Most of DORA tells banks and insurers how to manage their own technology risk. One part does something the EU had never done before: it puts the tech suppliers those firms depend on — the big clouds, SAP, Bloomberg, the telecoms — under direct EU oversight. On 18 November 2025 the first 19 of those suppliers were named. This is the register.
Quick facts
- What it is: the official list of Critical ICT Third-Party Providers (CTPPs) — ICT suppliers judged so systemically important to the EU financial sector that EU regulators oversee them directly, not just the financial firms that use them
- Designated: 18 November 2025 by the three European Supervisory Authorities — the EBA (banking), ESMA (markets) and EIOPA (insurance & pensions) — acting jointly (EIOPA announcement)
- Legal basis: Article 31 of DORA (Regulation (EU) 2022/2554); the list is published under Article 31(9)
- How many: 19 providers (official ESA list)
- What designation triggers: a Lead Overseer (one of the three ESAs) with powers to demand information, run on-site inspections, issue recommendations, and impose periodic penalty payments of up to 1% of the provider’s average daily worldwide turnover, accruing daily for up to six months (Article 35 DORA)
- Review: designations are reviewed annually — new providers can be added, existing ones de-designated
The 19 designated CTPPs
Names are reproduced exactly as they appear in the official ESA list (source) — including two spellings carried verbatim from the original: “Amazon web Services” (lower-case) and “International Business Machine Corporation” (singular).
| # | Provider (as listed) | Category | What they provide |
|---|---|---|---|
| 1 | Accenture plc | IT services | IT consulting & systems integration |
| 2 | Amazon web Services EMEA Sarl | Hyperscale cloud | AWS public cloud |
| 3 | Bloomberg L.P. | Specialised fintech | Financial data & terminals |
| 4 | Capgemini SE | IT services | IT consulting & systems integration |
| 5 | Colt Technology Services | Telecom / data centre | Network & connectivity |
| 6 | Deutsche Telekom AG | Telecom / data centre | Telecom & connectivity |
| 7 | Equinix (EMEA) B.V. | Telecom / data centre | Data centres & colocation |
| 8 | Fidelity National Information Services, Inc. | Specialised fintech | Core banking & payments technology (FIS) |
| 9 | Google Cloud EMEA Limited | Hyperscale cloud | Google Cloud public cloud |
| 10 | International Business Machine Corporation | IT services | IT services & cloud (IBM) |
| 11 | InterXion HeadQuarters B.V. | Telecom / data centre | Data centres & colocation |
| 12 | Kyndryl Inc. | IT services | Managed IT infrastructure |
| 13 | LSEG Data and Risk Limited | Specialised fintech | Market data & risk (LSEG / Refinitiv) |
| 14 | Microsoft Ireland Operations Limited | Hyperscale cloud | Microsoft Azure public cloud |
| 15 | NTT DATA Inc. | IT services | IT services & systems integration |
| 16 | Oracle Nederland B.V. | Hyperscale cloud | Oracle cloud & enterprise software |
| 17 | Orange SA | Telecom / data centre | Telecom & connectivity |
| 18 | SAP SE | Specialised fintech | Enterprise software (ERP) |
| 19 | Tata Consultancy Services Limited | IT services | IT services & systems integration |
Four practical groupings stand out: hyperscale cloud (AWS, Google Cloud, Microsoft, Oracle), IT services and systems integrators (Accenture, Capgemini, IBM, Kyndryl, NTT DATA, Tata Consultancy Services), telecom and data-centre infrastructure (Colt, Deutsche Telekom, Equinix, InterXion, Orange), and specialised financial and enterprise technology (Bloomberg, FIS, LSEG, SAP).
How a firm ends up on this list
The ESAs ran a structured assessment (EIOPA): they gathered data on financial entities’ ICT contracts, assessed each provider against the criticality criteria in Article 31(2) DORA (systemic impact if it fails, importance of the firms relying on it, reliance for critical functions, substitutability), and formally notified the providers assessed as critical — who then exercised their right to be heard before the list was finalised.
What designation does — and does not — mean
It means oversight, not a licence. A CTPP is not “authorised” or “regulated” in the financial-services sense. Each gets a Lead Overseer — one of EBA, ESMA or EIOPA — that can request information, inspect, and recommend changes, backed by penalty payments of up to 1% of daily worldwide turnover (Article 35). The full oversight regime — Lead Overseer, joint examination teams, the Oversight Forum, sub-contracting rules — is set out in the DORA pillar.
It does not make the recommendations directly enforceable against the provider. They bite through the financial entities that use it: those firms must take Lead Overseer recommendations into account in their contracts, so a CTPP that ignores oversight risks being dropped by the customers that made it critical.
What this means for you
- If you are a financial entity using any of the 19: your ICT-third-party governance (the Article 28 register of information, the Article 30 contractual clauses) has to reflect that these are now overseen providers — and you must factor in any Lead Overseer recommendations about them.
- If you are one of the 19 (or a likely future addition): expect information requests and on-site inspections from your Lead Overseer. The criteria are public; engaging early is materially smoother than after designation.
- If you are tracking EU tech regulation: this is the first concrete use of DORA’s most novel power. Watch the annual review for additions — the list is a living document.
Sources
- Official ESA list of designated CTPPs (Article 31(9) DORA) — the 19 names, verbatim
- EIOPA — ESAs designate Critical ICT Third-Party Providers, 18 November 2025
- Regulation (EU) 2022/2554 (DORA) — EUR-Lex — Articles 31 (designation) and 35 (penalty payments)
- Related: DORA pillar · EBA · ESMA · EIOPA