Most regulated firms have concentrated their critical systems on one or two cloud providers, and most cannot demonstrate a credible way off them. Under DORA, that combination is now a supervisory problem with a name: concentration risk without a tested exit strategy. Regulators have made clear they expect both a documented assessment of the risk and a demonstrable ability to move — and “we could migrate if we had to” is not a demonstrable ability.
Why this is now a live obligation, not a hypothetical
In November 2025 the European Supervisory Authorities designated the first critical ICT third-party providers under DORA — a list dominated by the cloud hyperscalers, alongside core market infrastructure. That designation formalised what the data already showed: a large majority of EU financial entities depend on the same handful of providers, with many using two of the three largest for separate critical functions. Supervisors now treat this as systemic, and DORA Article 28 requires each financial entity to assess concentration explicitly and to maintain documented, tested exit and transition plans for critical arrangements. Designation of a provider does not transfer this responsibility — it remains squarely with the financial entity.
What a real exit plan contains
The gap between most firms’ exit plans and a credible one comes down to whether it has been tested. A real plan includes:
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
- A mapped dependency, including the fourth parties. You cannot exit what you have not fully mapped, and the sub-providers your provider depends on can invalidate a naive diversification strategy.
- A defined target state. Where the workload would go, and whether that alternative is genuinely available at the scale you need — not an assumption that a competitor could absorb you overnight.
- Data portability and the exit clauses to enforce it. DORA requires the contractual right to migrate, with minimum notice periods; if your contract does not contain them, your exit plan is aspirational.
- Evidence it has been exercised. A plan that has never been tested is a document, and a supervisor will treat it as one.
The board’s question
The useful board question is not “are we too concentrated” — almost everyone is — but “could we actually move a critical workload within our stated tolerance, and can we prove it.” Most firms discover, when they test it honestly, that the answer is no. Finding that out in a diagnostic is far cheaper than finding it out in an incident or an inspection.
Who this is for
This reading is for:
- Boards of EU financial entities under DORA
- CTOs whose critical systems run on a single hyperscaler
- Risk owners asked to evidence a concentration assessment and exit strategy
- Operational resilience leads who know the exit plan is a slide, not a plan
Sixteen Pillars runs the concentration diagnostic and stress-tests the exit plan for your critical workloads, so what you tell a supervisor is demonstrable rather than aspirational. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming