Glossary · DORA
Critical ICT Third-Party Provider (CTPP)
An ICT provider designated as critical to the EU financial system and placed under direct European supervisory oversight.
Explained in depth: DORA overview
DORA introduces something no earlier EU financial law had: direct oversight of technology providers themselves. The European Supervisory Authorities designate ICT providers as critical based on the systemic impact a failure would have, the importance of the financial entities relying on them, and their substitutability. Major cloud providers were among the first designations in 2025. Each CTPP is assigned a Lead Overseer (one of the three ESAs), which can request information, conduct investigations and inspections, issue recommendations, and, ultimately, recommend that financial entities suspend or terminate the use of a provider that fails to cooperate. Providers pay oversight fees and must maintain an EU subsidiary to serve EU financial entities.
Why it matters
For financial entities, a supplier's CTPP status affects concentration-risk assessments and exit strategies. For large ICT vendors, designation means an entirely new supervisory relationship. For smaller vendors, the regime cascades down through the contractual chain.
