DORA turns the ICT contracts of financial entities, and of the providers that serve them, into regulated documents. Three certification programmes train the lawyers who draft, review and negotiate them, each ending in a certificate the lawyer can show clients.
Verifiable certificateSeats from 2 lawyersCard or bank transfer with POUpdated October 2026
Most of the legal work under the Digital Operational Resilience Act (Regulation (EU) 2022/2554) sits in its rules on ICT third-party risk (Articles 28 to 44), which work largely through contracts. A firm meets them from one of two sides.
Advising a financial entity
The entity is bound directly (Article 2). Its contracts, its register and its exit plans are its own obligations, and its competent authority can ask to see them.
Advising an ICT third-party service provider
The provider is not bound directly: the requirements reach it through the contracts its financial clients must sign (Articles 28 to 30). Only designated CTPPs come under EU oversight (Articles 31 to 44).
Contract provisions
Article 30(2) lists nine elements every ICT services contract must contain. Article 30(3) adds six more where the service supports a critical or important function.
DORA has applied since 17 January 2025 (Article 64), to contracts signed before that date as much as to new ones: the existing portfolio has to be brought up to the Article 30 standard.
Termination rights apply to every contract (Article 28(7)); exit strategies to critical or important functions (Article 28(8)). Subcontracting of those functions follows Delegated Regulation (EU) 2025/532.
Taught inLegal & Contract Teams, module 6
Intra-group and non-EU arrangements
Intra-group ICT arrangements fall under the same third-party rules as external ones. Non-EU providers are allowed, under conditions that shape the drafting, the subcontracting chain and the choice of governing law.
Taught inLegal & Contract Teams, module 7
Penalties, enforcement and liability
Article 50 leaves administrative penalties and remedial measures to each Member State. Designated critical ICT third-party providers (CTPPs) face a separate oversight regime (Articles 31 to 44).
Taught inLegal & Contract Teams, module 2
Supervisory engagement and evidence
The management body approves the policies that govern ICT risk (Article 5), and the competent authority can request the full register of information along with any information it deems necessary (Article 28(3)).
Article 30 is the core of the legal work. Every contract on the use of ICT services must contain nine elements (Article 30(2)), and a contract for services supporting a critical or important function six more (Article 30(3)). The full contract, service level agreements included, is documented in one written document (Article 30(1)).
Art. 30(2)(a)A clear and complete description of all functions and ICT services, stating whether subcontracting of a service supporting a critical or important function is permitted, and on what conditions.Every ICT contract
Art. 30(2)(b)The regions or countries where the services are provided and the data processed and stored, with advance notice to the financial entity of any planned change of location.Every ICT contract
Art. 30(2)(c)Provisions on the availability, authenticity, integrity and confidentiality of data, personal data included.Every ICT contract
Art. 30(2)(d)Access, recovery and return of the data in an easily accessible format if the provider becomes insolvent, enters resolution or stops its business, and on termination.Every ICT contract
Art. 30(2)(e)Service level descriptions, with their updates and revisions.Every ICT contract
Art. 30(2)(f)Assistance when an ICT incident related to the service occurs, at no additional cost or at a cost determined in advance.Every ICT contract
Art. 30(2)(g)Full cooperation with the competent authorities and resolution authorities of the financial entity, including the persons they appoint.Every ICT contract
Art. 30(2)(h)Termination rights and the related minimum notice periods, in line with the expectations of competent and resolution authorities.Every ICT contract
Art. 30(2)(i)The conditions for the provider's participation in the financial entity's ICT security awareness programmes and digital operational resilience training (Article 13(6)).Every ICT contract
Art. 30(3)(a)Full service level descriptions with precise quantitative and qualitative performance targets, so the financial entity can monitor the service and act without undue delay when levels are missed.Critical or important function
Art. 30(3)(b)Notice periods and reporting obligations, including notice of any development that might materially affect the provider's ability to deliver the service.Critical or important function
Art. 30(3)(c)Business contingency plans that the provider implements and tests, and ICT security measures, tools and policies giving an appropriate level of security.Critical or important function
Art. 30(3)(d)Participation and full cooperation in the financial entity's threat-led penetration testing (TLPT, Articles 26 and 27).Critical or important function
Art. 30(3)(e)Ongoing monitoring of performance: unrestricted rights of access, inspection and audit for the financial entity, a third party it appoints and the competent authority, with alternative assurance levels where other clients' rights are affected.Critical or important function
Art. 30(3)(f)Exit strategies, with a mandatory adequate transition period during which the service continues while the financial entity migrates to another provider or in-house.Critical or important function
Summarised from the text of Regulation (EU) 2022/2554, Article 30. A microenterprise may agree that its access, inspection and audit rights are delegated to an independent third party appointed by the provider (Article 30(3), last subparagraph), and the parties must consider standard contractual clauses developed by public authorities (Article 30(4)).
The DORA for Legal & Contract Teams programme takes each element in turn, and its Article 30 clause library gives preferred wording, a fallback position and red-line notes for every one.
DORA courses for lawyers, one per role in the firm
Each programme is self-paced and ends with a timed certification exam, marked on our server. A lawyer who passes receives a certificate with a unique ID and a public verification page. The first lesson of each is free to read.
Associates and counsel
DORA for Legal & Contract Teams
The lawyers who draft, review and negotiate DORA contracts and advise on the regime around them.
