Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Critical ICT third-party providers under DORA oversight

Critical ICT Third-Party Providers: A Clear DORA Guide for 2026

Critical ICT third-party providers are the part of DORA that regulates somebody other than you. Under Article 31 the European Supervisory Authorities designate the providers whose failure would matter to the financial system, place each under a Lead Overseer, and supervise them directly — and in November 2025 that stopped being theoretical, when the ESAs published a first list naming 19 providers.

This guide covers how designation works, the four criteria behind it, what the oversight framework does, and — the part that lands on financial entities rather than providers — the third-country subsidiary rule with a twelve-month clock attached.

Critical ICT third-party providers: the four DORA designation criteria and the oversight structure
Four criteria decide designation; the Lead Overseer follows from who uses the provider.

How critical ICT third-party providers are designated

The ESAs, acting through the Joint Committee and on a recommendation from the Oversight Forum, designate the ICT third-party service providers that are critical for financial entities. The assessment rests on four criteria set out in Article 31(2):

  1. Systemic impact of failure — the effect on the stability, continuity or quality of financial services if the provider suffered a large-scale operational failure, taking into account how many financial entities it serves and the total value of their assets.
  2. Systemic importance of the entities relying on it — assessed through parameters including how many global or other systemically important institutions depend on the provider, and the interdependence between them.
  3. Reliance for critical or important functions — whether financial entities depend on the provider for critical or important functions, whether directly or indirectly through subcontracting arrangements.
  4. Degree of substitutability — the lack of real alternatives, even partial, given the number of providers in the market, market share, or technical complexity.

The third criterion is the one that catches providers who believed they were out of scope: reliance counts even where it reaches the financial entity through somebody else’s subcontracting chain. A provider two tiers back from any bank can still be systemically relied upon.

Voluntary designation exists

Article 31(11) allows a provider that is not on the list to request designation, by submitting a reasoned application to EBA, ESMA or EIOPA, which decides through the Joint Committee. That is a real commercial option: for a provider selling to financial entities, being inside the oversight framework can be easier to explain to a prospect’s third-party risk team than a long questionnaire.

Who oversees critical ICT third-party providers

Each critical provider is assigned a Lead Overseer — the ESA responsible for the financial entities that together hold the largest share of total assets among that provider’s users, measured by the sum of their individual balance sheets. So the supervisor follows the customer base, not the provider’s own sector: a cloud platform used overwhelmingly by banks lands with the EBA, and one used mainly by insurers with EIOPA.

Article 32 sets the structure of the Oversight Framework and Article 33 the tasks of the Lead Overseer, which include assessing whether the provider has comprehensive, sound and effective rules and controls covering ICT risk management, incident handling, subcontracting and security. Oversight is exercised through examination teams drawn from the ESAs and national authorities, with powers to request information, conduct general investigations and carry out inspections.

The first list of critical ICT third-party providers was published on 18 November 2025, covering 19 providers — predominantly hyperscale cloud and platform businesses, data centre operators and financial-sector-specific technology suppliers — with operational supervision building through 2026.

What the critical ICT third-party providers list means for you

This is the part most firms under-plan, because it reads like somebody else’s obligation.

The third-country subsidiary rule. A financial entity may only use the services of a designated critical provider established outside the Union if that provider has established a subsidiary in the Union within twelve months of designation. Measured from 18 November 2025, that is a late-2026 deadline sitting inside contracts that were signed years ago. If a provider you depend on was designated and does not establish an EU subsidiary in time, the problem becomes yours — and the answer is an exit strategy you can actually execute.

Oversight does not transfer your accountability. DORA is explicit in structure: the Lead Overseer supervises the provider, while the financial entity remains fully responsible for managing its own ICT third-party risk. A provider being on the critical list is not a substitute for your own due diligence, contractual terms, concentration analysis or exit planning.

Your register still has to be right. Designation flows from information about ICT third-party dependencies that ultimately comes from financial entities’ own reporting. The register of information is the input to the process, which is a further reason for it to be accurate rather than approximately complete — see our guide to the register of information.

What to do about it now

  1. Map your providers against the designated list. Directly and through subcontractors — criterion three counts indirect reliance, and so should your mapping.
  2. For any designated third-country provider, check the subsidiary position. Ask in writing, record the answer, and diarize the twelve-month point.
  3. Re-read the exit strategy for those contracts. An exit plan that assumes an orderly migration over eighteen months is not an answer to a regulatory prohibition on continued use. Our guide to the DORA exit strategy covers what Article 28(8) expects.
  4. Revisit concentration risk. A designated provider is, by definition, one many firms could not easily replace — which is the regulator’s own statement that your concentration exposure is real. See ICT concentration risk.

Frequently asked questions

Who designates critical ICT third-party providers?
The ESAs, through the Joint Committee, on a recommendation from the Oversight Forum, under Article 31 of DORA.

How many have been designated?
The first list, published on 18 November 2025, named 19 providers. The list is not fixed — providers can be added, and Article 31(11) lets a provider apply to be designated.

How is the Lead Overseer chosen?
It is the ESA responsible for the financial entities that together hold the largest share of total assets among the provider’s users, by the sum of their balance sheets.

Does oversight reduce our own obligations?
No. Financial entities remain responsible for managing ICT third-party risk, including due diligence, contractual terms, concentration and exit planning.

What happens if a designated provider is outside the EU?
Financial entities may only continue using it if it establishes a subsidiary in the Union within twelve months of designation.

Where this leaves you

Treat the critical ICT third-party providers list as an input to your own third-party risk work rather than as news about somebody else. Map your dependencies including the indirect ones, check the EU subsidiary position for any designated third-country provider and put the twelve-month date in the calendar, and make sure the exit strategies behind those contracts could survive a regulatory prohibition rather than a commercial dispute. Oversight of the provider does not move your accountability an inch.

References

More on DORA third-party risk

Third-party registers, contractual clause sets and exit plans are in the DORA Compliance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.