Request for Microsoft DORA Addendum

Paolo Botta 0 Punti di reputazione
2026-09-03T16:25:02.88+00:00

We provide SaaS solutions to insurance-sector clients operating under IVASS supervision, who fall within the scope of Regulation (EU) 2022/2554 (DORA) as financial entities. As part of our ICT third-party risk management obligations under DORA Article 30 (contractual provisions with ICT third-party service providers) and our register of information, we need to obtain and review the Microsoft DORA Addendum applicable to our Azure subscription.

Operazioni di Azure IoT
Operazioni di Azure IoT

Operazioni di Azure IoT è un set di servizi modulari abilitati da Azure Arc.

0 commenti Nessun commento

1 risposta

Ordina per: Più utili
  1. Manish Deshpande 8,215 Punti di reputazione Personale Esterno Microsoft Moderatore
    2026-09-06T22:36:53.06+00:00

    Hello @Paolo Botta

    Thanks for laying out the regulatory context so clearly — it makes this much easier to answer precisely. You need the Microsoft DORA Addendum for your Azure subscription to satisfy Article 30 of Regulation (EU) 2022/2554 and to populate your register of information, on behalf of IVASS-supervised insurance clients. Here's exactly where it lives, which variant applies to you, and who has to sign it.

    First, why this is harder to find than it should be

    The DORA Addendum is referenced in Microsoft's compliance documentation but published somewhere else entirely — the Microsoft Customer Agreement amendments catalogue in Partner Center. It's a contractual amendment, not a licence, SKU, or subscription feature, so it can't be issued through technical support; execution runs through the licensing/purchasing channel. Distribution is also gated: that page states only Direct Bill Partners and Indirect Providers can download the files, and indirect resellers must obtain them from their indirect provider. Right document, unexpected page, restricted download — that's the combination that has stalled this request for others since early 2025.

    Step 1 — Open the catalogue page

    https://learn.microsoft.com/en-us/partner-center/enroll/csp-documents-and-learning-resources#microsoft-customer-agreement-amendments

    Scroll to "DORA - EU Digital Operational Resilience Act." You'll know you're in the right place when the table lists both "Financial Services Amendment DORA Addendum" and "ISV Financial Services Amendment DORA Addendum," each in English, French, German, and Italian.

    Step 2 — Take the ISV variant

    Since you're a software vendor supplying regulated entities rather than a regulated entity yourself, the ISV variant is the one built for your position in the supply chain. Picking the wrong one is the most common cause of an eligibility rejection, so it's worth getting right at the outset. Check the PDF cover page title matches what you intended.

    ISV: English https://assetsprod.microsoft.com/mpn/isv-dora-addendum.pdf | Italian https://assetsprod.microsoft.com/mpn/it-it/isv-dora-addendum.pdf | French https://assetsprod.microsoft.com/mpn/fr-fr/isv-dora-addendum.pdf | German https://assetsprod.microsoft.com/mpn/de-de/isv-dora-addendum.pdf

    Standard: English https://assetsprod.microsoft.com/mpn/dora-addendum.pdf | Italian https://assetsprod.microsoft.com/mpn/it-it/dora-addendum.pdf | French https://assetsprod.microsoft.com/mpn/fr-fr/dora-addendum.pdf | German https://assetsprod.microsoft.com/mpn/de-de/dora-addendum.pdf

    Step 3 — Confirm the parent Financial Services Amendment is already executed

    The DORA Addendum amends the Financial Services Amendment — without the parent in force, there's nothing for it to attach to. Check your contracting record shows an executed FSA against your MCA or EA.

    ISV FSA Worldwide, January 2025 — English https://assetsprod.microsoft.com/mpn/isv-financial-services-amendment-worldwide.pdf | Italian https://assetsprod.microsoft.com/mpn/it-it/isv-financial-services-amendment-worldwide.pdf

    Step 4 — Route execution through your licensing channel

    If you buy Azure directly from Microsoft (EA or MCA-direct), your Microsoft account/licensing team owns issuance and countersignature. If you buy through a CSP partner, your partner coordinates with Microsoft and supplies the executed amendment. The distinction matters because an unsigned PDF is only a review copy — it won't stand up as Article 30 contractual evidence. You're done when you hold a countersigned copy referencing your agreement number and effective date.

    Step 5 — Pull the DORA contract mapping document now, in parallel

    https://servicetrust.microsoft.com/DocumentPage/ffb7c37c-4efa-4b01-8dc2-da0ea7cdc2ab

    Don't wait on execution for this one. It maps DORA Article 30 provisions and the Regulatory Technical Standards on subcontracting ("RTS 53," JC 2024 53) to each specific Microsoft contract, with Microsoft's commentary on how each requirement is addressed. It's directly consumable for your register of information, so you can make progress on that workstream while the signature process runs. It should open as a requirement-to-contract mapping with a commentary column.

    What the addendum actually covers

    Per Microsoft's published description, it outlines — but isn't limited to — how Microsoft collaborates with material subcontractors (Important Providers); Microsoft's commitment to safeguarding your data in the specific terms of the regulation; additional termination rights if you don't agree with a material change involving an Important Provider; and provisions for monitoring and reporting to ensure transparency and accountability throughout service delivery. It sits within a seven-document stack: Product Terms, the DPA, Security and privacy terms, the Online Services SLA, the Enterprise Agreement, the DORA Addendum, and the Financial Services Agreement.

    Two things I'd rather flag than gloss over

    The DORA amendment table on the Partner Center page carries no version date, unlike the Financial Services Amendments listed alongside it, which are stamped January 2025. Please confirm the version on the PDF cover page before legal sign-off.

    Also worth stating plainly for your clients' benefit: Microsoft's contractual commitments support but do not discharge their DORA obligations — per Microsoft's own guidance, financial entities remain accountable for their own compliance. For the insurance sector, EIOPA is the relevant European Supervisory Authority alongside IVASS: https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en

    References

    Thanks,
    Manish.

    La risposta è stata utile?

    0 commenti Nessun commento

Risposta

Le risposte possono essere contrassegnate come "Accettata" dall'autore della domanda e "Consigliata" dai moderatori, in modo da consentire agli utenti di sapere che la risposta ha risolto il problema dell'autore.