Updated augustus 30, 2026
Summary: In November 2025, EBA, EIOPA and ESMA designated the first Critical Third-Party ICT Providers under DORA, creating new sovereignty risks for financial entities that rely on those providers. This article explains the oversight mechanics, ICT Register obligations, and a practical migration path to sovereign infrastructure.

The Digital Operational Resilience Act, DORA Regulation (EU) 2022/2554, introduced a direct oversight mechanism for ICT providers whose failure could destabilise the European financial system. In November 2025, the European Banking Authority (EBA), EIOPA and ESMA jointly published the first official list of Critical Third-Party ICT Providers (CTPPs), marking the moment when concentration risk in cloud and software supply chains shifted from a compliance concept to a live supervisory fact. For IT managers, CISOs and DPOs inside financial entities, that list immediately created new obligations that contractual arrangements alone cannot resolve.

Which Providers Were Designated and What Obligations Follow

The November 2025 CTPP designation list, published jointly by EBA, EIOPA and ESMA, names a set of ICT providers deemed systemically significant based on their market share, substitutability and interconnectedness across the EU financial sector. The list is not static: DORA Article 31 provides for annual reviews, so a provider that is not yet designated can be added in subsequent cycles.

For financial entities using a designated CTPP, the immediate consequences are operational and documentary. The entity must update its ICT Register of Information under DORA Article 28(3) to reflect the provider’s CTPP status, review concentration risk assessments, and verify that its exit strategy remains credible. Critically, designation does not prohibit continued use of the provider. It does, however, mean that the Lead Overseer, one of the three European Supervisory Authorities depending on the provider’s primary sector, can now exercise powers that reach indirectly into the financial entity’s own operations.

Key point: DORA applies to more than 22,000 financial entities and ICT third-party service providers across the EU (European Commission, DORA factsheet, 2023). The CTPP designation process is therefore not a niche concern: it affects any financial entity that relies on a major cloud, SaaS or data analytics provider.

Lead Overseer Authority and Residual Sovereignty Risk

The Lead Overseer holds authority that operates independently of the private contracts between a financial entity and its chosen provider. Under DORA Article 31, the Lead Overseer can request information directly from a designated CTPP, conduct off-site and on-site investigations, and issue recommendations that the CTPP must respond to. Where a CTPP fails to comply, fines of up to 1% of average daily worldwide turnover can be imposed for each day of non-compliance, for a maximum of six months (DORA Article 35).

The sovereignty risk for financial entities arises because Lead Overseer investigations can surface configuration details, sub-processing arrangements and infrastructure locations that the financial entity may have considered confidential or adequately protected by contract. José Manuel Campa, Chairperson of the EBA, noted that “the designation of critical ICT third-party service providers is a cornerstone of the DORA framework, ensuring that systemic risks stemming from concentration in cloud and data services are brought under direct supervisory scrutiny.” The EBA has also stated clearly that “financial entities cannot outsource their regulatory responsibility,” and that contractual arrangements do not transfer accountability for ICT risk management to the third party (EBA Guidelines EBA/GL/2019/04).

For a financial entity that has structured its architecture around a designated CTPP, this means that even a well-drafted contract with robust data protection clauses does not insulate it from examination findings that expose its infrastructure to cross-border regulatory reach.

See how Qsentinel solves this in practice.Start a 10-user pilot →

Updating the ICT Register of Information After CTPP Designation

The EBA published its final Implementing Technical Standards (ITS) on the ICT Register of Information in January 2024. Those standards require financial entities to document not only direct contractual relationships but also the sub-outsourcing chain behind each arrangement. When a provider receives CTPP designation, at least three register fields require immediate review: the provider’s designation status, the concentration risk indicator, and the sub-processor records that sit beneath the primary contract.

Sub-outsourcing chain transparency: If a designated CTPP itself uses sovereign infrastructure partners to deliver part of its service, those sub-processors must appear in the financial entity’s register. Gaps in this chain are a primary focus area during supervisory reviews and Joint Examination Team activities.
Register element Before CTPP designation After CTPP designation
Provider classification Third-party ICT provider Designated CTPP (with ESA reference)
Concentration risk flag Internal assessment only Must align with Lead Overseer findings
Exit strategy evidence Policy document sufficient Tested exit plan with timeline required
Sub-outsourcing disclosure Material sub-processors Full chain including CTPP sub-processors

Migration Timeline: From Designated CTPP to Sovereign Infrastructure

A compliant migration involves four sequential phases, each with its own regulatory evidence requirements. First, contractual notice: major cloud and SaaS providers typically require 12 months written notice to terminate an enterprise agreement without penalty. Second, data repatriation: bulk export, format conversion and integrity verification of production data must be completed before decommissioning begins. Third, parallel-run: the replacement infrastructure must demonstrably handle production workloads before the designated CTPP is switched off. Fourth, evidence submission: the financial entity’s competent authority expects a post-migration report confirming that exit has been executed and that no critical dependencies on the designated CTPP remain.

Realistic total timelines for this sequence range from 12 to 24 months, depending on data volume, application complexity and the availability of a tested sovereign alternative. Managed Nextcloud Enterprise deployments, available through providers such as Qsentinel with Swiss or on-premises hosting, are designed to map directly onto the ICT Register ITS fields, which reduces the time needed to produce compliant documentation during and after migration.

Joint Examination Teams, TLPT and Sovereign Infrastructure Advantages

DORA establishes Joint Examination Teams (JETs), composed of staff from the Lead Overseer and relevant national competent authorities, to coordinate oversight of designated CTPPs. JETs can interview a CTPP’s staff, review its technical documentation and assess the resilience of services provided to financial entities. For a financial entity, this means that the perimeter of a JET examination can extend to the specific configuration of its own environment if that environment is hosted on a designated CTPP’s shared infrastructure.

Threat-Led Penetration Testing (TLPT) obligations under DORA apply to the financial entity regardless of infrastructure choice. Sovereign on-premises infrastructure does not eliminate TLPT requirements. It does, however, fundamentally change the practicalities of scope isolation. When infrastructure is fully under the financial entity’s control, it can define the TLPT boundary precisely, restrict lateral access during the test, and provide the Lead Overseer with clean evidence that no test traffic crossed into shared third-party environments. On a designated CTPP’s shared platform, achieving the same isolation requires the CTPP’s active cooperation, which the JET process may complicate during an active examination period.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Can a financial entity continue using a designated CTPP after November 2025?
Yes, designation does not prohibit use. However, the financial entity must update its ICT Register of Information to reflect the CTPP status, demonstrate that concentration risk is managed, and accept that the Lead Overseer may request information about the entity's arrangements with the designated provider.
Does a contractual exit clause protect a financial entity from Lead Overseer scrutiny?
No. Contractual protections govern the relationship with the provider, but the Lead Overseer's authority under DORA Article 31 is regulatory in nature and operates independently of private contracts. The financial entity remains accountable to its own competent authority for ICT risk regardless of what the contract says.
How long does a compliant migration away from a designated CTPP typically take?
Most migration projects involving regulated financial entities take between 12 and 24 months when accounting for contractual notice periods (often 12 months for major cloud providers), data repatriation, parallel-run testing, and production of evidence for the competent authority. Starting the process before formal supervisory pressure is strongly advisable.
What specific fields in the ICT Register of Information must change when a provider receives CTPP designation?
Under the EBA ITS on the Register of Information, entities must record whether each third-party provider is a designated CTPP and must document the full sub-outsourcing chain. A CTPP designation therefore triggers a review of all related sub-contractor entries to verify that the chain is transparent and that concentration risk disclosures are current.
Does sovereign on-premises infrastructure eliminate TLPT obligations?
No. Threat-Led Penetration Testing obligations under DORA apply to the financial entity regardless of where infrastructure is hosted. However, sovereign on-premises infrastructure simplifies the scope isolation required during Joint Examination Team activities, because the entity controls access and can demonstrate clean boundaries without depending on a third-party provider's cooperation.