DORA and ContractHero:
The addendum pursuant to Article 30 is ready for signature

Your contract with a third-party ICT service provider must include the minimum requirements specified in Article 30 of DORA. In addition, you will receive the master data for your information register and the supporting documentation specified in the addendum: an ISO 27001 certificate, summary results of external audits and security tests, and completed security questionnaires.

ISO 27001
ISO 27001 certified
GDPR
GDPR-compliant
Hosting in Germany
Hosting in Germany
EU AI Act
Compliant with the EU AI Act

Hundreds of leading companies manage their contracts with ContractHero

Hosting in Germany
100 %
Data Processing in Germany
ISO 27001 certified
ISO 27001
certified
Penetration Tests
24 hours
Notification of
ICT Incidents
Audit Log
20 days
Deadline for responding to your requests for supporting documentation
Rating: 4.7 to 4.9 stars
4.7–4.9
OMR · G2 · Capterra
Why ContractHero

Why ContractHero Is the Secure Choice

What sets ContractHero apart from providers who first have to compile the DORA documents.

Cover all required content


Performance, information security, ICT incidents, audit rights, subcontractors, termination, and information register. Nine sections based on Articles 28 and 30 of DORA, attached as an appendix to the main contract and signed by both parties.

Faster Through Vendor Audits


The ISO 27001 certificate and the complete list of subcontractors are publicly available in the Trust Center. Additional documentation will be provided upon request within 20 business days.

Master Data for Your Information Registry

Legal entity, commercial registry number, description of services, processing locations, and subcontractors—all on one page. You can enter the information required under Article 28(3) of DORA instead of having to gather it from various sources.

Regulatory Framework
Why DORA Affects Your Contract with Us

DORA has been in effect since January 17, 2025

Regulation (EU) 2022/2554 is mandatory for financial institutions as defined in Article 2. You are responsible for determining whether and to what extent it applies to you.

ContractHero is your third-party ICT service provider

Because we provide an ICT service to you, we are considered an ICT third-party service provider in this regard. The regulation primarily applies to you, not to us. Our role is to provide you with the basis for compliance.

Article 30 requires certain minimum provisions in the contract

Processing locations, information security, reporting of ICT incidents, audit rights, subcontractors, and termination must be governed by contract. Our DORA addendum provides precisely these provisions.

Article 28, paragraph 3, requires an information registry

You maintain a registry of all third-party ICT service providers and keep it available for your regulatory oversight. We will provide you with the master data for ContractHero on a single sheet.

You retain control over the criticality classification

You decide, based on your internal assessment, whether ContractHero supports a critical or important function as defined in Article 3(22) of DORA. We provide the information, but we do not make the assessment for you.

ISO 27001 and GDPR Certificates
Customer Testimonials

What Customers Say About Security

"Compliance with strict security standards was a key priority for our organization, and ContractHero met these requirements with ease."

Maria Kruber
Maria Kruber
SVP Finance & CFO

“It’s important to have a German provider, because with the certifications that ContractHero has, we’re in a particularly secure position when it comes to storing contract data.”

Jan Kaeten
Jan Kaeten
Group CFO, The Relevance Group

What's Behind DORA

Deadline Reminder
Complete list of subcontractors

We currently use 11 subcontractors, all of which have processing locations in the EU or the EEA.
For critical or important functions, we will notify you in advance, and you have the right to object. We require subcontractors to comply with the same DORA-related obligations and remain fully responsible to you. The list in the Trust Center is binding and is continuously updated.

Approval Workflows
You retain control over the criticality classification

You will determine whether ContractHero supports a critical or important function for you, as defined in Article 3(22) of DORA, based on your internal criticality assessment. We will provide you with the necessary information but will not perform the assessment for you.

Icon
Encryption and comprehensive audit trail

Data at rest and in transit is encrypted using AES-256. Access is governed by role-based permissions, and every change is logged. The technical and organizational measures are specified in the data processing agreement.

Icon
Recovery is tested regularly

Backups are performed regularly at data centers in Germany, and the recovery process is tested on a regular basis. Availability, as well as the target values for recovery time and recovery point, are based on a Service Level Agreement (SLA) agreed upon with you, if applicable. You can view the current availability status at any time at status.contracthero.com.

Icon
One document, a clear hierarchy

In the event of any conflict between the Addendum and the Main Agreement, the provisions of the Addendum shall take precedence with respect to matters relevant to DORA.
With respect to data protection matters, the Data Processing Agreement shall remain applicable. Any amendments to the Addendum must be made in writing. No liability shall arise beyond the scope of the Main Agreement.

For Your Vendor Assessment

All certificates are consolidated in the Trust Center

Your IT and legal teams can find the relevant documents in one place, where they are publicly accessible.

