The DORA Critical Third-Party Provider (CTPP) oversight framework, operational since January 2025 under Regulation (EU) 2022/2554, introduces a new category of supervisory pressure for financial entities: regulators can now inspect not just the banks and insurers themselves, but the cloud and software vendors those institutions depend on. For compliance officers and CISOs evaluating whether to stay with a designated hyperscaler or migrate to a sovereign alternative, understanding exactly what Joint Examination Teams can demand, and how provider choice changes that exposure, is now a board-level question.
What Joint Examination Teams actually have the power to do
Joint Examination Teams hold direct investigative authority over designated CTPPs, which reshapes the contractual risk picture for every financial entity using those providers.
The EBA, EIOPA and ESMA exercise their CTPP oversight jointly through the Joint Oversight Vehicle (JOV). In practice, the JOV deploys Joint Examination Teams composed of staff from all three authorities to carry out investigations into designated providers. Those teams can request documents, conduct on-site inspections and, critically, review the individual contractual arrangements between a provider and its financial-entity clients. That last power is the one that changes the compliance calculus most sharply.
When a Joint Examination Team audits a designated CTPP, it looks at whether the provider’s contracts with financial entities contain the mandatory clauses required by DORA Article 30: explicit termination rights, audit-access provisions, data-portability guarantees, defined service levels and full sub-contracting disclosure. If a bank’s contract with a designated provider falls short, the supervisory finding lands on the bank’s own regulatory record, not just the provider’s. The financial entity remains the party accountable under DORA, as the regulation states explicitly in Recital 63: “Financial entities remain fully responsible for compliance with their obligations under this Regulation when they outsource functions to ICT third-party service providers.”
The first designation round, published in January 2025, named 19 ICT third-party service providers as critical. That list includes the largest hyperscalers, whose infrastructure underpins a significant share of EU financial-sector operations. DORA applies to more than 22,000 financial entities across the EU, meaning the intersection of designated providers and regulated clients is enormous.
DORA Article 31(11) opt-in: proactive designation and what it means for sovereign providers
A provider that does not meet the quantitative thresholds for mandatory designation can voluntarily seek CTPP status under DORA Article 31(11), turning a compliance signal into a competitive credential, but at a cost.
The thresholds for mandatory designation are defined in Commission Delegated Regulation (EU) 2025/295, which sets criteria based on systemic relevance, the number and type of financial entities served, and concentration risk across the EU financial sector. A sovereign cloud provider operating primarily in Switzerland or a single EU jurisdiction may not cross those thresholds, meaning designation is optional rather than compelled.
Article 31(11) creates the opt-in pathway. A provider that requests voluntary designation goes through the same assessment process and, once designated, falls under the full Joint Examination Team oversight regime. The fees associated with that oversight are governed by Commission Delegated Regulation (EU) 2025/420, which sets a tiered fee structure based on the provider’s annual revenue from ICT services to EU financial entities. For a smaller sovereign provider, those fees can represent a material operating cost.
The strategic logic for voluntary designation is straightforward: a financial-entity client dealing with a designated sovereign provider has regulatory certainty that the contractual framework meets DORA’s mandatory standards, because the JOV will verify it. That certainty can accelerate procurement decisions in regulated sectors. The countervailing logic is that voluntary designation imports the full burden of JOV oversight, including the right of Joint Examination Teams to inspect contracts, sub-contracting chains and operational resilience records. A sovereign provider that competes on simplicity and auditability may find voluntary designation incompatible with the lean governance model it offers clients.
Contract renegotiation: where banks are falling short
DORA’s contract-renegotiation requirements have proven one of the most practically difficult obligations, and the compliance gap is measurable and documented.
DORA Article 30 sets out a mandatory minimum content list for all ICT third-party contracts. The EBA’s technical standards on the register of information, which became applicable on 17 January 2025, require financial entities to record every ICT third-party arrangement in a structured format and to confirm that each contract contains the Article 30 clauses. Legacy contracts with hyperscalers, many negotiated under standard terms that predate DORA, rarely contain explicit termination-for-regulatory-cause clauses, audit-access rights broad enough to satisfy supervisors, or meaningful data-portability commitments with defined timescales.
Migrating to a sovereign provider simplifies this renegotiation in one important respect: sovereign providers operating in the EU or Swiss jurisdiction typically have shorter, more negotiable contract structures than hyperscalers whose standard terms are governed by US or Irish law and amended unilaterally at scale. A financial entity negotiating a bespoke sovereign hosting agreement can insert the Article 30 clauses from the outset rather than fighting to amend a 200-page hyperscaler service agreement that has been reviewed by tens of thousands of clients.
The complication is that migration itself requires a transitional period during which the financial entity operates across both environments, and the register of information must reflect both the legacy contract and the new sovereign arrangement simultaneously, including any sub-contracting at both layers.
Sub-contracting transparency for sovereign and on-premises stacks
Commission Delegated Regulation (EU) 2024/1502 governs how financial entities must document sub-contracting chains in their DORA register of information, and the obligations apply regardless of whether the primary provider is a designated CTPP or a sovereign alternative.
