The European Supervisory Authorities (EBA, EIOPA, and ESMA – the ESAs) have published a list of designated critical ICT third-party providers (CTPPs) under the Digital Operational Resilience Act (DORA).
The designated CTPPs provide a range of ICT services (e.g. from core infrastructure to business and data services) to financial entities of all types and sizes across the European Union, reflecting their critical role within the financial ecosystem.
Through direct oversight engagement, the ESAs will assess whether CTPPs have appropriate risk management and governance frameworks in place to ensure the resilience of the services they deliver to financial entities. This ‘serves to mitigate risks that could impact the operational resilience of the financial sector of the EU,’ say the ESAs.
The designated critical ICT third-party service providers are:
- Accenture plc
- Amazon Web Services EMEA Sarl
- Bloomberg L.P.
- Capgemini SE
- Colt Technology Services
- Deutsche Telekom AG
- Equinix (EMEA) B.V.
- Fidelity National Information Services, Inc.
- Google Cloud EMEA Limited
- International Business Machines Corporation
- InterXion HeadQuarters B.V.
- Kyndryl Inc.
- LSEG Data and Risk Limited
- Microsoft Ireland Operations Limited
- NTT DATA Inc.
- Oracle Nederland B.V.
- Orange SA
- SAP SE
- Tata Consultancy Services Limited






