Critical ICT third-party providers under DORA
Critical ICT third-party providers, CTPPs for short, are the technology firms that the European Supervisory Authorities place under direct EU oversight because so much of the financial sector depends on them. On November 18, 2025, EBA, EIOPA and ESMA published the first list under the Digital Operational Resilience Act. It names 19 companies, from hyperscale clouds and data center operators to market data and core banking technology.
For a bank, the list is a map of its own concentration risk. The cloud platforms that run its AI models and the vendors behind its payment software now report to an EU overseer, while the bank keeps every duty it had toward them.
The 19 providers on the list
The official list, in alphabetical order, names Accenture plc, Amazon Web Services EMEA Sarl, Bloomberg L.P., Capgemini SE, Colt Technology Services, Deutsche Telekom AG, Equinix (EMEA) B.V., Fidelity National Information Services, Inc., Google Cloud EMEA Limited, International Business Machines Corporation, InterXion HeadQuarters B.V., Kyndryl Inc., LSEG Data and Risk Limited, Microsoft Ireland Operations Limited, NTT DATA Inc., Oracle Nederland B.V., Orange SA, SAP SE and Tata Consultancy Services Limited.
Read by function, the list covers four kinds of dependency that Morgan Lewis sorts into hyperscale cloud, data centers, infrastructure and networks, and technology built for financial services. Some of these touch Frankfurt directly: Equinix runs the FR2 data center where the primary Eurex and Xetra back-ends sit, which the page on data centers for finance in Frankfurt describes.
How the ESAs chose them
The designation started from data the banks and insurers had already filed. The ESAs collected the registers of information in which every financial entity lists its ICT contracts, assessed criticality together with the national supervisors, notified the providers that met the threshold and gave each one the right to respond with a reasoned statement before the final decision.
The criteria are in Article 31(2) of DORA: the systemic impact if the provider suffered a large-scale operational failure, the systemic importance of the financial entities that rely on it, how far they rely on it for critical or important functions, and the degree to which the provider can be substituted. A provider that is not on the list may ask to be designated under Article 31(11).
What oversight means for the providers
Each designated provider gets a Lead Overseer from one of the three ESAs, and joint examination teams with staff from the ESAs and the national authorities carry out the work, as PayTechLaw describes. The overseer can inspect the provider and issue recommendations. A provider that does not comply can face periodic penalty payments of up to 1 percent of its average daily worldwide turnover, for at most six months, under Article 35. Providers pay annual oversight fees.
A provider based outside the EU has to set up a subsidiary in the Union within 12 months of its designation, or financial entities may no longer use it, according to Article 31(12). The ESAs update the list once a year.
What stays with the bank
Designation moves no responsibility away from the customer. A bank still assesses the provider before signing, writes the DORA contract clauses, records the arrangement in its register and holds a tested cloud exit strategy. What it gains is a second line of sight: findings from the EU oversight can feed into its own ICT risk management.
The list also changes the conversation about concentration. When the AI assistant and the core banking platform both depend on providers from the same list, the bank's resilience plan has to show what happens if one of them fails. As a last resort, supervisors can require financial entities to suspend or end the use of a critical provider that ignores the overseer's recommendations.
Upcoming events on digital infrastructure
Who are the critical ICT third-party providers under DORA?
The first list of November 2025 names 19 companies: Accenture, Amazon Web Services, Bloomberg, Capgemini, Colt, Deutsche Telekom, Equinix, FIS, Google Cloud, IBM, InterXion, Kyndryl, LSEG Data and Risk, Microsoft, NTT DATA, Oracle, Orange, SAP and Tata Consultancy Services. The list names specific legal entities, such as Microsoft Ireland Operations Limited.
Does a bank still need due diligence for a designated provider?
Yes. DORA keeps the financial entity fully responsible for its ICT third-party risk. The pre-contract assessment, the contract terms, the register entry and the exit plan stay with the bank, whether the provider is designated or not.
What is the difference between a CTPP and a critical or important function?
A critical or important function is something the bank does, classified by the bank itself, and it decides which DORA contract rules apply. A CTPP is a provider that the ESAs designate because many financial entities depend on it. A small provider can support a critical function of one bank without ever becoming a CTPP.
Critical ICT providers and Finance Loop
Finance Loop brings the vendor managers and IT risk officers of banks together with the providers they depend on, in its Digital Infrastructure & Sovereignty track and its Risk & Compliance track. Finance Loop gives a provider that wants to explain its DORA readiness to financial institutions a format through a sponsored webinar or a partnership.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.