Enforcement

ESAs designate the first critical ICT third-party providers under DORA

Enforcement18 Nov 2025✓ verified 4 Jul 2026

On 18 November 2025 the ESAs published the first list of critical ICT third-party providers under DORA, bringing them under direct EU oversight.

What changed

On 18 November 2025 the European Supervisory Authorities (EBA, EIOPA and ESMA) published the first list of ICT third-party service providers designated as critical under DORA's oversight framework. Designation brings a provider under direct ESA oversight: the authorities will assess whether each critical provider has appropriate risk-management and governance frameworks for the services it delivers to the EU financial sector, and have stated they will keep engaging with designated providers in upcoming examination activities.

Why it matters

DORA's oversight regime is operating, not theoretical: the infrastructure providers the financial sector depends on now have an EU supervisor of their own. For financial entities, designation status becomes a concrete input to third-party risk work — and oversight findings about a critical provider will be relevant to every firm that relies on it.

Who is affected

The designated ICT providers directly; every financial entity that relies on them for critical or important functions indirectly — concentration-risk questions about these providers now have a supervisory counterpart.
Rolesrisk teamsvendor management teamscompliance teamssecurity teams
Organisationsfinancial entitiesICT service providers

What to check next

  • Check which of your ICT vendors appear on the ESAs' designation list
  • Record designation status in the register of information and vendor files
  • Review concentration risk for services sourced from designated providers
  • Prepare to factor ESA oversight findings into your third-party risk assessments as examinations proceed

Key dates

  • 2025-11-18First designation list published
Source. European Banking Authority — ESAs designate critical ICT third-party providers ↗
Document: ESAs (EBA/EIOPA/ESMA) joint designation of critical ICT third-party service providers under DORA (18 November 2025)
Verified by Trusq against this source on 4 Jul 2026. Trusq publishes only what it can trace to an official source; the source text prevails. Not legal advice.
Relates to DORA
← All updates