A small group of ICT firms, mostly hyperscale cloud and core infrastructure providers, are designated critical ICT third-party providers (CTPPs) under Article 31 and placed under direct EU oversight led by a Lead Overseer. Once designated, a CTPP pays an annual oversight fee set by Commission Delegated Regulation (EU) 2024/1505, and it has a formal right to challenge both the designation and the Lead Overseer's decisions before the ESAs' Joint Board of Appeal. Here is how designation, fees, and appeals actually work in practice.
What makes a provider "critical" in the first place
The Oversight Framework (Articles 31-44) does not apply to every ICT supplier a bank or insurer uses. The European Supervisory Authorities (EBA, ESMA, and EIOPA, acting jointly) designate a provider as critical only when it cumulatively meets four criteria: the systemic impact a large-scale failure at the provider would have on financial stability, the systemic importance of the financial entities that depend on it, how far financial entities rely on the same provider for critical or important functions, and how substitutable the provider actually is. That last criterion does most of the work in practice: a provider that dominates a narrow, hard-to-replace niche, such as a specific core banking platform or a hyperscale cloud region, is far more likely to be designated than a larger firm whose services are easy to switch away from.
The ESAs draw the raw material for this assessment from the registers of information that every financial entity must maintain under Article 28, which record every ICT third-party arrangement supporting a critical or important function. The first designation round, published 18 November 2025, named 19 providers spanning core cloud infrastructure, data and analytics services, and business-process platforms. It will not be the last: the ESAs review the market annually, and providers can also request voluntary designation under Article 31(11) if they want the legal certainty (and the marketing signal to EU financial-sector clients) that comes with it.
Designation is not a surprise letter, it comes with a right to respond
Before a designation becomes final, the ESAs notify the provider that it has been assessed as potentially critical and give it a window (roughly six weeks in the first round) to submit a reasoned statement contesting the assessment. The ESAs can request further information within 30 calendar days to help them decide. Only after that exchange do they confirm the designation and assign a Lead Overseer, chosen from the three ESAs according to which one regulates the largest share of the financial entities relying on the provider.
This matters for ICT third-party providers generally, not only the ones eventually designated: any firm supplying critical or important functions to enough EU financial entities should assume it could be assessed in a future round, and should have its own evidence ready (substitutability, market share, incident history) rather than treating designation as something that only happens to obvious hyperscalers.
What Lead Overseer oversight actually involves
Once designated, a CTPP does not deal with dozens of national supervisors individually for this purpose. A single Lead Overseer, supported by a Joint Examination Team drawn from across the ESAs and national competent authorities, becomes the provider's direct counterpart. Under Articles 33 and 37-40, the Lead Overseer can request any information relevant to the provider's ICT risk management, run general investigations and on-site inspections, and issue recommendations on security, resilience, and sub-outsourcing practices. A provider that fails to address a recommendation can face periodic penalty payments of up to 1% of its average daily worldwide turnover until it complies. The structure of the framework also gives supervisors, separately, the power to require a financial entity to suspend or terminate its own contract with a critical provider whose risks are not being adequately mitigated, which is why CTPP status affects the provider's clients as much as the provider itself.
Oversight fees: who pays, how much, and when
Article 43 lets the Lead Overseer recover the full cost of running this regime from the providers it oversees, and Commission Delegated Regulation (EU) 2024/1505 of 22 February 2024 sets out exactly how. The fee is calculated to cover the Lead Overseer's and the other ESAs' necessary oversight expenditure for that provider, apportioned using the provider's relevant EU turnover as the basis rather than a flat per-provider charge, so larger, more deeply embedded providers carry a larger share of the cost. A provider designated as of 1 January in a given year must pay its fee by 30 April of that year; a provider designated partway through the year pays by 31 December instead. Providers that request a voluntary designation under Article 31(11) face an additional fixed fee on top of the standard charge, reflecting the extra assessment work that request creates.
None of this cost is passed through as a line item to the financial entities that use the provider, at least not directly. It sits with the CTPP as a cost of doing systemically important business in the EU, alongside the compliance resourcing needed to respond to inspections and recommendations on an ongoing basis.
The appeal route: the Joint Board of Appeal
A designated provider is not without recourse. Under Article 60(1) of the regulations establishing the ESAs, a CTPP can lodge a complaint against a designation decision, or against a specific oversight measure such as a recommendation or penalty, with the ESAs' joint Board of Appeal, an independent body separate from the ESAs' own supervisory staff. This is the same appeal mechanism the ESAs use across other EU financial-services oversight regimes, not a DORA-specific tribunal, and its decisions can in turn be challenged before the Court of Justice of the EU. For a provider, the appeal route matters most in two situations: disputing whether it truly meets the substitutability and systemic-impact criteria in the first place, and disputing a specific finding or penalty rather than the designation itself.
What this means if you are the client, not the provider
Most readers of this site are financial entities managing their own third-party risk, not the small number of firms actually designated as CTPPs. Three practical implications follow from the oversight regime described above:
- A CTPP badge is not a compliance guarantee. Oversight targets the provider's own resilience; it does not replace your obligation under Articles 28-30 to run your own due diligence, contractual reviews, and exit-strategy planning for that provider.
- Watch for Lead Overseer recommendations that name your provider. A public enforcement action or recommendation against a CTPP you rely on is exactly the kind of development your own ICT risk-management framework should be tracking, since supervisors can require you to suspend or terminate the contract if the underlying risk goes unaddressed.
- Concentration risk assessments should reflect the current CTPP list. If a function you outsource sits with a designated provider, your concentration-risk review and your ICT third-party register should say so explicitly, not just describe the provider generically.
A broader read on where your third-party risk programme stands is available through the DORA Readiness Score, and firms weighing whether a specific cloud dependency needs a formal review can start with a cloud resilience assessment.
Frequently asked questions
What is a critical ICT third-party provider (CTPP) under DORA?
How much are DORA oversight fees, and who pays them?
When are DORA oversight fees due?
Can a provider appeal a critical designation?
Does CTPP oversight replace a financial entity's own third-party risk duties?
How many providers have been designated critical so far?
Sources
- European Supervisory Authorities, ESAs specify criticality criteria and oversight fees for critical ICT third-party providers under DORA, ESMA.
- Commission Delegated Regulation (EU) 2024/1505 of 22 February 2024, EUR-Lex.
- Regulation (EU) 2022/2554 (DORA), Articles 31-44 and Article 60 (via the ESA founding regulations), EUR-Lex.
Last updated: 3 August 2026.