Advanced2.5 hours8 modulesPass mark 75%
The 8 modules
DORA as Law: Why Legal Owns So Much of It
Penalties, Enforcement & Liability
Article 30: The Mandatory Contractual Clauses
Re-Papering the Legacy Portfolio
The Register of Information as a Legal Artefact
Outsourcing, Sub-Outsourcing & Exit Law
Intra-Group Arrangements, Non-EU Exposure & Governing Law
From two seats, every seat is billed at the discount of the tier the seat count reaches. One licence covers one programme, so a practice group that trains partners and associates on different programmes takes one licence for each. Prices exclude VAT.
Programme
1 person
2-4 seats
5-9 seats
10-24 seats
25+ seats
DORA for Legal & Contract Teams
€199
€179.10-10%
€159.20-20%
€139.30-30%
€119.40-40%
Certified DORA Advisor (CDA)
€149
€134.10-10%
€119.20-20%
€104.30-30%
€89.40-40%
Certified DORA Contract Manager (CDCM)
€59
€53.10-10%
€47.20-20%
€41.30-30%
€35.40-40%
DORA for Legal & Contract Teams Track
€299
€269.10-10%
€239.20-20%
€209.30-30%
€179.40-40%
Example: a DORA practice group of 12
2 × Certified DORA Advisor (CDA) (partners leading engagements, €134.10 per seat)
€268.20
6 × DORA for Legal & Contract Teams (associates and counsel, €159.20 per seat)
€955.20
4 × Certified DORA Contract Manager (CDCM) (paralegals and contract teams, €53.10 per seat)
€212.40
Three licences, excl. VAT
€1,435.80
€292.20 less than 12 individual purchases.
Pay by card, with a VAT invoice in the firm's name, or by bank transfer against our invoice with your PO number. The seat manager receives a private page to add lawyers, reassign seats and export the training record.
“This certification is to the point through providing the necessary background information together with practical examples and useful tips.”
Laurent GK, ConsultantVerified certified learnerCertified DORA Advisor (CDA)
The certificates are private training credentials issued by Cryptaguard SRL (DORA Academy). They attest to a passed exam, not to any legal conclusion, and they are not a qualification issued by a regulator or a bar.
Questions lawyers and firms ask
Is there a DORA certification for lawyers?
Yes. DORA for Legal & Contract Teams is a certification programme written for counsel: it ends in a timed exam and, for those who pass, a certificate with a public verification page. DORA itself creates no qualification for lawyers or anyone else, so DORA certifications, ours included, are private training credentials.
What DORA training does a lawyer need?
DORA imposes no training on outside counsel: Article 13(6) requires financial entities to train their own staff and, where appropriate, to include their ICT third-party service providers. What a lawyer needs is the competence clients pay for: the Article 30 clauses for every contract and for critical or important functions, termination and exit under Article 28, the Register of Information, and how the competent authority will read all of it.
Can in-house counsel take these programmes?
Yes. DORA for Legal & Contract Teams is written for the legal function of a financial entity as much as for outside counsel, and a legal department can buy seats in the same way as a firm.
Which programme should each lawyer take?
Associates and counsel who draft, review and negotiate DORA contracts take DORA for Legal & Contract Teams. The partner who leads a client's DORA engagement beyond the contracts (scope, programme, evidence file) takes the Certified DORA Advisor. Paralegals, contract managers and junior associates working on a re-papering exercise take the Certified DORA Contract Manager. The lawyer who leads the contract practice can take the DORA for Legal & Contract Teams Track, which adds the contract deep-dives to the programme. A practice group can combine them: each programme is its own licence, priced on its own seat count.
Does it count towards our continuing professional development hours?
Each bar sets its own rules on which training counts, so check with yours. The DORA Academy is not accredited by a bar association. If your bar asks for evidence, the public verification page of each certificate shows the programme, the date and the result, and the programme page lists the modules and the study time.
Is the training specific to one jurisdiction?
No. DORA is a Regulation, directly applicable in every Member State, and so are its technical standards: the programmes teach the EU text, identical everywhere. Where the outcome depends on national law, as with administrative penalties under Article 50, the course says so.
Do our lawyers need to share any client information?
No. The courses are self-paced lessons, quizzes and an exam. A seat needs only the lawyer's email address, for the access link; each lawyer enters their own name for the certificate. Nothing about your clients is asked for.
In which language are the courses?
In English: the lessons, the exams and the certificates.
How long does it take?
Between 2 hours and 2.5 hours of study per programme, at each lawyer's own pace. There is no deadline and access does not expire.
Can we pay by bank transfer and quote our PO number?
Yes, whatever the number of seats. You receive a quote immediately and our invoice within one business day, with your PO number on it; the seats are activated when the transfer is received. Card payment is also available, with a VAT invoice in the firm's name. Prices are shown excluding VAT.
What happens to a certificate when a lawyer leaves the firm?
It stays valid: it is personal and records an exam that was passed. If someone leaves before finishing, the seat manager removes them and gives the seat to someone else.
Is there reference material we can cite in advice?
The RTS/ITS Professional Reference Dossier, on the DORA for Professionals page, gives one sheet per technical standard (legal basis, who it applies to, obligations, deadlines, EUR-Lex reference) to cite in opinions and memos. It is sold separately from the training.