monitoring.
ICT service providers and their subcontractors serving EU financial clients
Direct third-party providers and their subcontractors may face contractual and assessment expectations passed down by financial-entity clients seeking to satisfy the RTS. Understanding which provisions apply to subcontracted ICT services supporting critical or important functions helps providers anticipate client demands, though the RTS's direct legal obligations fall on the financial entities themselves.

Inside Joint RTS on Subcontracting

Scope of ICT Subcontracting Covered
The Joint RTS on Subcontracting is intended to specify how financial entities should manage arrangements where an ICT third-party service provider subcontracts ICT services that support critical or important functions. It typically focuses on subcontracting chains rather than the direct third-party relationship alone, meaning it addresses fourth-party and lower-tier (Nth-party) dependencies. It does not, by itself, cover non-ICT subcontracting or supplier arrangements outside the supported function's criticality determination.
Conditions for Subcontracting
The RTS is designed to set out the conditions under which subcontracting of ICT services supporting critical or important functions may occur, including elements the financial entity should assess before and during the arrangement. This is an assessment and governance obligation on the financial entity and its direct provider; it is not an outright prohibition on subcontracting, and it does not guarantee that risks in the subcontracting chain are eliminated.
Chain Monitoring and Oversight Expectations
The framework contemplates ongoing oversight of the subcontracting chain rather than a single onboarding check. This distinguishes point-in-time due diligence from continuous monitoring, and it recognizes that visibility beyond the first tier can be limited. The extent of expected oversight typically depends on the criticality of the function the subcontracted service supports.
Contractual and Documentation Elements
The RTS is associated with contractual arrangements between the financial entity and its direct ICT provider that should address how subcontracting is permitted, documented, and reflected in the register of information. These provisions concern the direct contractual relationship as the mechanism to reach down the chain; the financial entity generally has no direct contract with lower-tier subcontractors.
Regulatory Anchoring
The RTS is a regulatory technical standard developed in the context of the EU's Digital Operational Resilience Act (DORA) framework by the European Supervisory Authorities. Its applicability is therefore jurisdiction- and sector-specific, applying to in-scope financial entities operating under that regime rather than serving as a globally binding standard.

Common questions

Answers to the questions practitioners most commonly ask about Joint RTS on Subcontracting.

Do the Joint RTS on Subcontracting cover every third party an organization contracts with?
No. This is a common misconception. The Joint RTS on Subcontracting focus on subcontracting arrangements associated with ICT services supporting critical or important functions within the DORA framework. They do not purport to govern the full universe of third-party relationships an organization maintains, and they should not be treated as a general-purpose third-party risk management standard. Relationships that fall outside the defined scope, such as suppliers unconnected to ICT services supporting critical or important functions, typically remain governed by an organization's broader TPRM policies and other applicable requirements rather than by these RTS.
Do the RTS mean a financial entity only needs to assess its direct ICT third-party provider and not the subcontractors beneath it?
No, and this is where direct third-party risk and Nth-party risk are often conflated. The RTS are specifically concerned with subcontracting chains, meaning the arrangements extending below the direct ICT third-party service provider. The intent is that oversight and risk considerations do not stop at the first contractual tier where subcontracting supports critical or important functions. That said, the depth of visibility achievable in practice is often constrained the further one moves down the chain, so the RTS should not be read as a guarantee of complete visibility across all subcontracting tiers.
What contractual arrangements typically fall within the scope of these RTS?
The RTS generally apply to subcontracting arrangements that support the provision of ICT services underpinning critical or important functions. Scoping therefore usually begins with identifying which ICT services support such functions, then tracing where subcontracting occurs within those service chains. Arrangements unrelated to critical or important functions typically fall outside the specific expectations of these RTS, though organizations may still apply internal controls to them. Precise scoping depends on how the organization has classified its functions and services under the broader DORA framework.
How should conditions for subcontracting be reflected in contractual terms?
In many programs, the expectations translate into contractual provisions addressing when and how subcontracting of relevant ICT services is permitted, requirements for the direct provider to remain accountable, notification or approval mechanisms for material subcontracting changes, and rights that allow the financial entity to monitor and, where appropriate, respond to the subcontracting arrangement. The specific drafting depends on the risk profile of the service and the function it supports. Contractual language alone establishes obligations but does not by itself verify that subcontractors meet them, so it is typically paired with ongoing monitoring.
What monitoring is expected once a subcontracting chain is in place?
Because point-in-time due diligence at onboarding can become stale as subcontracting arrangements change, the expectations generally extend to ongoing oversight rather than a single assessment. This can include tracking material changes to the subcontracting chain, maintaining awareness of which subcontractors support critical or important functions, and reassessing risk when the chain is modified. The practical depth of monitoring often diminishes at lower tiers of the chain, and organizations typically rely in part on information supplied by the direct provider, which is a limitation to account for in program design.
How do these RTS interact with an organization's existing register of information and TPRM processes?
In practice, organizations often integrate the subcontracting expectations into their existing arrangements rather than building a parallel process, for example, by ensuring that relevant subcontracting information relating to ICT services supporting critical or important functions is captured within the register of information maintained under the broader framework, and by aligning subcontracting oversight with established due diligence and monitoring workflows. The RTS address a specific slice of third-party arrangements, so they typically supplement, rather than replace, an organization's wider TPRM and supply chain risk practices, including those covering financial, operational, or geopolitical risk that fall outside the RTS focus.

Common misconceptions

The Joint RTS on Subcontracting bans or prevents ICT providers from subcontracting critical services.
The RTS is generally framed to set conditions and governance expectations for subcontracting, not to prohibit it. It addresses how such arrangements should be assessed, documented, and monitored, and it does not by itself eliminate the risks present in a subcontracting chain.
Because the direct ICT provider is contractually bound, the financial entity has full visibility and control over all lower-tier subcontractors.
The financial entity typically contracts only with its direct third party, and visibility into fourth-party and Nth-party layers is often limited and mediated through that direct relationship. The RTS relies on contractual and monitoring mechanisms to extend oversight, but this does not equate to direct control over each subcontractor.
The RTS applies broadly to all suppliers and subcontractors, as a global standard.
The RTS is tied to the EU DORA framework and is focused on ICT subcontracting that supports critical or important functions for in-scope financial entities. It does not universally govern non-ICT suppliers or apply as a global cross-sector requirement, so applicability varies by jurisdiction and entity type.

Best practices

Distinguish between your direct ICT third parties and their subcontractors, and maintain documentation that reflects the subcontracting chain for services supporting critical or important functions rather than only the first-tier relationship.
Calibrate the depth of assessment and oversight to the criticality of the supported function, applying more rigorous conditions and monitoring where a subcontracted ICT service underpins a critical or important function.
Embed subcontracting conditions in the contract with your direct ICT provider, since that direct contractual relationship is typically the primary mechanism for reaching visibility and expectations into lower tiers where you hold no direct contract.
Treat onboarding due diligence and ongoing monitoring as separate obligations, recognizing that point-in-time assessments of a subcontracting chain can become stale and that continuous oversight is generally expected.
Acknowledge and document the limits of visibility beyond the first tier, and define what falls outside your assurance where independent verification of lower-tier subcontractors is not available.
Confirm the applicability of the RTS to your specific entity and jurisdiction under the DORA framework rather than assuming it governs all suppliers or applies as a global standard.
Promotional banner for the Penetration Report Template Kit