ISO/IEC 27001:2022 Certificate (publicly available)
Data Processing Agreement (DPA) pursuant to Article 28 of the GDPR
List of subprocessors, including location and role
Technical and Organizational Measures (TOMs)
Summary of the Most Recent Penetration Test
Availability & Status (Status Page)
Trust Center

Publicly accessible; no login or sales pitch required.

trust.contracthero.com →
In detail

Explore Security Topics in Depth

Data Security Overview

All security measures and documentation at a glance.

Learn more →
ISO 27001

Certified Information Security for Businesses and Servers.

Learn more →
EU AI Act

Responsible, audited AI for your contracts.

Learn more →

Contract data under full control - checked, protected and processed exclusively in Germany

  • Data processing exclusively on servers in Germany

    The processing of your data - including storage, retrieval, forwarding and archiving - takes place exclusively in ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019 and CSA STAR CCM v4.0. certified data centers in Frankfurt, Germany.

  • US CLOUD Act? Our data structure protects you

    Our technical architecture - including end-to-end encryption - and contractual safeguards ensure that data access from abroad is neither possible nor legally enforceable. Access to confidential content is reserved exclusively for authorized users.

  • Complete traceability of all activities

    ContractHero documents all relevant actions in detailed audit logs. From file accesses and rights changes to user logins, every step is logged completely and comprehensibly. This allows you to meet internal and regulatory requirements for transparency and compliance in a legally compliant manner.

  • Certified security standards and regular penetration tests

    ContractHero has its systems regularly tested by external security experts (penetration testing). In addition, we meet the highest requirements in accordance with international security standards - over and above ISO certifications.

  • Privacy by design & default (according to GDPR)

    Our platform is designed in such a way that data protection is already guaranteed at a technical level and by default. Functions that could disclose data are deactivated by default and must be consciously activated.

Would you like to get to know ContractHero?
Want to know how ContractHero can make your contract management more automated and secure? Request a product demo now to get your questions answered and experience the benefits for yourself.
Schedule a demo
Recommendations

Would you like to learn more about ContractHero?

Want to know how ContractHero can make your contract management more automated and secure? Request a product demo now to get your questions answered and experience the benefits for yourself.

A clear overview of your contracts in 30 minutes – live in the demo

Book a demo

Frequently asked questions

Is ContractHero DORA-compliant?

DORA primarily applies to you as a financial institution, not to us as a software provider. There is no DORA certification for providers. Our role is to provide you with the contractual framework and the supporting documentation you need to comply with Article 30 of DORA and maintain your information register. We have a ready-made addendum for this purpose.

What does the DORA amendment cover?

The addendum covers the minimum contractual requirements specified in Art. 30 of DORA: scope of services and classification, processing locations, information security, notification of ICT incidents, access, information, inspection, and audit rights, subcontractors, termination and data return, as well as the master data for your information register. It is an annex to the main contract and is signed by both parties, just like the Data Processing Agreement.

Do you provide the data for our information registry?

Yes. You will receive a one-page summary sheet listing the legal entity, commercial register number, description of services, processing and storage locations, and the subcontractors used. Important to note: ContractHero does not maintain an LEI; identification is based on the commercial register number HRB 223237. You are responsible for uploading this information to your registry in the specified format.

What audit rights do we and our regulatory authority have?

You may request information and evidence regarding compliance with the addendum; we will respond within 20 business days. This includes the current ISO 27001 certificate, summary results of external audits and security tests, and completed security questionnaires. Your relevant supervisory and resolution authorities, as well as the individuals designated by them, have unrestricted rights of access, information, and inspection, and we cooperate fully with regulatory audits.

How quickly do we find out about an ICT incident?

In the event of a serious ICT incident or a significant cyber threat affecting you, we will notify you immediately, no later than 24 hours after becoming aware of it. The notification will include the nature and scope of the incident, the data and services affected, the measures taken, and a point of contact. We will assist you with your own reporting obligations under Article 19 of DORA.

What happens if you switch providers or if a provider goes bankrupt?

The amendment provides for an orderly transition over a 60-day transition period. We will return your data in a standard, structured format and then delete it. This obligation applies to any termination of service, including, specifically, in the event of insolvency, liquidation, or cessation of business operations. The transition will be carried out in such a way that your business operations are not interrupted and your regulatory requirements continue to be met.

Where is our contract data processed?

Exclusively within the European Union and the EEA. Primary hosting takes place in ISO 27001-certified data centers in Germany; the data does not leave the EU. Data at rest and in transit is encrypted using AES-256, and backups are stored in German data centers. Currently, 11 subcontractors are engaged, all of which have processing locations in the EU or the EEA. Before relocating any processing location, we will notify you with reasonable advance notice and grant you the right to object.