The European Supervisory Authorities (ESAs) published on November 18, 2025 a list of 19 critical information and communications technology (ICT) third-party providers (CTPP) that will be subject to direct oversight under the EU Digital Operational Resilience Act (DORA). The list includes hyperscale cloud providers, data center providers, infrastructure and network providers, and providers of financial services-specific technology….
Why it matters:
- Reduces systemic risk in the EU financial sector
- Establishes direct regulatory oversight over critical ICT providers
Key Points
- 19 critical ICT third‑party providers identified
- Covers hyperscale cloud, data‑center, infrastructure and network services
- Includes providers of financial‑services‑specific technology
- Providers will be subject to direct oversight under DORA
- Oversight aims to improve digital operational resilience
- List published by ESAs on November 18, 2025
Source: Read original