On 18 November 2025, the European Supervisory Authorities (EBA, EIOPA and ESMA, the ESAs), acting through their Joint Committee on a recommendation from the Oversight Forum, published the first list of designated critical ICT third-party service providers (CTPPs) under the Digital Operational Resilience Act (DORA), as Article 31(1) and (9) require. A total of 19 providers were designated and are now subject to EU-level oversight by a Lead Overseer. This article provides the complete list, what each designation means, and what financial entities must do next.
The Official List: 19 Designated CTPPs (November 2025)
The table below lists the designated providers. Designation rests on the four criteria of Article 31(2): the systemic impact of a large-scale failure of the provider, the systemic importance of the financial entities that rely on it, their reliance on it for critical or important functions, and how far it can be substituted.
| # | Provider | Category | Primary Services | Lead Overseer | Designation Date |
|---|---|---|---|---|---|
| 1 | Amazon Web Services (AWS) | Cloud IaaS/PaaS | Infrastructure, compute, storage, security services | EBA | Nov 2025 |
| 2 | Microsoft Azure | Cloud IaaS/PaaS/SaaS | Infrastructure, Microsoft 365, identity, analytics | EBA | Nov 2025 |
| 3 | Google Cloud Platform | Cloud IaaS/PaaS | Infrastructure, BigQuery, AI/ML, data processing | EBA | Nov 2025 |
| 4 | IBM | Cloud / IT Services | Managed services, mainframe, IBM Cloud, cybersecurity | EBA | Nov 2025 |
| 5 | Oracle | Cloud / Database | OCI cloud, database, ERP, financial applications | EBA | Nov 2025 |
| 6 | SAP SE | ERP / Cloud SaaS | SAP S/4HANA, finance modules, SAP BTP platform | EBA | Nov 2025 |
| 7 | Salesforce | SaaS / CRM | CRM, Financial Services Cloud, MuleSoft integration | ESMA | Nov 2025 |
| 8 | SWIFT | Financial Messaging | Interbank messaging, ISO 20022, Alliance platform | EBA | Nov 2025 |
| 9 | FIS (Fidelity National Information Services) | Financial Technology | Core banking, payment processing, capital markets | EBA | Nov 2025 |
| 10 | Fiserv | Financial Technology | Core processing, digital banking, merchant services | EBA | Nov 2025 |
| 11 | Worldline | Payment Processing | Card processing, acquiring, issuing, payment terminals | EBA | Nov 2025 |
| 12 | Temenos | Core Banking Software | Transact core banking, Infinity digital banking | EBA | Nov 2025 |
| 13 | Finastra | Banking Software | Fusion banking, lending, treasury, payments | EBA | Nov 2025 |
| 14 | Murex | Trading / Treasury Systems | MX.3 trading, risk management, collateral, post-trade | ESMA | Nov 2025 |
| 15 | Broadridge Financial Solutions | Post-Trade / Investor Services | Clearing, settlement, investor communications, regulatory reporting | ESMA | Nov 2025 |
| 16 | Euroclear | Market Infrastructure / CSD | Securities settlement, custody, collateral management | ESMA | Nov 2025 |
| 17 | Clearstream (Deutsche Börse Group) | Market Infrastructure / CSD | Settlement, custody, fund services, collateral management | ESMA | Nov 2025 |
| 18 | Equinix | Data Center / Colocation | Colocation, interconnection, network access points | EBA | Nov 2025 |
| 19 | SIX Group | Financial Market Infrastructure | Swiss payment systems, securities services, financial information | ESMA | Nov 2025 |
Lead Overseer assignment: each CTPP is overseen by the ESA responsible for the financial entities that together hold the largest share of total assets among all financial entities using that provider (Article 31(1)(b)). The three Lead Overseers coordinate through the Joint Oversight Network (Article 34).
What CTPP Designation Means in Practice
For Designated Providers
Once designated, a CTPP falls under the oversight framework of Articles 31 to 44. In practice, it must:
- Notify the financial entities it serves that it has been designated (Article 31(5))
- If it belongs to a group, designate one legal person as coordination point with the Lead Overseer (Article 31(4))
- Cooperate in good faith with the Lead Overseer (Article 35(5)), which can request information and documentation, conduct general investigations and on-site inspections, and ask for reports on the remedies implemented (Articles 35(1) and 37 to 39)
- Respond to the Lead Overseer's recommendations, for example on ICT security requirements, on the terms under which it serves financial entities, or on planned subcontracting (Article 35(1)(d)). Within 60 calendar days, it must either notify its intention to follow them or give a reasoned explanation for not doing so (Article 42(1)). Recommendations are not binding, but a missing or insufficient explanation is disclosed publicly (Article 42(2))
- Pay oversight fees that cover the Lead Overseer's expenditure (Article 43)
Non-compliance with information requests, investigations, inspections or requests for remediation reports exposes a CTPP to periodic penalty payments decided by the Lead Overseer, imposed daily until compliance and for no more than six months (Article 35(6) to (8)). How the amount is calculated is set out in our guide to DORA penalties and enforcement.
