Comparison

Critical vs Non-Critical ICT Third-Party Providers Under DORA: Designation Criteria and What Changes

The Kopik team8 min read

Under DORA, the European Supervisory Authorities (EBA, EIOPA and ESMA) designate an ICT provider as critical (a CTPP) after a two-step assessment set out in Commission Delegated Regulation (EU) 2024/1502. The first systemic-impact test is met where the provider serves at least 10% of the financial entities in a category, and at least 10% of that category's assets, for services supporting critical or important functions. A designated provider comes under direct EU oversight by a Lead Overseer. Providers not on the list can opt in for a fixed EUR 50,000 fee. For US providers there is a key extra rule: EU financial entities may only keep using a third-country CTPP if it sets up an EU subsidiary within 12 months of designation.

Two different meanings of "critical"

DORA uses "critical" in two ways, and mixing them up is the most common error in vendor negotiations:

  • A critical ICT third-party service provider (CTPP) is a provider designated by the ESAs under Article 31. Designation is about the provider's systemic weight across the EU financial sector, and it triggers EU oversight of the provider.
  • An ICT service supporting a critical or important function is a client-level concept (Article 3(22)): a function whose disruption would materially impair the financial entity's performance, soundness, continuity or compliance. It drives the contractual requirements of Article 30(3) and the subcontracting rules of RTS 2025/532, whether or not the provider is designated.

So a small US SaaS vendor that will never be designated can still face audit rights, TLPT cooperation and subcontracting approval clauses, because its client uses the service for a critical or important function. Designation adds a second layer on top.

How designation works: the step-1 and step-2 tests

Article 31(2) of DORA sets four criteria: systemic impact, the systemic character of the entities that rely on the provider, reliance for critical or important functions, and substitutability. RTS 2024/1502 turns them into a two-step test. A provider must meet all the step-1 sub-criteria, then is assessed against step-2 sub-criteria (Article 1).

Step-1 sub-criteria under RTS 2024/1502

CriterionStep-1 test
Systemic impact (Art. 2)For at least one category of financial entities, both the share of entities served and the share of their total assets are at least 10%, counting only services that support critical or important functions
Systemic importance (Art. 3)Services used by at least one G-SII, or at least three O-SIIs, or one O-SII with a score above 3,000; and, for other entities identified as systemic, at least one CSD, CCP, trading venue or trade repository, or at least three other systemic entities
Critical functions (Art. 4)Assessed at step 2 only: whether the service is of a critical nature for the entities' activities
Substitutability (Art. 5)At least 10% of a category of entities either have no alternative provider with the required capacity, or would find migration highly difficult

The 10% test, worked through (illustrative figures)

Suppose a category of financial entities has 400 firms with EUR 2,000 billion of total assets. A provider supports critical or important functions at 48 of them, holding EUR 260 billion. Shares: 48 ÷ 400 = 12% of entities and 260 ÷ 2,000 = 13% of assets. Both are at least 10%, so the Article 2 step-1 sub-criteria are met for that category. If it served 48 firms holding only EUR 150 billion (7.5%), the test would fail, since both shares must reach 10%.

Step 2 then looks at the intensity of the impact of discontinuing the service, dependence on the same subcontractors (applied from 16 January 2025 under Article 7), interdependence among G-SIIs and O-SIIs, the critical nature of the service, and the lack of real alternatives. The ESAs rely mainly on the registers of information that financial entities file (Article 6), which is why your clients' registers matter to you. For groups, the criteria are assessed for the group as a whole (DORA Article 31(3)).

Some providers cannot be designated at all (Article 31(8)): financial entities providing ICT services to other financial entities, providers under the oversight frameworks supporting Article 127(2) TFEU, ICT intra-group service providers, and providers serving financial entities in only one Member State that are active only there.

The designation procedure and the opt-in route

  1. The Lead Overseer notifies the provider of the assessment outcome; the provider has 6 weeks to submit a reasoned statement, and may be asked for more information within 30 calendar days (Article 31(5)).
  2. Once designated, the provider is told the start date of oversight, no later than one month after notification, and must notify its financial-entity clients of its designation.
  3. The ESAs publish and update the list of CTPPs yearly (Article 31(9)).

A provider not on the list can ask to be designated under Article 31(11). According to the ESAs' oversight page, the reasoned application must contain the information in Article 1 of RTS 2025/295, including corporate structure, estimated EU market share, the services and financial-entity clients concerned, and a self-assessment of substitutability. It carries a fixed opt-in fee of EUR 50,000, and the ESAs reply within 6 months. For a group, the information covers the group's ICT services as a whole, and non-EU entities are required to submit applications in English.

