Skip to main content
Category: Supply Chain Mapping

Subcontracting of ICT Services

Also known as: ICT Subcontracting, Subcontracting of ICT Services Supporting Critical or Important Functions
Simply put

Subcontracting of ICT services occurs when a company's direct technology provider hands off part of the service to one or more further providers, rather than delivering it entirely itself. This means the organization relying on the service depends not only on its direct provider but also on subcontractors it may not have a contract with. In the EU financial sector, this arrangement is subject to specific regulatory expectations under the Digital Operational Resilience Act (DORA).

Formal definition

Under DORA, subcontracting of ICT services arises when an ICT third-party service provider engages one or more further providers (ICT subcontractors) to deliver part of an ICT service supplied to a financial entity. It is a form of Nth-party (fourth-party and beyond) dependency, distinct from the direct third-party relationship between the financial entity and its ICT provider: the financial entity typically has no direct contractual privity with subcontractors further down the chain. The Joint Regulatory Technical Standards (RTS) developed to supplement DORA set out requirements and conditions specifically for the use of subcontracted ICT services supporting critical or important functions (CIFs); arrangements that do not support CIFs may fall outside the scope of these heightened conditions. The scope of this term is confined to the subcontracting relationship and its governance (for example contractual chain-of-service requirements, oversight, and monitoring of subcontractors), and it does not by itself address the broader operational resilience, information security, or concentration-risk assessment of the direct ICT provider. These requirements are jurisdiction- and sector-specific, applying to in-scope EU financial entities and their ICT providers, and should not be assumed to apply globally or to non-financial sectors.

Why it matters

When a financial entity contracts with an ICT provider, the service it ultimately receives may be delivered in part by subcontractors with which the entity has no direct contractual relationship. This creates a fourth-party and Nth-party dependency: the organization relies on providers it may not directly govern, monitor, or even fully identify. A disruption, security failure, or performance problem several links down the chain can still impair the ICT service the financial entity depends on, even though the entity's contractual leverage extends only to its direct provider. This gap between where dependency exists and where contractual control ends is the central concern the term addresses.

Under the Digital Operational Resilience Act (DORA), this arrangement is subject to specific regulatory expectations for in-scope EU financial entities. The Joint Regulatory Technical Standards developed to supplement DORA set out requirements and conditions specifically for subcontracted ICT services supporting critical or important functions (CIFs). This reflects a regulatory judgment that heightened oversight is warranted where the subcontracted service underpins functions whose disruption could materially affect the entity's operations. Arrangements that do not support CIFs may fall outside these heightened conditions, so the significance of a given subcontracting chain depends on what function it supports.

It is important to keep the scope of this term contained. Governing the subcontracting relationship, through chain-of-service contractual requirements, oversight, and monitoring, does not by itself resolve the broader operational resilience, information security, or concentration-risk questions attached to the direct ICT provider. These requirements are jurisdiction- and sector-specific, applying to in-scope EU financial entities and their ICT providers, and should not be assumed to apply globally or to non-financial sectors.

Who it's relevant to

EU financial entities in scope of DORA
Banks, insurers, investment firms, and other in-scope financial entities must account for subcontracting when their ICT services supporting critical or important functions are delivered in part by providers below the direct-contract tier. They are responsible for ensuring appropriate governance of these chains even though contractual privity typically ends at the direct provider.
Third-party risk and vendor management teams
Professionals managing ICT provider relationships need to identify where direct providers subcontract, distinguish arrangements that support critical or important functions from those that do not, and put in place oversight and monitoring mechanisms that reach beyond the first tier. This work centers on the subcontracting relationship and does not by itself cover the direct provider's broader resilience or security assessment.
Compliance and legal functions
Teams responsible for DORA readiness must translate the Joint Regulatory Technical Standards on subcontracting into contractual and governance requirements, including chain-of-service provisions passed down through direct providers. They should note that these requirements are jurisdiction- and sector-specific and apply to in-scope EU financial entities rather than globally.
ICT third-party service providers to financial entities
Providers serving in-scope financial entities may need to disclose and manage their own subcontractors, and to enable the oversight and monitoring their financial-entity clients require, particularly where the subcontracted service supports critical or important functions.

Inside Subcontracting of ICT Services

Direct ICT Service Provider (Third Party)
The entity with which the organization holds a direct contractual relationship for the provision of information and communication technology services. This third party is the primary accountable party under the contract, even where it relies on others to deliver portions of the service.
ICT Subcontractor (Fourth Party / Nth Party)
An entity engaged by the direct ICT service provider to perform some part of the contracted service. From the contracting organization's perspective this is a fourth-party (or, where further chains exist, Nth-party) relationship, meaning there is typically no direct contract and correspondingly reduced visibility and control.
Chain of Reliance
The layered dependency created when subcontracting extends across multiple tiers. Each additional tier can introduce operational, security, geographic, and concentration considerations that may not be apparent from the direct contract alone, and visibility often diminishes with each tier beyond the first.
Flow-Down Obligations
Contractual provisions intended to ensure that requirements imposed on the direct provider (for example, security, confidentiality, audit, or continuity expectations) are passed down to subcontractors. Their practical effectiveness depends on enforceability and the provider's willingness and ability to impose and monitor them at lower tiers.
Subcontracting Notification and Consent Rights
Terms defining whether and how the provider must inform the organization of, or seek approval for, the use, addition, or replacement of subcontractors for material portions of the service. The scope of what qualifies as 'material' typically varies by risk tier and by contract.
Concentration and Fourth-Party Visibility
The assessment of whether multiple providers rely on the same underlying subcontractor, which can create concentration risk or a shared single point of failure that is not visible when each direct relationship is examined in isolation.