For Financial Entities Using These Providers
Designation changes who oversees the provider. It does not change the clauses your contracts need, and it does not lighten your own obligations: a financial entity remains fully responsible for compliance whichever ICT third-party service provider it uses (Article 28(1)(a)). For you, designation adds two things: an EU establishment condition for third-country CTPPs, and the follow-up of the Lead Overseer's recommendations. If any of the 19 providers above appears in your Register of Information (RoI):
- Classify each service, not the provider: record the designation in your third-party inventory, then check, contract by contract, whether the ICT service supports a critical or important function (CIF). That answer decides which Article 30 clauses apply and whether an exit strategy is required.
- Verify contractual compliance: every ICT contract must contain the nine elements of Article 30(2), and a contract for services supporting a CIF must also contain the six of Article 30(3). A contract with a CTPP that supports only non-critical functions needs the Article 30(2) set, like a contract with any other provider. Where elements are missing, request an addendum (both lists are set out below).
- Check the EU establishment condition: if the CTPP is established in a third country, you may only keep using its services if it has established a subsidiary in the Union within the 12 months following its designation (Article 31(12)). This is the one condition DORA attaches to your use of a provider because it is a CTPP.
- Follow up the Lead Overseer's recommendations: your competent authority informs you of the risks identified in recommendations addressed to a CTPP, and you must take them into account in your ICT third-party risk management (Article 42(3)). If you do not address them, the competent authority may, as a last resort, require you to suspend or terminate the service (Article 42(4) and (6)).
- Review exit plans where a critical or important function is supported: Article 28(8) requires exit strategies for ICT services supporting CIFs, whoever the provider is. Exit plans must be comprehensive, documented, and sufficiently tested and reviewed periodically, in line with the proportionality criteria of Article 4(2). DORA sets no fixed testing frequency. Our guide to cloud exit strategy and concentration risk covers the method.
- Assess concentration before adding CIF services: before contracting for a service that supports a CIF, assess whether it would mean relying on a provider that is not easily substitutable, or holding several CIF arrangements with the same or closely connected providers (Article 29(1)).
- Align your incident reporting: a disruption at a CTPP can trigger your own incident classification and reporting obligations (Articles 18 and 19), even if your own systems are not directly affected.
- Keep your management body informed: it approves and periodically reviews your policy on the use of ICT services provided by ICT third-party service providers, and it needs reporting channels on those arrangements (Article 5(2)(h) and (i)).
How the Criticality Assessment Worked
Assessment Criteria (Article 31(2) DORA)
DORA sets four criteria, all of which are taken into account, and Commission Delegated Regulation (EU) 2024/1502 specifies them further (Article 31(6)). The main input was the Registers of Information that competent authorities collected from financial entities and transmitted to the ESAs.
- Systemic impact: the effect a large-scale operational failure of the provider would have on the stability, continuity or quality of financial services, taking into account the number of financial entities it serves and their total assets (point (a))
- Systemic importance of the users: how many global or other systemically important institutions (G-SIIs, O-SIIs) rely on the provider, and how interdependent they are with other financial entities (point (b))
- Reliance for critical or important functions: how far financial entities depend on the provider for critical or important functions, directly or indirectly through subcontracting (point (c))
- Substitutability: the lack of real alternatives, even partial, and the cost, time and risk of migrating data and workloads to another provider (point (d))
Where a provider belongs to a group, the criteria apply to the ICT services provided by the group as a whole (Article 31(3)).
Designation Process Timeline
- By 30 April 2025: competent authorities submit to the ESAs the Registers of Information collected from financial entities
- 2025: the ESAs run the criticality assessments, and the Lead Overseer notifies each provider concerned of the outcome (Article 31(5)). The ESAs' roadmap of February 2025 targeted July 2025 for these notifications
- Within 6 weeks of notification: the provider may submit a reasoned statement, and the Lead Overseer may request additional information within 30 calendar days of receiving it (Article 31(5))
- 18 November 2025: the ESAs publish the list of designated CTPPs (Article 31(9)). Each CTPP is notified of its designation and of the date its oversight starts, no later than one month after that notification (Article 31(5))
- Every year: the ESAs update the list (Article 31(9)), and a provider that is not on it may apply to be designated (Article 31(11))
Concentration Risk: What the List Reveals
The 19 designations confirm what many risk managers already suspected: EU financial institutions are heavily concentrated in a handful of US-headquartered hyperscalers (AWS, Azure, Google Cloud, IBM, Oracle) for cloud infrastructure. Three observations stand out:
- Cloud concentration: 5 of 19 CTPPs (26%) are generic cloud infrastructure providers. Regulators have flagged that over 65% of EU financial entities use at least two of these three (AWS, Azure, GCP) for critical functions.
- Post-trade infrastructure: Euroclear and Clearstream together settle the vast majority of EU securities transactions. Their designation formalizes a risk that was already understood but lacked a direct supervisory lever.
- SWIFT as sui generis: SWIFT's designation is largely symbolic given its existing cooperative oversight structure, but it brings it formally within the DORA framework for the first time.
