European Supervisory Authorities Designate the First Critical ICT Third-Party Providers Under DORA
On November 18, 2025, the three European Supervisory Authorities (the EBA, EIOPA and ESMA) published their first list of critical ICT third-party service providers designated under the Digital Operational Resilience Act, Regulation (EU) 2022/2554. The designated providers span core infrastructure, business and data services supplied to financial entities across the EU, and they now come under direct oversight by the ESAs rather than being supervised only indirectly through their financial-sector customers. DORA itself has applied since January 17, 2025 under Article 64.
Key Analytics
Impact Analysis
For technology vendors outside the EU, the significant point is not the designation list; it is what DORA already requires of every EU financial entity that buys from you. Articles 28 to 30 oblige banks, insurers, payment institutions and investment firms to hold specific contractual terms with each ICT third-party provider and to record every arrangement in a Register of Information. Where a service supports what DORA calls a critical or important function, those contracts must additionally carry performance targets, audit and access rights, exit and transition provisions, and the provider's participation in threat-led penetration testing. A US SaaS or infrastructure company is rarely in scope in its own right, yet it inherits these terms the moment a European financial customer sends a DORA addendum. Firms that cannot evidence audit rights, documented exit plans or resilience testing are finding the contract, not the regulation, is what stalls the deal.
Recommended Actions
- Identify which of your customers are EU financial entities subject to DORA, since their obligations reach you through contract rather than through direct regulation
- Review existing agreements against the Article 30 contractual requirements and separate the baseline terms from the enhanced set that applies to critical or important functions
- Prepare the evidence a DORA addendum will ask you to stand behind: audit and access rights, subcontracting disclosure, service levels, and a documented exit and transition plan
- Confirm whether any of your services would be treated as supporting a critical or important function, because that determination drives the heavier contractual set and possible participation in threat-led penetration testing
- Give customers the information they need for their Register of Information, including service descriptions, processing locations and subcontracting chains
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Lessons-learned review
- ›Targeted control hardening
- ›Incident response validation
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 35 to 110 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.