What changes once a provider is designated

Non-critical vs critical ICT third-party provider

TopicNon-designated providerDesignated CTPP
Who supervisesIndirectly, through its financial-entity clientsDirectly overseen by a Lead Overseer (one of the ESAs), with joint examination teams
Information and inspectionsThrough contractual audit and access rightsLead Overseer may request information, run general investigations and inspections, and issue recommendations (Article 35)
SubcontractingGoverned by client contracts and RTS 2025/532Lead Overseer may also recommend refraining from certain third-country subcontracting for critical or important functions
SanctionsContractual remedies onlyPeriodic penalty payments of up to 1% of average daily worldwide turnover, daily, for up to six months
FeesNoneOversight fees covering the Lead Overseer's costs, proportionate to turnover (Article 43)
EU presenceNo DORA requirementA third-country CTPP must establish an EU subsidiary within 12 months for clients to keep using it (Article 31(12))
GroupNo requirementDesignate one legal person as coordination point (Article 31(4))

A CTPP has 60 calendar days to say whether it will follow the Lead Overseer's recommendations or explain why not (Article 42(1)). Failures are disclosed publicly. As a last resort, competent authorities can require financial entities to suspend, in part or completely, the use of a CTPP's service until the risks are addressed (Article 42(6)). For US providers, Article 36 allows the Lead Overseer to inspect premises outside the EU used to serve EU financial entities, but only if the inspection is necessary and directly related to those services, the provider consents, and the relevant third-country authority has been notified and raised no objection.

What does not change: contract terms for critical or important functions

Whatever a provider's status, contracts for ICT services supporting critical or important functions must include the Article 30(3) terms: precise service levels, notice and reporting duties, business contingency plans, TLPT cooperation, unrestricted rights of access, inspection and audit for the entity and its competent authority, and exit strategies with a mandatory transition period. Microenterprises may agree to delegate audit rights to an independent third party appointed by the provider.

RTS 2025/532 adds subcontracting rules. Before allowing subcontracting, the entity must check, among other conditions, that the subcontractor grants it and the authorities the same rights of access and inspection as the provider (Article 3(1)(d)). The provider must give notice of material changes to subcontracting and may only implement them after the entity approves or does not object by the end of the notice period (Article 5(3)). The contract may allow termination if the provider pushes changes through anyway (Article 6).

Checklist for US ICT providers

  • Map which EU clients use your services for critical or important functions, and in which entity categories.
  • Estimate your shares of entities and assets per category against the 10% thresholds.
  • Prepare Article 30(3) and RTS 2025/532 contract language now; it applies regardless of designation.
  • Plan for an EU subsidiary if designation is plausible.
  • Decide whether opting in, with its EUR 50,000 fee and English-language application, makes strategic sense.

To test a specific scenario, ask the DORA knowledge base: for example, "Our cloud provider isn't on the ESAs' published list of critical ICT third-party providers. Can it still ask to be designated as critical?"

Search the CTPP rules with citations

The DORA base covers Articles 28 to 44 of DORA, RTS 2024/1502, RTS 2025/295, RTS 2025/532 and the ESAs' oversight page, with every answer tied to its source.

This comparison is informational and not legal advice. Official texts: RTS 2024/1502 on EUR-Lex, RTS 2025/532 on EUR-Lex and the ESAs' DORA oversight page.

Frequently asked questions

What is a critical ICT third-party service provider under DORA?

An ICT provider designated as critical by the ESAs under Article 31 of DORA, using the criteria in RTS 2024/1502. It is then overseen directly by a Lead Overseer.

What is the 10% threshold for CTPP designation?

Under Article 2(4) of RTS 2024/1502, the step-1 systemic-impact test is met where both the share of financial entities served and the share of their total assets are at least 10% for at least one category of financial entities, counting services supporting critical or important functions.

How much does it cost to opt in for critical designation?

A fixed opt-in fee of EUR 50,000, according to the ESAs' DORA oversight page. The ESAs reply within 6 months of receiving the reasoned application.

Must a US provider set up an EU entity if designated critical?

Article 31(12) of DORA says financial entities may only use a third-country provider designated as critical if it has established a subsidiary in the Union within the 12 months following designation.

Do audit and subcontracting clauses only apply to critical providers?

No. They apply to contracts for ICT services supporting critical or important functions of the financial entity (DORA Article 30(3) and RTS 2025/532), whether or not the provider is designated.

What penalties can a Lead Overseer impose?

Periodic penalty payments of up to 1% of the CTPP's average daily worldwide turnover in the preceding business year, imposed daily for up to six months (Article 35(6) to (8)).

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.