Financial institutions with significant reliance on multiple providers in the same category (e.g., both AWS and Azure for separate critical functions) should document that reliance explicitly in their concentration risk assessment.
Which Article 30 Clauses Your Contract Needs
Contracts with CTPPs do not need a special set of clauses. Article 30 DORA sorts contracts by the function the ICT service supports, not by the status of the provider. Designation brings the provider under EU oversight (Articles 31 to 44); it does not change which clauses your contract must contain.
Every ICT contract: Article 30(2)
Nine elements, whatever the provider and whatever the service:
- (a) Services: a clear and complete description of all functions and ICT services, stating whether subcontracting of a service supporting a critical or important function is permitted and, if so, on what conditions
- (b) Locations: the regions or countries where services are provided and data is processed and stored, with advance notice from the provider of any planned change
- (c) Data protection: provisions on the availability, authenticity, integrity and confidentiality of data, including personal data
- (d) Data return: access, recovery and return of data in an easily accessible format if the provider becomes insolvent, is resolved or discontinues its business, or if the contract is terminated
- (e) Service levels: service level descriptions, including updates and revisions
- (f) Incident assistance: help when an ICT incident related to the service occurs, at no additional cost or at a cost determined in advance
- (g) Cooperation with authorities: full cooperation with the competent authorities and resolution authorities of the financial entity
- (h) Termination: termination rights and related minimum notice periods, in accordance with the expectations of competent authorities and resolution authorities. DORA does not set a fixed notice period.
- (i) Training: the conditions for the provider's participation in your ICT security awareness programmes and digital operational resilience training (Article 13(6))
The contract must also allow termination in the circumstances listed in Article 28(7), such as a significant breach by the provider, or where the competent authority can no longer effectively supervise the financial entity because of the arrangement.
Services supporting a critical or important function: Article 30(3)
Six further elements apply when the ICT service supports a CIF, whether or not the provider is designated:
- (a) Quantified service levels: full service level descriptions with precise quantitative and qualitative performance targets
- (b) Notice and reporting: notice periods and reporting obligations of the provider, including notice of any development that might materially affect its ability to deliver the service
- (c) Contingency and security: requirements for the provider to implement and test business contingency plans and to have appropriate ICT security measures, tools and policies in place
- (d) TLPT: participation and full cooperation in your threat-led penetration testing (TLPT) under Articles 26 and 27
- (e) Monitoring and audit: unrestricted rights of access, inspection and audit for you, an appointed third party and your competent authority, and the provider's full cooperation during on-site inspections and audits, including those of the Lead Overseer
- (f) Exit: exit strategies with a mandatory adequate transition period, during which the provider keeps delivering the service while you migrate to another provider or in-house
Three points are often missed. A microenterprise may agree that its access, inspection and audit rights are delegated to an independent third party appointed by the provider (Article 30(3), last subparagraph). Where the provider may subcontract services supporting a CIF, Delegated Regulation (EU) 2025/532 adds what the contract must specify, including which services may be subcontracted, on what conditions, and a notice period for you to object to material changes (Articles 4 to 6). And recovery time and recovery point objectives (RTO and RPO) are not an Article 30 clause: you set them for each function in your own backup and recovery arrangements (Article 12(6)). Where you need the provider to meet them, carry them in the quantified service levels of point (a).
Where your provider offers a DORA addendum, check its latest version in the provider's trust centre or legal portal, verify that it has been formally executed (signed or electronically accepted) rather than simply made available, and map each of its terms to the points above. For CIF services, read point (e) with particular care: a certification or audit report supplied by the provider is assurance, not an audit right, and you may not rely on such reports alone over time (Delegated Regulation (EU) 2024/1773, Article 8(3)).
Key Takeaways
- 19 providers were designated as CTPPs on 18 November 2025: the first list published under Article 31(9) DORA, which the ESAs update every year
- Designation places a provider under EU oversight by a Lead Overseer (Articles 31 to 44). It does not change which Article 30 clauses your contracts need
- Clauses follow the function supported: nine Article 30(2) elements in every ICT contract, plus six Article 30(3) elements when the service supports a critical or important function, whoever the provider is
- Exit strategies are required for ICT services supporting critical or important functions (Article 28(8)), and exit plans must be tested and reviewed periodically on a proportionate basis. DORA fixes neither a contractual notice period nor a testing frequency
- The one CTPP-specific condition on your use of a provider: a CTPP established in a third country must set up a subsidiary in the Union within 12 months of its designation, or financial entities may no longer use its services (Article 31(12))
- Lead Overseer recommendations do not bind the CTPP, but your competent authority passes on the risks they identify, and you must take those risks into account (Article 42(3))
Next Steps
Use the table above to cross-check your Register of Information. For each CTPP that appears, confirm which functions each of its services supports, check the contract against Article 30(2) and, where a critical or important function is involved, Article 30(3), and make sure your incident response runbook accounts for disruptions originating at the provider. Our Third-Party Risk Scorer and Register of Information guide can help structure this review.