Critical ICT Third-Party Providers Under DORA: Designation, Opt-In and Oversight Compared
DORA creates an EU oversight framework for critical ICT third-party service providers (CTPPs). The ESAs designate them using a two-step test in RTS 2024/1502, whose first systemic-impact limb requires shares of at least 10% of both the number and the assets of financial entities in a category. A provider not on the list may opt in for a fixed fee of EUR 50,000. Designation brings direct oversight by a Lead Overseer, oversight fees, possible penalty payments and, for a supplier based outside the EU, such as in the UK, an EU subsidiary within 12 months. The contract terms that clients impose for critical or important functions apply either way.
The UK context
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and is not part of UK law. A UK-incorporated supplier is, in DORA's words, an "ICT third-party service provider established in a third country" (Article 3(24)). It is drawn in through its contracts with EU financial entities and, potentially, through designation as a CTPP. The DORA knowledge base holds EU and ESAs sources only, so it cannot say what UK rules apply to the same supplier.
One UK-specific item does appear in the base. The ESAs' DORA oversight page lists the United Kingdom under "Memoranda of Understanding with Third-Country Authorities", and records a DORA-specific equivalence assessment of the confidentiality and professional secrecy regimes of the Financial Conduct Authority and the Prudential Regulation Authority, with an overall assessment of "Equivalent". The page explains that establishing such equivalence is a prerequisite for concluding an MoU; it does not describe the MoU's contents.
Critical provider or critical function?
Keep two concepts apart. Designation as a CTPP (Article 31) concerns the supplier's systemic role across the EU financial sector. A critical or important function (Article 3(22)) concerns a single client: a function whose failure would materially impair its performance, soundness, continuity or compliance. Contract clauses on audit rights, TLPT cooperation and subcontracting follow from the second concept, not the first.
The designation criteria
The ESAs first check all step-1 sub-criteria, then apply step-2 sub-criteria to providers that pass (RTS 2024/1502, Article 1). Criteria are assessed for the group as a whole (DORA Article 31(3)).
- Systemic impact (Article 2): in at least one category of financial entities, the provider serves at least 10% of the entities and at least 10% of their total assets, for services supporting critical or important functions. Step 2 looks at the intensity of impact if services stopped, and at dependence on the same subcontractors.
- Systemic importance (Article 3): at least one G-SII, at least three O-SIIs, or one O-SII scoring above 3,000; and at least one systemic CSD, CCP, trading venue or trade repository, or at least three other systemic entities.
- Critical nature of the service (Article 4): assessed at step 2.
- Substitutability (Article 5): at least 10% of a category of entities have no alternative provider with the capacity required, or would find migration highly difficult.
Substitutability, worked through (illustrative figures)
Imagine a category of 250 financial entities. For 30 of them, no alternative provider has the capacity to deliver the same service supporting a critical or important function. 30 ÷ 250 = 12%, which is at least 10%, so the Article 5 step-1 test is met, as either limb suffices. At 20 entities (8%), it would depend on the migration-difficulty limb.
The data come mainly from the registers of information that financial entities submit (RTS Article 6), so a UK supplier's exposure is visible through its EU clients' registers. Some providers are outside designation altogether (DORA Article 31(8)), including ICT intra-group service providers, financial entities providing ICT services to other financial entities, and providers serving only one Member State's financial entities active only there.
Procedure and opt-in
After the assessment, the provider has 6 weeks to submit a reasoned statement (Article 31(5)). Oversight starts no later than one month after notification of designation, and the provider must inform its financial-entity clients. Groups designate one legal person as coordination point. The ESAs publish an updated list of CTPPs every year.
Under Article 31(11), a provider not on the list may apply to be designated. The ESAs' oversight page sets out the practicalities: a reasoned application with the information in Article 1 of RTS 2025/295 (corporate structure, estimated EU market share, services and clients, a substitutability self-assessment, business strategy), a fixed EUR 50,000 fee, an optional informal draft application, and a reply within 6 months. Non-EU entities must apply in English.
Side by side: what designation changes
Non-critical provider vs designated CTPP
| Area | Not designated | Designated as CTPP |
|---|---|---|
| Oversight | None directly; clients manage the risk | Lead Overseer (EBA, EIOPA or ESMA) supported by joint examination teams |
| Powers | Contractual audit rights of clients | Information requests, general investigations, inspections, recommendations (Article 35) |
| Responding to findings | Contract-driven | 60 calendar days to accept recommendations or explain why not; non-compliance may be disclosed publicly (Article 42) |
| Penalties | None under DORA | Up to 1% of average daily worldwide turnover, daily, for up to six months |
| Fees | None | Oversight fees proportionate to turnover |
| Location | No requirement | Third-country CTPP needs an EU subsidiary within 12 months of designation (Article 31(12)) and must notify changes to its management structure |
For premises outside the EU, such as a UK data centre, Article 36 lets the Lead Overseer exercise information and inspection powers only where it cannot meet its objectives through the EU subsidiary or EU premises, the inspection is necessary and directly linked to services for EU financial entities, the provider consents, and the third-country authority has been officially notified and has not objected. Where it cannot carry out such oversight, the Lead Overseer acts on the facts available and records the consequences, which feed into its recommendations. As a last resort, competent authorities may require EU financial entities to suspend use of a CTPP's service (Article 42(6)).
Contract terms that apply regardless of status
For ICT services supporting critical or important functions, DORA Article 30(3) requires, among other things, precise service levels, business contingency plans, cooperation in TLPT, unrestricted access, inspection and audit rights for the client and its competent authority, and exit strategies with a mandatory transition period. Article 30(2)(b) also requires the contract to state where services are provided and data processed, with advance notice of changes.
RTS 2025/532 governs subcontracting of those services: subcontractors must grant the same access and inspection rights as the provider (Article 3(1)(d)); the provider must give notice of material changes and may only implement them once the client has approved or not objected by the end of the notice period (Article 5(3)); and the client may terminate if this is ignored (Article 6).
Action points for UK suppliers
- Identify EU clients relying on you for critical or important functions, by entity category.
- Benchmark your entity and asset shares against the 10% thresholds.
- Align standard contracts with Article 30(3) and RTS 2025/532.
- Consider how you would set up and run an EU subsidiary within 12 months of designation.
- Weigh an opt-in application against the EUR 50,000 fee and the oversight it brings.
To check a scenario against the texts, ask the DORA knowledge base, for instance: "How much does an ICT provider have to pay to voluntarily apply (opt in) for critical designation under DORA's oversight framework?"
Cited answers on DORA oversight
Query DORA, RTS 2024/1502, RTS 2025/295, RTS 2025/532 and the ESAs' oversight page in plain English, with a citation on every answer.
This comparison explains the rules; it is not legal advice. Sources: RTS 2024/1502 on EUR-Lex, DORA on EUR-Lex and the ESAs' oversight page.
Frequently asked questions
Can a UK ICT provider be designated as critical under DORA?
DORA's designation applies to ICT third-party providers serving EU financial entities, including those established in a third country. If designated, EU financial entities may only keep using a third-country CTPP that establishes an EU subsidiary within 12 months (Article 31(12)).
What is the DORA oversight framework?
The regime in Articles 31 to 44 of DORA under which the ESAs designate critical ICT providers and a Lead Overseer oversees each one through information requests, investigations, inspections and recommendations.
How does the DORA opt-in work?
A provider not on the CTPP list submits a reasoned application to the ESAs with the information in Article 1 of RTS 2025/295, pays a fixed EUR 50,000 fee, and receives a decision within 6 months. Non-EU entities must apply in English.
Does the ESAs' oversight page mention the UK?
Yes. It lists the United Kingdom under memoranda of understanding with third-country authorities and records an equivalence assessment of the FCA and PRA confidentiality and professional secrecy regimes, assessed as equivalent.
Can the Lead Overseer inspect premises in the UK?
Under Article 36, only if necessary, directly related to services for EU financial entities, with the provider's consent, and after official notification of the third-country authority without objection.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.