Skip to main content
DORA Auditor

guide

DORA Concentration Risk: What Article 29 Requires

DORA Article 29 requires assessing ICT concentration risk before outsourcing critical functions. What it covers and how to assess it. Updated July 2026.

DORA Auditor Editorial Team·Published

DORA Article 29 requires financial entities to assess ICT concentration risk before signing a contract for services supporting a critical or important function: whether the provider is easily substitutable, whether other contracts already sit with the same or a closely connected provider, and what sub-outsourcing the arrangement allows. It is a preliminary check, done before the contract, not an afterthought once the dependency already exists.

What "concentration risk" means under DORA

Concentration risk is the danger that a financial entity, or the sector as a whole, becomes so dependent on one ICT third-party provider, or a small cluster of them, that the provider's failure causes damage far beyond a single vendor outage. ECB Banking Supervision's outsourcing register analysis found that more than 30% of significant EU banks' total ICT outsourcing budget sits with just ten providers, most headquartered outside the EU. Concentration risk is what that statistic describes, and DORA gives it a specific legal home under the third-party-risk pillar.

Two levels, two different tools

DORA addresses concentration risk twice, at different levels, with different mechanisms.

At the entity level, Article 29 puts the burden on the financial entity itself. Before entering a contract for ICT services supporting a critical or important function, the entity must assess whether that contract would create an unhealthy dependency, and document the reasoning.

At the systemic level, the Oversight Framework (Articles 31-44) addresses the same risk from the regulator's side. Because so much of the sector relies on the same handful of cloud and infrastructure providers, the European Supervisory Authorities designate the most systemically important ones as critical ICT third-party providers (CTPPs) and place them under direct EU-level oversight through a Lead Overseer. Substitutability and interconnectedness, the same factors an individual entity weighs under Article 29, are also the criteria the ESAs use to decide who gets designated.

What Article 29 actually requires before you sign

Before concluding a contractual arrangement for ICT services supporting a critical or important function, a financial entity must consider:

  1. Substitutability. Could this service realistically be moved to a different provider without disrupting the business, or is switching costly, slow, or technically impractical?
  2. Existing exposure to the same provider. Does the entity already have multiple contracts, for different services, with the same provider or with providers that are closely connected (shared ownership, shared infrastructure, shared parent company)?
  3. Benefits and costs of alternatives. Would splitting the service across multiple providers, or choosing a different one entirely, better match the entity's business needs and risk appetite, even at higher cost or added complexity?
  4. Sub-outsourcing. Where the provider intends to subcontract part of the service, particularly to a provider established in a third country, what risk that chain adds and whether it can be adequately monitored.

None of this requires walking away from concentrated providers outright. Article 29 does not ban the use of dominant cloud or infrastructure vendors. It requires that the dependency be a documented, considered decision, not a default one, and that the entity can show its supervisor it weighed the alternatives.

Why sub-outsourcing chains matter here

A single "provider" on a register entry can conceal several layers of dependency. A SaaS vendor might run on one hyperscale cloud, which in turn depends on specific regions or data centres. Article 30 requires contracts covering critical or important functions to set out whether sub-outsourcing is permitted and under what conditions, so the entity retains visibility of the full chain, not just its direct counterparty. Skipping that visibility is one of the most common ways concentration risk gets underestimated: an entity believes it has diversified across three providers, when all three ultimately sit on the same underlying infrastructure.

The November 2025 CTPP designations changed the reference point

In November 2025, the European Supervisory Authorities published their first list of designated critical ICT third-party providers, 19 firms including major cloud and infrastructure providers, now subject to direct oversight by a Lead Overseer. That list is a useful, publicly available signal for Article 29 assessments: if a prospective or existing provider appears on it, the systemic-level concentration the ESAs identified is a strong argument for extra scrutiny at the entity level too, even though CTPP status and an individual entity's Article 29 obligations are legally distinct. A provider being outside the designated list does not mean concentration risk is absent; regional infrastructure providers and niche specialist vendors can create just as much dependency for the entities that rely on them, without ever appearing on an EU-wide list.

Building it into the register and the exit strategy

Concentration risk is not a one-time memo. It belongs in the same process as the register of information, reviewed whenever a new contract is proposed and at least annually thereafter. Two practical anchors keep it current:

  • Tag providers, not just contracts, in the register. A register organised only by contract can hide that five contracts all trace back to one parent company. Our TPP register generator builds entries in the EBA structure, which makes provider-level rollups possible from the start.
  • Treat exit strategy as the practical test of substitutability. If an entity cannot describe, in concrete terms, how it would migrate a critical function off a provider within a reasonable timeframe, the Article 29 substitutability question probably has not been answered honestly.

Common mistakes

  • Assessing at the contract level only. Article 29 is explicit that entities must look at existing exposure to the same or connected providers, not just the new contract in isolation.
  • Treating "diversified" as "concentration-free." Multiple vendor names on paper does not mean independent infrastructure underneath. Check the sub-outsourcing chain, not just the logo on the contract.
  • No documented alternatives analysis. Supervisors expect to see that alternatives were actually weighed, with a reasoned conclusion, not a box checked after the vendor was already chosen.
  • Ignoring geography. Where a provider or its subcontractors are based outside the EU affects both substitutability and the risk profile of the arrangement; it is a required factor, not an optional one.

A practical assessment approach

  1. Before any new contract for a critical or important function, list every existing arrangement with the same provider and any closely connected entities.
  2. Check whether the provider, or a subcontractor in its chain, appears on the ESAs' designated CTPP list, and note the result in the assessment.
  3. Document at least one realistic alternative provider or architecture, with the cost and disruption of switching.
  4. Confirm the contract gives visibility into sub-outsourcing, in line with Article 30.
  5. Record the conclusion, including who signed off, in the register of information and the exit-strategy documentation for that arrangement.

For a broader view of where third-party-risk management stands against the other four pillars, run the DORA Readiness Score, or work through the full compliance checklist. Entities that need outside help structuring the assessment can also start from a DORA gap assessment.

Frequently asked questions

What is ICT concentration risk under DORA?
Does DORA Article 29 ban using dominant cloud providers?
How is Article 29's entity-level assessment different from the CTPP oversight framework?
Which providers were designated as critical ICT third-party providers under DORA?
Does sub-outsourcing count toward concentration risk?
How often should a concentration risk assessment be reviewed?

Sources

Last updated: 20 July 2026.

#third-party-risk#concentration-risk#outsourcing#banks

More from the blog