Skip to main content
DORA Auditor

DORA for Critical ICT Third-Party Providers

Last updated: 2 authoritative sourcesDORA Auditor Editorial Team

Critical ICT third-party providers (CTPPs) are the systemic cloud, software and infrastructure firms designated under Article 31. Uniquely under DORA, they are subject to a direct EU oversight framework (Articles 31–44), led by a Lead Overseer with powers to examine, recommend, and levy penalties.

How designation works

The European Supervisory Authorities designate CTPPs based on criteria such as the systemic impact of a failure, the systemic importance of the financial entities relying on them, and the degree of substitutability. Designation is not about company size alone but about concentration and concentration risk in the financial system.

What oversight involves

  • A designated Lead Overseer (one of the ESAs) coordinates supervision.
  • Powers to request information, conduct inspections, and issue recommendations.
  • Periodic penalty payments of up to 1% of average daily worldwide turnover to compel compliance.

Preparing for the framework

Prospective CTPPs should map their EU financial-sector footprint, formalise resilience and sub-outsourcing controls, and align with the oversight framework expectations. See DORA penalties for enforcement detail.

Oversight fees and the right to appeal

Direct EU oversight is not free to the designated provider. Under Commission Delegated Regulation (EU) 2024/1505, the Lead Overseer charges an annual oversight fee calculated to cover the ESAs' actual supervision costs and apportioned across designated CTPPs broadly by turnover, due in two instalments (30 April and 31 December). A provider that voluntarily opts into the regime under Article 31(11), rather than being designated outright, pays an additional fixed fee of EUR 50,000. Providers that disagree with a Lead Overseer decision, a fee assessment, or a designation itself are not left without recourse: Article 60 of the ESAs' founding regulations gives them the right to challenge it before the Joint Board of Appeal. See our guide to CTPP oversight fees and the appeals process for how the fee calculation and the Board of Appeal route actually work.

Frequently asked questions

Who decides which providers are critical?
What is a Lead Overseer?
Can critical providers be fined?
Do critical ICT providers pay for their own oversight?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  2. ESMA, Digital Operational Resilience Act (DORA)