DORA Critical Third Party Designation: A Reading for Both Sides

A reading of DORA’s Critical Third Party regime — what it does to financial entities and what it does to the providers themselves. Two readings in one, because the regime cuts both ways.

DORA Articles 31 to 44 establish what may be the most consequential single innovation in EU financial services regulation in a decade: direct supervision of certain ICT third-party providers by EU authorities. The “Critical ICT Third-Party Provider” (CTPP) designation is not a label. It is a regulatory status that brings the provider — typically a hyperscaler, a payment infrastructure firm, or a major software vendor — into direct oversight by the European Supervisory Authorities.

This is a reading for both sides of the regime: financial entities that depend on CTPPs, and the CTPPs themselves.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

What the regime is

Articles 31 to 33 set out the designation framework. The European Supervisory Authorities — the European Banking Authority, the European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority — jointly identify which ICT third-party service providers are “critical” to the EU financial sector based on:

  • The systemic impact on the stability, continuity, or quality of financial services provided in the Union if the provider were to fail.
  • The systemic character of financial entities relying on the provider.
  • The reliance of financial entities on the provider for critical or important functions.
  • The degree of substitutability — how easy or hard it would be to replace the provider.

Once designated, a CTPP comes under the oversight of a Lead Overseer — one of the three ESAs — with powers to request information, conduct inspections, and issue recommendations. Articles 35 to 39 set out what the Lead Overseer can do; Article 38 sets out the recommendations and the publication regime.

The first wave of CTPP designations was completed during 2025. The major hyperscalers and several specialised infrastructure providers were among the designated.

Who this is for

  • The financial entity CTO who needs to know how the firm’s CTPP dependencies affect its DORA compliance and supervisory engagement.
  • The compliance or risk officer at a financial entity tracking the first wave of CTPP designations and assessing the implications.
  • The compliance team at an ICT provider that may be designated, or has been recently designated, and is preparing for Lead Overseer engagement.

The financial entity side

For financial entities, the CTPP regime does several things at once.

The register of information becomes more important. DORA Article 28 requires every financial entity to maintain a register of all ICT third-party contractual arrangements. That register is the input to ESA-level identification of CTPPs. A financial entity with an incomplete register effectively underreports its CTPP exposure — which the supervisor can identify by comparison with peer firms.

Contracts with CTPPs need to meet Article 30 requirements at the highest standard. The supervisory expectation for contracts with CTPPs is stricter than for contracts with non-critical providers — audit rights, exit plans, sub-outsourcing controls, data residency, security incident notification. Standard cloud terms-of-service do not satisfy this for a CTPP relationship.

Concentration risk has to be measured and managed. If a meaningful proportion of the financial entity’s critical functions depend on a single CTPP, that is concentration risk under DORA. The supervisory expectation is documented assessment and, where the concentration is material, an active mitigation plan.

Exit plans need to be real. An exit plan that says “in the event of provider failure, we will migrate to an alternative provider” is not an exit plan. The supervisory expectation is documented, tested, time-bound migration paths for each critical CTPP relationship.

The CTPP side

For the ICT provider, designation brings a set of obligations that did not exist before.

The Lead Overseer becomes a stakeholder. The Lead Overseer has powers to request information, conduct on-site inspections, and issue recommendations. The CTPP needs a defined engagement point — typically a regulatory affairs function — and the ability to respond to information requests within reasonable timelines.

Recommendations carry weight even though they are not legally binding. Article 38 allows the Lead Overseer to issue recommendations to a CTPP. Non-compliance is publishable. The reputational and commercial consequences of a published non-compliance finding are significant — financial entities will see it, and procurement will react.

The “sub-contractor” obligation flows through. Article 39 requires CTPPs to maintain awareness of and exercise risk-based oversight over their own ICT sub-contractors that perform parts of the services relied on by financial entities. This is a substantive new obligation on the provider’s own supply chain.

Documentation expectations move closer to financial entity standards. The technical and operational documentation a CTPP needs to be able to produce to its Lead Overseer is closer to what a regulated financial entity produces than to what a typical software-as-a-service provider has historically maintained.

Where both sides get this wrong

Financial entities assume CTPP oversight is the provider’s problem. It is not. The financial entity remains accountable for its critical and important functions even when those functions depend on a designated CTPP. The CTPP regime does not transfer accountability — it adds a layer of provider-level supervision on top.

CTPPs underestimate the documentation burden. Lead Overseer information requests can be substantial. A CTPP that has not built a regulatory documentation capability finds itself producing artefacts under time pressure, often inconsistently.

Exit plans are paper exercises. The most common deficiency identified in early supervisory engagement is that exit plans have not been tested. A migration path that has never been exercised is a plan, not a capability.

How we engage with this

On the financial entity side, as part of a Supplier and Dependency Review, we read the register of information, the contracts with material providers, the concentration risk assessment, and the exit plans. The output is a written assessment of where the firm stands relative to what DORA Articles 28 to 30 demand for CTPP relationships.

On the CTPP side, we read the regulatory engagement readiness — documentation, sub-contractor oversight, response capability. We do not represent CTPPs to the Lead Overseer. We do not implement controls. We read what is there and identify what is missing.

Pricing is published at /pricing/. If the CTPP regime is now a live consideration on either side, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming