📣 Send us your press release
Site updates every 15 minutes
Professional Services

EU Designates 19 Critical ICT Third-Party Providers Under DORA

European Supervisory Authorities (ESAs) have identified 19 critical information and communication technology (ICT) third-party providers under the EU's Digital Operational Resilience Act (DORA). The selection focuses on major cloud service providers and other key technology platforms.

26 July 2026
EU Designates 19 Critical ICT Third-Party Providers Under DORA

The European Supervisory Authorities (EBA, ESMA, and EIOPA) have released the first list of 19 critical information and communication technology (ICT) third-party providers under the EU's Digital Operational Resilience Act (DORA). These companies, including major cloud platforms like Amazon Web Services, Google Cloud, and Microsoft, provide essential technology services to financial entities across the EU.

DORA, which became effective in January 2025, aims to enhance the digital operational resilience of the financial sector, particularly concerning risks associated with the concentration of ICT service providers. This initial list represents a significant step in the implementation of the DORA framework and includes hyperscalers as well as network and data center providers, and specialized ICT service suppliers.

The designated 19 providers, such as Accenture, Bloomberg, Deutsche Telekom, and SAP, will now be subject to direct European oversight. Their designation is based on the criticality of their services to the operations of financial institutions and the potential systemic impact of any disruptions.

The DORA oversight framework designates one of the three European authorities as the 'Lead Overseer' for each provider, supported by Joint Examination Teams. Critical providers will face enhanced obligations, including reporting major incidents, conducting risk assessments, and undergoing regular audits.

Despite the increased oversight, financial entities retain their operational responsibility for outsourced services. DORA establishes a unified EU-wide supervisory regime without diminishing the financial institutions' own accountability for digital operational resilience.

Original source: bdo.de