The list, and what it changed
In November 2025 the three European Supervisory Authorities - EBA, EIOPA and ESMA - published the first designation of critical ICT third-party providers under DORA. The designation was built from the Registers of Information that financial entities themselves submitted, assessed for criticality in cooperation with national competent authorities across banking, insurance and pensions, and securities and markets.
Designated providers now sit under direct oversight. They must name a coordination entity, ideally an EU subsidiary with real resources. They pay annual oversight fees. The ESAs can request information, monitor continuously, conduct investigations and inspections, and issue recommendations on cybersecurity measures directly to the provider rather than through its customers. The list is refreshed annually.
That is the provider side, and it has been well covered. The part that has been under-discussed is what designation does to the firms buying those services.
Your register became a supervisory input
The designation process ran on the Registers of Information submitted by financial entities. That is worth sitting with for a moment. The regulatory instrument that many firms treated as a reporting chore turned out to be the raw material for a union-wide criticality assessment with real consequences for named companies.
The practical implication is that register quality is no longer only about your own compliance posture. Underreporting a dependency, misclassifying a function as non-critical, or describing a subcontracting chain incompletely now distorts a supervisory picture that reaches beyond your firm. Supervisors comparing registers across entities will see inconsistencies, and inconsistency in a dataset used for designation is a more interesting finding than inconsistency in a filing nobody reads.
We wrote about the mechanics of getting the register right in DORA's Register of Information: the third-party risk deadline most financial firms are quietly missing. The designation cycle is the reason that post matters more than it looked like it did.
Four consequences for customers of a designated provider
- Your provider's oversight findings become your risk information. When an ESA issues a recommendation to a CTPP and the provider does not follow it, financial entities using that provider are expected to take that into account - which means you need a mechanism to learn about it
- Exit planning stops being theoretical. DORA already required exit strategies for critical functions; designation makes the question of whether yours is executable considerably more likely to be tested
- Contract terms need to survive oversight. Information access, audit rights, and subcontracting notification clauses that were negotiated as boilerplate now have to work under supervisory scrutiny
- Concentration risk is now supervisory-visible. If your firm and three peers all depend on the same designated provider for the same critical function, that pattern is legible to your supervisor in a way it was not before
Exit planning is an evidence problem before it is a technical one
Most exit plans fail their first serious test not because migration is impossible but because nobody can establish what state the data was in when it left. If you exit a provider under pressure - a supervisory recommendation ignored, a resilience failure, a commercial breakdown - you inherit a dataset whose integrity you cannot independently confirm, from a counterparty who now has an interest in the transition looking clean.
The firms that have solved this did something unglamorous. They established, continuously and while the relationship was healthy, an independently verifiable record of the data held at the provider. Not a copy - a proof. When exit comes, the migrated data can be checked against what it was, by a party that trusts neither the outgoing nor the incoming provider.
This is a narrow application of a general principle we set out in why backups prove nothing after an incident: possession of data is not the same as knowledge of what the data was.
What to do before the next annual cycle
- Re-run your register against reality rather than against last year's submission, and check that subcontracting chains are described to the depth the template asks for
- Identify which of your providers are designated and establish a monitoring path for oversight outcomes affecting them
- Test one exit plan end to end on a non-critical function, and keep the evidence of the test
- Confirm that your contractual information-access rights would produce evidence you could hand to a supervisor unedited
- Map concentration across your own portfolio before your supervisor maps it for you
For the broader implementation picture, DORA compliance in 2026: how financial institutions build defensible resilience covers the programme level, and the ROOTKey DORA page covers where verifiable evidence fits into it. If you want to see what a provider-independent integrity record looks like across data you do not host yourself, you can set one up on a single critical dataset.
Recibe ideas sobre ciber-resiliencia en tu correo
Orientación práctica y lista para auditorías sobre integridad de datos, cumplimiento y continuidad, según publicamos.





