The European Supervisory Authorities (ESAs) have published a list of 19 critical information and communications technology (ICT) third‑party providers (CTPP) that will be subject to direct oversight when the EU Digital Operational Resilience Act (DORA) takes effect. The list, released on November 18, 2025, includes hyperscale cloud providers, data‑center operators, infrastructure and network service firms, and providers of financial‑services‑specific technology. By designating these providers as critical, regulators aim to reduce systemic risk and enhance the overall digital resilience of the EU’s financial sector. The oversight will require the listed firms to comply with stricter operational resilience standards and ongoing supervisory monitoring. This regulatory step is a cornerstone of DORA’s broader effort to ensure that key technology services supporting Europe’s financial markets can withstand and quickly recover from disruptions.