DORA Critical Third-Party Oversight: What Designation Means for You

On 18 November 2025 the European Supervisory Authorities designated the first critical ICT third-party providers under DORA — nineteen of them, dominated by the cloud hyperscalers and core market infrastructure. Oversight engagement has begun, with the first examinations running through 2026. For most regulated firms this landed as a headline and then a shrug, on the assumption that direct EU oversight of these providers makes them someone else’s problem. That assumption is wrong, and it is the expensive kind of wrong.

What designation actually does

A designated critical third-party provider (CTPP) comes under direct oversight by a Lead Overseer — one of the three ESAs — working through Joint Examination Teams. The overseer can request information, inspect, and issue recommendations, backed by daily penalty payments of up to 1% of worldwide turnover for non-compliance, and in the last resort can require financial entities to suspend or terminate use of the provider. The list is reviewed and republished annually, so a provider not designated now can be designated later.

Why it does not reduce your obligations

Here is the point most firms miss: designation does not shift responsibility from the financial entity to the overseer. If you contract with a designated CTPP for a critical or important function, your DORA duties are unchanged. You still must include the Article 30 mandatory contractual terms — service levels, audit and access rights, incident cooperation, and exit rights with minimum notice periods. You still must maintain that provider in your Register of Information, assess your concentration exposure against your risk appetite, and hold a tested exit plan. Some providers may push back on customer audit rights, arguing that ESA oversight already covers it. That framing is wrong: your obligations are independent of the oversight regime, and accepting it leaves you exposed.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

What to do now

  • Cross-check your Register against the designated list. Know exactly which of your critical providers are now CTPPs.
  • Confirm your contracts carry the Article 30 terms. Designation is a good trigger to close the gaps that were easy to defer.
  • Re-run your concentration assessment. If your critical functions cluster on one or two CTPPs, document the exposure and your mitigation.
  • Test the exit plan for each. This is the obligation firms most often hold only on paper, and it is the one an examiner is most likely to probe.

The Q1 2026 Register submissions were the first hard supervisory test, and national authorities are already cross-referencing the data automatically. Incomplete or inconsistent registers are drawing follow-up. Designation raised the stakes on getting the third-party pillar right; it did not hand the work to someone else.

Who this is for

This reading is for:

  • Financial entities contracting with a designated critical ICT provider
  • ICT providers assessing whether they will be designated next
  • Third-party risk owners maintaining the DORA Register of Information
  • Boards that assumed regulator oversight reduces their own obligations

Sixteen Pillars cross-checks your Register against the designated CTPPs, closes the Article 30 contract gaps, and tests the exit plans an examiner is most likely to probe. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming