The finding is generally transaction-ready.
Record the assumptions in the data room and reflect them in the appropriate warranty or condition.
DORA in a FinTech acquisition: ICT contracts, outsourcing, registers, FMA checks and SPA closing conditions.
BRANDAUER Rechtsanwälte
Salzburg law firm for corporate, company and transaction law
Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.
A buyer of a FinTech, payment institution or ICT-heavy regulated target must review more than software and licences. Under DORA, digital operational resilience, ICT providers, outsourcing registers and incident processes become transaction issues.
This post deliberately separates DORA from general cyber due diligence. It focuses on deal questions: which ICT contracts are critical, which subcontracting chains exist and what must be resolved before signing or closing.
Two questions show whether the point needs deeper review before signing or closing.
Already know you want to get in touch? Go straight to the enquiry form.
If the answer is yes, the point belongs in the deal risk list.
Record the assumptions in the data room and reflect them in the appropriate warranty or condition.
If documents or responsibilities are missing, the buyer should not move the point into a vague post-closing list. Clarify risk, price effect and contract protection before the next milestone.
DORA is not merely an IT standard. Regulation (EU) 2022/2554 requires financial undertakings to manage ICT risk in a structured way. In an acquisition, this affects the data room, risk matrix and the question whether the target controls its critical functions.
The post on regulated targets covers FMA and licence issues more broadly. DORA is the narrower review of digital operational resilience.
Buyers should not sort critical ICT providers only by cost and term. Audit rights, sub-outsourcing, place of performance, data access, exit scenarios and realistic provider replacement matter.
The post on source code, licences and data remains relevant. DORA adds the regulatory layer for ongoing operational stability.
The overview separates finding, review and agreement consequence.
| DORA point | Deal question | Agreement consequence |
|---|---|---|
| ICT register Are critical providers fully recorded? | Data room request and warranty | |
| Sub-outsourcing Are approval chains involved? | Condition or indemnity | |
| Exit Is provider replacement realistic? | Plan, cost and timing rule |
The concrete drafting depends on the data room, deal structure and specialist advice.
Practical point: This point should not be phrased as a post-closing task without responsibility. If it can affect price, approval or liability, it belongs in the data room and SPA before closing.
If key documents are missing, DORA should not become a vague post-closing task. Depending on the finding, the SPA needs a condition, a specific warranty or a holdback for remediation.
The post on closing conditions explains how conditions to completion should be drafted.
Cybersecurity due diligence asks about technical security and NIS2 interfaces. DORA additionally asks about governance, registers, testing and control of ICT third-party providers.
Keeping the two workstreams separate avoids duplication and blind spots. A FinTech deal needs both, but with different questions and owners.
Not every contract has the same relevance. Critical ICT services require special review and contractual protection.
That depends on the target and findings. Critical gaps may justify a closing condition or specific warranty.
No. DORA adds regulatory governance, outsourcing and resilience to the technical review.
Direct follow-up for the deeper review.
Direct follow-up for the deeper review.
Direct follow-up for the deeper review.
Direct follow-up for the deeper review.
Direct follow-up for the deeper review.
When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg
Phone
+43 662 6280000