Skip to content
DORA

DORA Critical ICT Providers: Designation and Requirements

4 min readUpdated 1 July 2026

DORA creates a category of ICT service providers designated as "critical third-party providers" (CTPPs) — subject to direct oversight by EU supervisory authorities rather than just through their financial entity customers. This designation fundamentally changes the regulatory relationship for the providers involved and has significant implications for financial entities relying on those providers.


What Is a Critical Third-Party Provider?

A CTPP is an ICT third-party service provider that has been formally designated by the Joint Supervisory Network (a body established by EBA, ESMA, and EIOPA) as critical to the stability of the EU financial system.

The designation is based on:

  • The number and systemic importance of financial entities that rely on the provider
  • The degree of substitutability (how easily could the provider be replaced?)
  • The cross-border reach of the provider's services
  • The level of dependence of financial entities on the provider

In practice: The first CTPP designations have focused on the major cloud providers — AWS, Microsoft Azure, and Google Cloud — and on large specialised financial infrastructure providers. The ESAs have been building the designation list since 2024.


CTPP Designation Process

The Joint Oversight Network (JON) — established by the ESAs to oversee CTPPs — follows this process:

  1. Data collection: Financial entities submit their Registers of Information, allowing ESAs to identify which ICT providers are most widely used
  2. Concentration analysis: ESAs calculate concentration levels — which providers are critical to systemic stability?
  3. Provisional designation: ESAs notify the provider of potential designation and seek their views
  4. Final designation: ESA decision and publication on the European Union register of designated CTPPs

What DORA Requires from Designated CTPPs

Once designated, a CTPP must:

Lead Overseer relationship: Each CTPP is assigned a Lead Overseer — one of EBA, ESMA, or EIOPA — who acts as the primary regulatory contact and coordinator.

Annual oversight assessments: The Lead Overseer conducts annual assessments covering the CTPP's operational resilience practices, ICT risk management, and the robustness of the services provided to financial entities.

Information provision: CTPPs must provide the Lead Overseer with comprehensive information about their ICT infrastructure, risk management practices, and any planned changes to their services.

Remediation actions: Where the Lead Overseer identifies deficiencies, the CTPP must implement remediation actions within defined timeframes.

Oversight visits: The Lead Overseer may conduct on-site inspections and remote access reviews.

Concentration reporting: CTPPs must report their own dependency concentration — if one financial entity is over-reliant on a single CTPP service.


Implications for Financial Entities Relying on CTPPs

If your critical ICT provider is or becomes a CTPP, this has direct operational implications:

Enhanced oversight visibility: The ESAs can access information about the CTPP's practices through the oversight process. This may reveal vulnerabilities in the CTPP's operations that you were not previously aware of.

Coordination during incidents: When a CTPP experiences a major incident, the ESA oversight mechanism activates, potentially providing financial entities with better coordination and information than they would get through standard commercial channels.

Contractual enhancements: ESA assessments may result in remediation obligations that your CTPP must implement, potentially requiring contract updates or service changes.

Exit obligation: If a CTPP is found to be critically deficient and remediation fails, the ESA can recommend that financial entities reduce their dependence on the CTPP. This is a significant but proportionate power — the intent is to strengthen, not disrupt, the financial system.


Implications for ICT Providers

If you are a large ICT provider with significant financial services clients in the EU, monitor CTPP designation criteria closely:

Pre-designation: Conduct a self-assessment of your potential CTPP exposure — how many EU financial entities rely on your services? What would the systemic impact of a major disruption be?

Designation engagement: If you receive a provisional designation notice, engage seriously with the process. The ESAs have published guidance on the designation criteria and the oversight framework. Understand what will be assessed.

Post-designation: Assign dedicated oversight team resources. The Lead Overseer engagement requires ongoing management — information requests, annual assessments, and remediation tracking are substantial administrative burdens.


Providers Currently in Scope for CTPP Assessment

The ESAs have been building the CTPP register since 2024. Publicly confirmed areas of assessment focus:

  • Major hyperscale cloud providers: AWS, Azure, Google Cloud — all conducting active engagement with the JON
  • Specialised financial services providers: Core banking platform providers, payment scheme operators, interbank messaging systems
  • Data and analytics providers: Market data providers, credit rating data feeds relied upon by large numbers of financial entities

The CTPP register is published and updated by the ESAs.

ComplyOne maps your DORA obligations, tracks your readiness across all five pillars, and maintains your audit evidence.

Run your DORA compliance check →