Common questions

Answers to the questions practitioners most commonly ask about Subcontracting of ICT Services.

Does approving a direct ICT provider mean the organization has also assessed its subcontractors?
No. Approving a direct provider (the third party) addresses that contractual relationship, but the subcontractors it engages to deliver the service are fourth parties (or further, Nth parties). Their controls, financial stability, geographic exposure, and security posture are typically not covered by the assessment of the direct provider unless the program deliberately extends visibility and due diligence into those tiers. In many programs, visibility beyond the first tier is limited, so the assumption that first-tier approval cascades downward is often unfounded.
Is a provider's attestation that its subcontractors meet security requirements the same as independent verification?
No. An attestation is a self-reported representation by the provider, not independent validation of the subcontractor's controls. Even where a provider passes those obligations down its supply chain contractually, an attestation does not confirm that the subcontractor actually operates the stated controls. Independent verification, such as a report from an external examiner or an on-site assessment, provides a different level of assurance, and depending on the risk tier a program may treat attestations as insufficient for critical or material subcontracted services.
How can an organization gain visibility into subcontractors it has no direct contract with?
Because the organization typically has no contractual relationship with fourth or Nth parties, visibility usually depends on obligations placed on the direct provider. In many programs this includes contractual rights to a current list of material subcontractors, prior notification or approval before subcontracting critical functions, flow-down of security and operational requirements, and access to relevant assessment evidence. The depth of visibility that can be achieved often depends on the provider's cooperation and the leverage available at the risk tier in question.
When should notification or approval rights over subcontractors be required?
Requirements are often calibrated to the criticality or materiality of the service. For subcontractors supporting critical or material ICT functions, many programs seek prior notification and, in some cases, approval or objection rights before the provider engages or changes a subcontractor. For lower-tier services, a periodic disclosure of the subcontractor list may be considered proportionate. The appropriate threshold depends on the risk tier, the nature of the data or function involved, and applicable regulatory expectations, which can vary across regions and sectors.
How should concentration exposure across subcontracted ICT services be monitored?
Subcontracting can create concentration that is not visible at the direct-provider level, for example, multiple approved providers relying on the same underlying subcontractor, hosting environment, or geographic location. Monitoring typically involves mapping known subcontractor dependencies across the portfolio to identify shared reliance that could constitute a concentration risk or a single point of failure. This mapping is often incomplete because it depends on disclosure from providers, and it should be distinguished from single-source dependency, which concerns the absence of alternatives rather than shared underlying reliance.
What are the practical limitations of relying on point-in-time subcontractor assessments?
A point-in-time assessment of a subcontractor reflects conditions at the moment it was performed and can become stale as subcontractors change controls, ownership, location, or their own downstream dependencies. Because assessments frequently rely on information relayed through the direct provider, they may also lag behind operational changes. Many programs address this by combining periodic reassessment with ongoing monitoring signals and contractual notification obligations, while recognizing that neither approach guarantees continuous, complete visibility into subcontracted tiers.

Common misconceptions

Because there is no direct contract with a subcontractor, the organization bears no responsibility for risks arising at that tier.
The absence of a direct contract limits direct control and visibility, but it does not necessarily eliminate the organization's exposure or, depending on jurisdiction and sector, its accountability for outcomes affecting its services. Responsibility is typically managed through the direct provider via flow-down obligations rather than removed.
Third-party due diligence on the direct ICT provider automatically covers its subcontractors.
Assessment of the direct provider centers on that contractual relationship and often does not extend, with the same depth, into fourth-party or Nth-party tiers. Subcontractor risk generally requires separate identification and, where feasible, targeted review; visibility beyond the first tier is frequently limited.
A provider's attestation that its subcontractors meet required controls is equivalent to independent verification of those controls.
An attestation is a self-reported representation by the provider. It is not the same as independent verification, and its reliability depends on the provider's own oversight of its subcontractors, which the organization may have limited ability to validate directly.

Best practices

Require contractual flow-down of material security, confidentiality, continuity, and audit obligations to subcontractors, and confirm the direct provider has the mechanisms to enforce and monitor them at lower tiers.
Establish notification and, for higher-risk services, prior-consent rights covering the addition, replacement, or material use of subcontractors, calibrating what triggers these rights to the risk tier of the service.
Map the subcontracting chain for critical or high-risk ICT services to identify fourth-party and Nth-party dependencies rather than relying solely on review of the direct provider.
Assess for concentration risk and shared single points of failure by checking whether multiple providers depend on the same underlying subcontractor.
Treat provider attestations about subcontractors as self-reported inputs, and where the risk tier warrants, seek independent evidence or the right to obtain it rather than relying on attestation alone.
Refresh subcontractor visibility on an ongoing basis, since chains change over time and point-in-time reviews can become stale, and account for differing regulatory expectations across the jurisdictions where subcontractors operate.
Promotional banner for the Penetration Report Template Kit