Glossary · DORA

Critical ICT Third-Party Provider (CTPP)

An ICT provider designated as critical to the EU financial system and placed under direct European supervisory oversight.

Explained in depth: DORA overview

DORA introduces something no earlier EU financial law had: direct oversight of technology providers themselves. The European Supervisory Authorities designate ICT providers as critical based on the systemic impact a failure would have, the importance of the financial entities relying on them, and their substitutability. Major cloud providers were among the first designations in 2025. Each CTPP is assigned a Lead Overseer (one of the three ESAs), which can request information, conduct investigations and inspections, issue recommendations, and, ultimately, recommend that financial entities suspend or terminate the use of a provider that fails to cooperate. Providers pay oversight fees and must maintain an EU subsidiary to serve EU financial entities.

Why it matters

For financial entities, a supplier's CTPP status affects concentration-risk assessments and exit strategies. For large ICT vendors, designation means an entirely new supervisory relationship. For smaller vendors, the regime cascades down through the contractual chain.

Used in

See also

← All glossary terms