For a sovereign Nextcloud deployment, the register must identify the sovereign hosting provider, the data-centre operator (if different), any CDN or network provider involved, and any open-source software supply chain elements that represent a critical dependency. On-premises infrastructure reduces this chain considerably: the financial entity itself becomes the operational party for many layers, and sub-contracting entries are limited to hardware maintenance contracts, network carriers and any managed security service providers.
| Infrastructure model | Typical register-of-information entries | Sub-contracting depth | JOV direct oversight exposure |
|---|---|---|---|
| Designated CTPP (hyperscaler) | Primary provider, 4 to 8 sub-processors, CDN, identity provider | High, often opaque | Direct, via Joint Examination Team |
| Sovereign EU/Swiss cloud (non-designated) | Primary provider, data-centre operator, 1 to 3 sub-contractors | Low to medium, contractually controlled | Indirect only (through financial entity’s own supervision) |
| On-premises sovereign stack | Hardware vendor, network carrier, MSSP if applicable | Minimal | None for ICT provision layer |
What delegated regulations require of providers by jurisdiction
Commission Delegated Regulations (EU) 2025/295 and (EU) 2025/420 together define the designation criteria and fee framework, and they apply to providers regardless of whether the provider is headquartered in the EU or a third country, including Switzerland.
Under 2025/295, designation is assessed on systemic relevance to the EU financial sector, not on the provider’s own regulatory home. A Swiss-domiciled provider serving a large number of EU financial entities could, in principle, be designated as critical, even though Switzerland is not an EU member state. The regulation requires that a designated CTPP establish an EU subsidiary or legal representative if it does not already have one, to ensure the JOV has a legal addressee for enforcement. This is a significant structural requirement for any provider currently operating exclusively through a Swiss legal entity.
Commission Delegated Regulation (EU) 2025/420 sets annual oversight fees on a sliding scale. Providers with lower EU financial-sector revenue pay lower fees, which means that a genuinely sovereign alternative, serving a smaller client base than a hyperscaler, faces a proportionately lower fee burden if it does enter the designation regime.
Documenting sovereign resilience in a DORA business continuity plan
A financial entity whose sovereign provider is not a designated CTPP cannot point to JOV certification as evidence of resilience. Instead, the business continuity plan must construct that evidence directly, from verifiable contractual and architectural facts.
The most important elements are: a documented exit strategy with a tested data-portability procedure, confirmation that the sovereign provider operates under a legal framework that does not permit foreign-government compelled access (the Swiss revised Federal Act on Data Protection provides this for Swiss-hosted data), evidence of geographic redundancy within the sovereign jurisdiction, and a sub-contracting map showing that no element of the infrastructure stack introduces a dependency on a designated CTPP or a US-law-governed entity subject to the CLOUD Act or FISA 702.
The business continuity plan should also quantify recovery objectives with reference to the provider’s actual service-level commitments, not generic assumptions. Given that the average total cost of a data breach reached USD 4.88 million in 2024 (IBM Cost of a Data Breach Report 2024), supervisors reviewing BCP documentation will expect loss-scenario modelling that reflects real incident economics, not theoretical downtime tables.
For threat scenarios involving ransomware or extended provider unavailability, the plan should demonstrate that the financial entity can operate from on-premises backups or a secondary sovereign environment without routing recovery traffic through any designated CTPP. That architectural independence is the operational resilience argument that sovereign hosting makes most credibly, and it belongs explicitly in the BCP narrative that compliance officers submit to national competent authorities.
FAQ
Does switching to a sovereign, non-designated cloud provider exempt a financial entity from DORA obligations?
No. DORA Recital 63 makes clear that financial entities remain fully responsible for compliance regardless of which provider they use. What changes is the supervisory pathway: a non-designated provider is not subject to Joint Examination Team inspections, reducing indirect regulatory friction for the financial entity. The entity must still document ICT risk, sub-contracting chains and contractual rights in its register of information.
Can a sovereign cloud provider voluntarily seek CTPP designation to reassure financial-entity clients?
Yes. DORA Article 31(11) allows a provider that does not meet the quantitative designation thresholds to request recognition as a critical provider. The process follows the criteria set out in Commission Delegated Regulation (EU) 2025/295. Voluntary designation can provide contractual certainty for clients but also subjects the provider to the full Joint Examination Team oversight regime and the fee structure under Commission Delegated Regulation (EU) 2025/420.
Which specific contractual clauses must be renegotiated under DORA, and by when?
DORA Article 30 requires contracts with ICT third-party providers to include termination rights, audit rights, data portability provisions, service-level definitions and sub-contracting disclosure obligations. The EBA’s register-of-information technical standards set the compliance deadline at the DORA application date of 17 January 2025. Many banks missed complete renegotiation of legacy contracts by that date, and national competent authorities are actively reviewing gaps.
How does Swiss hosting interact with DORA’s sub-contracting transparency requirements?
A Swiss-hosted sovereign provider falls outside the EU regulatory perimeter for mandatory CTPP designation but still appears in a financial entity’s DORA register of information as an ICT third-party service provider. The entity must document the provider’s sub-contractors, the jurisdictions involved and any applicable data-transfer mechanisms. Swiss hosting under the revised FADP removes CLOUD Act and FISA 702 exposure, because Swiss law does not compel local providers to hand data to foreign governments without Swiss legal process, but the DORA documentation obligation itself remains unchanged.
What is the difference between the Joint Oversight Vehicle and a Joint Examination Team?
The Joint Oversight Vehicle (JOV) is the permanent coordination structure shared by EBA, EIOPA and ESMA for exercising CTPP oversight under DORA. A Joint Examination Team is the operational unit that the JOV deploys for a specific investigation or inspection of a designated CTPP. The JOV sets strategy and coordinates between the three ESAs; the Joint Examination Team is the team that actually shows up, reviews contracts and issues findings.
