The Digital Operational Resilience Act, DORA Regulation (EU) 2022/2554, introduced a direct oversight mechanism for ICT providers whose failure could destabilise the European financial system. In November 2025, the European Banking Authority (EBA), EIOPA and ESMA jointly published the first official list of Critical Third-Party ICT Providers (CTPPs), marking the moment when concentration risk in cloud and software supply chains shifted from a compliance concept to a live supervisory fact. For IT managers, CISOs and DPOs inside financial entities, that list immediately created new obligations that contractual arrangements alone cannot resolve.
Which Providers Were Designated and What Obligations Follow
The November 2025 CTPP designation list, published jointly by EBA, EIOPA and ESMA, names a set of ICT providers deemed systemically significant based on their market share, substitutability and interconnectedness across the EU financial sector. The list is not static: DORA Article 31 provides for annual reviews, so a provider that is not yet designated can be added in subsequent cycles.
For financial entities using a designated CTPP, the immediate consequences are operational and documentary. The entity must update its ICT Register of Information under DORA Article 28(3) to reflect the provider’s CTPP status, review concentration risk assessments, and verify that its exit strategy remains credible. Critically, designation does not prohibit continued use of the provider. It does, however, mean that the Lead Overseer, one of the three European Supervisory Authorities depending on the provider’s primary sector, can now exercise powers that reach indirectly into the financial entity’s own operations.
Lead Overseer Authority and Residual Sovereignty Risk
The Lead Overseer holds authority that operates independently of the private contracts between a financial entity and its chosen provider. Under DORA Article 31, the Lead Overseer can request information directly from a designated CTPP, conduct off-site and on-site investigations, and issue recommendations that the CTPP must respond to. Where a CTPP fails to comply, fines of up to 1% of average daily worldwide turnover can be imposed for each day of non-compliance, for a maximum of six months (DORA Article 35).
The sovereignty risk for financial entities arises because Lead Overseer investigations can surface configuration details, sub-processing arrangements and infrastructure locations that the financial entity may have considered confidential or adequately protected by contract. José Manuel Campa, Chairperson of the EBA, noted that “the designation of critical ICT third-party service providers is a cornerstone of the DORA framework, ensuring that systemic risks stemming from concentration in cloud and data services are brought under direct supervisory scrutiny.” The EBA has also stated clearly that “financial entities cannot outsource their regulatory responsibility,” and that contractual arrangements do not transfer accountability for ICT risk management to the third party (EBA Guidelines EBA/GL/2019/04).
For a financial entity that has structured its architecture around a designated CTPP, this means that even a well-drafted contract with robust data protection clauses does not insulate it from examination findings that expose its infrastructure to cross-border regulatory reach.
Updating the ICT Register of Information After CTPP Designation
The EBA published its final Implementing Technical Standards (ITS) on the ICT Register of Information in January 2024. Those standards require financial entities to document not only direct contractual relationships but also the sub-outsourcing chain behind each arrangement. When a provider receives CTPP designation, at least three register fields require immediate review: the provider’s designation status, the concentration risk indicator, and the sub-processor records that sit beneath the primary contract.
| Register element | Before CTPP designation | After CTPP designation |
|---|---|---|
| Provider classification | Third-party ICT provider | Designated CTPP (with ESA reference) |
| Concentration risk flag | Internal assessment only | Must align with Lead Overseer findings |
| Exit strategy evidence | Policy document sufficient | Tested exit plan with timeline required |
| Sub-outsourcing disclosure | Material sub-processors | Full chain including CTPP sub-processors |
Migration Timeline: From Designated CTPP to Sovereign Infrastructure
A compliant migration involves four sequential phases, each with its own regulatory evidence requirements. First, contractual notice: major cloud and SaaS providers typically require 12 months written notice to terminate an enterprise agreement without penalty. Second, data repatriation: bulk export, format conversion and integrity verification of production data must be completed before decommissioning begins. Third, parallel-run: the replacement infrastructure must demonstrably handle production workloads before the designated CTPP is switched off. Fourth, evidence submission: the financial entity’s competent authority expects a post-migration report confirming that exit has been executed and that no critical dependencies on the designated CTPP remain.
Realistic total timelines for this sequence range from 12 to 24 months, depending on data volume, application complexity and the availability of a tested sovereign alternative. Managed Nextcloud Enterprise deployments, available through providers such as Qsentinel with Swiss or on-premises hosting, are designed to map directly onto the ICT Register ITS fields, which reduces the time needed to produce compliant documentation during and after migration.
Joint Examination Teams, TLPT and Sovereign Infrastructure Advantages
DORA establishes Joint Examination Teams (JETs), composed of staff from the Lead Overseer and relevant national competent authorities, to coordinate oversight of designated CTPPs. JETs can interview a CTPP’s staff, review its technical documentation and assess the resilience of services provided to financial entities. For a financial entity, this means that the perimeter of a JET examination can extend to the specific configuration of its own environment if that environment is hosted on a designated CTPP’s shared infrastructure.
Threat-Led Penetration Testing (TLPT) obligations under DORA apply to the financial entity regardless of infrastructure choice. Sovereign on-premises infrastructure does not eliminate TLPT requirements. It does, however, fundamentally change the practicalities of scope isolation. When infrastructure is fully under the financial entity’s control, it can define the TLPT boundary precisely, restrict lateral access during the test, and provide the Lead Overseer with clean evidence that no test traffic crossed into shared third-party environments. On a designated CTPP’s shared platform, achieving the same isolation requires the CTPP’s active cooperation, which the JET process may complicate during an active examination period.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
