EBA - List of designated critical ICT third-party providers (CTPPs) under the Digital Operational Resilience Act (DORA)
The ESAs published the list of designated critical ICT third-party providers (CTPPs) under the Digital Operational Resilience Act (DORA).
The designation process followed the methodology mandated by DORA.
First, the ESAs collected data from the Registers of Information maintained by financial entities, which detail their contractual arrangements for ICT services.
Second, the ESAs conducted a detailed criticality assessment in cooperation with the Competent Authorities (CAs) across the EU from the banking, insurance and pensions, and securities and markets sectors.
Third, ICT third-party providers assessed as critical were formally notified, after which they benefitted from their right to be heard by providing a reasoned statement.
The objective of the DORA Oversight Framework, mandated to the ESAs, is to promote the sound management of ICT risk by the critical providers

