Deal
Due diligence

DORA in a FinTech acquisition: ICT contracts, outsourcing and FMA closing checks

DORA in a FinTech acquisition: ICT contracts, outsourcing, registers, FMA checks and SPA closing conditions.

BRANDAUER Rechtsanwälte
Your law firm

BRANDAUER Rechtsanwälte

Salzburg law firm for corporate, company and transaction law

Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.

7 August 2026 · Mag. Bernhard Brandauer, Rechtsanwalt

A buyer of a FinTech, payment institution or ICT-heavy regulated target must review more than software and licences. Under DORA, digital operational resilience, ICT providers, outsourcing registers and incident processes become transaction issues.

This post deliberately separates DORA from general cyber due diligence. It focuses on deal questions: which ICT contracts are critical, which subcontracting chains exist and what must be resolved before signing or closing.

Classify DORA risk

Are ICT outsourcing arrangements closing-ready?

Two questions show whether the point needs deeper review before signing or closing.

Already know you want to get in touch? Go straight to the enquiry form.

01 Question 1

Is the target a regulated financial undertaking or payment institution?

If the answer is yes, the point belongs in the deal risk list.

All paths at a glance

Overview of all answers.

01

The finding is generally transaction-ready.

Record the assumptions in the data room and reflect them in the appropriate warranty or condition.

02

The finding needs a clear solution before signing or closing.

If documents or responsibilities are missing, the buyer should not move the point into a vague post-closing list. Clarify risk, price effect and contract protection before the next milestone.

What DORA changes in the transaction

DORA is not merely an IT standard. Regulation (EU) 2022/2554 requires financial undertakings to manage ICT risk in a structured way. In an acquisition, this affects the data room, risk matrix and the question whether the target controls its critical functions.

The post on regulated targets covers FMA and licence issues more broadly. DORA is the narrower review of digital operational resilience.

ICT contracts, subcontractors and exit rights

Buyers should not sort critical ICT providers only by cost and term. Audit rights, sub-outsourcing, place of performance, data access, exit scenarios and realistic provider replacement matter.

The post on source code, licences and data remains relevant. DORA adds the regulatory layer for ongoing operational stability.

Review grid

Translate DORA findings into deal consequences

The overview separates finding, review and agreement consequence.

Translate DORA findings into deal consequences
DORA point Deal question Agreement consequence
ICT register Are critical providers fully recorded? Data room request and warranty
Sub-outsourcing Are approval chains involved? Condition or indemnity
Exit Is provider replacement realistic? Plan, cost and timing rule

The concrete drafting depends on the data room, deal structure and specialist advice.

Practical point: This point should not be phrased as a post-closing task without responsibility. If it can affect price, approval or liability, it belongs in the data room and SPA before closing.

DORA as closing condition or warranty

If key documents are missing, DORA should not become a vague post-closing task. Depending on the finding, the SPA needs a condition, a specific warranty or a holdback for remediation.

The post on closing conditions explains how conditions to completion should be drafted.

Separate this from cyber due diligence

Cybersecurity due diligence asks about technical security and NIS2 interfaces. DORA additionally asks about governance, registers, testing and control of ICT third-party providers.

Keeping the two workstreams separate avoids duplication and blind spots. A FinTech deal needs both, but with different questions and owners.

Frequent questions

DORA in a FinTech acquisition: ICT contracts, outsourcing and FMA closing checks.

Must every IT contract in a FinTech deal be DORA-compliant? +

Not every contract has the same relevance. Critical ICT services require special review and contractual protection.

Is DORA an FMA closing issue? +

That depends on the target and findings. Critical gaps may justify a closing condition or specific warranty.

Does DORA replace cybersecurity due diligence? +

No. DORA adds regulatory governance, outsourcing and resilience to the technical review.

Topics
DORAFinTechPayment institutionICT outsourcingDue diligence

Structuring a deal, reviewing a contract, securing the risks?

When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.

Contact

A direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg