ESAs publish list of critical ICT third-party providers under DORA
The European Supervisory Authorities (ESAs), comprising the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA), have published the list of designated critical ICT third-party providers (CTPPs) under the Digital Operational Resilience Act (Regulation (EU) 2022/2554) (DORA). The designations were made in accordance with the methodology mandated by DORA. The designated CTPPs provide a range of ICT services, from core infrastructure to business and data services, supporting financial entities of varying types and sizes across the EU. Through direct oversight engagement, the ESAs will assess whether these providers have appropriate risk management and governance frameworks in place to ensure the resilience of the services they deliver. The ESAs will continue to engage with CTPPs as part of upcoming examination activities.