← Enforcement
DORA EU 2022/2554 EU-wide

DORA CTPP register: the 19 critical ICT providers under direct EU oversight

On 18 November 2025 the EU designated its first Critical ICT Third-Party Providers (CTPPs) under DORA — 19 tech firms, from the hyperscale clouds to SAP and Bloomberg, now overseen directly by EU regulators. The full list, what designation means, and the powers behind it — sourced to the official ESA document.

Most of DORA tells banks and insurers how to manage their own technology risk. One part does something the EU had never done before: it puts the tech suppliers those firms depend on — the big clouds, SAP, Bloomberg, the telecoms — under direct EU oversight. On 18 November 2025 the first 19 of those suppliers were named. This is the register.

Quick facts

  • What it is: the official list of Critical ICT Third-Party Providers (CTPPs) — ICT suppliers judged so systemically important to the EU financial sector that EU regulators oversee them directly, not just the financial firms that use them
  • Designated: 18 November 2025 by the three European Supervisory Authorities — the EBA (banking), ESMA (markets) and EIOPA (insurance & pensions) — acting jointly (EIOPA announcement)
  • Legal basis: Article 31 of DORA (Regulation (EU) 2022/2554); the list is published under Article 31(9)
  • How many: 19 providers (official ESA list)
  • What designation triggers: a Lead Overseer (one of the three ESAs) with powers to demand information, run on-site inspections, issue recommendations, and impose periodic penalty payments of up to 1% of the provider’s average daily worldwide turnover, accruing daily for up to six months (Article 35 DORA)
  • Review: designations are reviewed annually — new providers can be added, existing ones de-designated

The 19 designated CTPPs

Names are reproduced exactly as they appear in the official ESA list (source) — including two spellings carried verbatim from the original: “Amazon web Services” (lower-case) and “International Business Machine Corporation” (singular).

#Provider (as listed)CategoryWhat they provide
1Accenture plcIT servicesIT consulting & systems integration
2Amazon web Services EMEA SarlHyperscale cloudAWS public cloud
3Bloomberg L.P.Specialised fintechFinancial data & terminals
4Capgemini SEIT servicesIT consulting & systems integration
5Colt Technology ServicesTelecom / data centreNetwork & connectivity
6Deutsche Telekom AGTelecom / data centreTelecom & connectivity
7Equinix (EMEA) B.V.Telecom / data centreData centres & colocation
8Fidelity National Information Services, Inc.Specialised fintechCore banking & payments technology (FIS)
9Google Cloud EMEA LimitedHyperscale cloudGoogle Cloud public cloud
10International Business Machine CorporationIT servicesIT services & cloud (IBM)
11InterXion HeadQuarters B.V.Telecom / data centreData centres & colocation
12Kyndryl Inc.IT servicesManaged IT infrastructure
13LSEG Data and Risk LimitedSpecialised fintechMarket data & risk (LSEG / Refinitiv)
14Microsoft Ireland Operations LimitedHyperscale cloudMicrosoft Azure public cloud
15NTT DATA Inc.IT servicesIT services & systems integration
16Oracle Nederland B.V.Hyperscale cloudOracle cloud & enterprise software
17Orange SATelecom / data centreTelecom & connectivity
18SAP SESpecialised fintechEnterprise software (ERP)
19Tata Consultancy Services LimitedIT servicesIT services & systems integration

Four practical groupings stand out: hyperscale cloud (AWS, Google Cloud, Microsoft, Oracle), IT services and systems integrators (Accenture, Capgemini, IBM, Kyndryl, NTT DATA, Tata Consultancy Services), telecom and data-centre infrastructure (Colt, Deutsche Telekom, Equinix, InterXion, Orange), and specialised financial and enterprise technology (Bloomberg, FIS, LSEG, SAP).

How a firm ends up on this list

The ESAs ran a structured assessment (EIOPA): they gathered data on financial entities’ ICT contracts, assessed each provider against the criticality criteria in Article 31(2) DORA (systemic impact if it fails, importance of the firms relying on it, reliance for critical functions, substitutability), and formally notified the providers assessed as critical — who then exercised their right to be heard before the list was finalised.

What designation does — and does not — mean

It means oversight, not a licence. A CTPP is not “authorised” or “regulated” in the financial-services sense. Each gets a Lead Overseer — one of EBA, ESMA or EIOPA — that can request information, inspect, and recommend changes, backed by penalty payments of up to 1% of daily worldwide turnover (Article 35). The full oversight regime — Lead Overseer, joint examination teams, the Oversight Forum, sub-contracting rules — is set out in the DORA pillar.

It does not make the recommendations directly enforceable against the provider. They bite through the financial entities that use it: those firms must take Lead Overseer recommendations into account in their contracts, so a CTPP that ignores oversight risks being dropped by the customers that made it critical.

What this means for you

  • If you are a financial entity using any of the 19: your ICT-third-party governance (the Article 28 register of information, the Article 30 contractual clauses) has to reflect that these are now overseen providers — and you must factor in any Lead Overseer recommendations about them.
  • If you are one of the 19 (or a likely future addition): expect information requests and on-site inspections from your Lead Overseer. The criteria are public; engaging early is materially smoother than after designation.
  • If you are tracking EU tech regulation: this is the first concrete use of DORA’s most novel power. Watch the annual review for additions — the list is a living document.

Sources