The European Supervisory Authorities (EBA, EIOPA, and ESMA – the ESAs) have announced the timeline for the collection of information for the designation of critical ICT third-party service providers (CTPPs) under the EU Digital Operational Resilience Act.
The ESAs state that the ‘competent authorities’ must report on the designation of critical ICT third-party service providers under DORA by 30th April 2025. This will take the form of registers of information on contractual arrangements of the financial entities with ICT third-party service providers.
However, although the deadline for the competent authorities is clear, the situation is less clear for the regulated financial entities and the critical ICT third-party service providers themselves.
The ESAs states that they, along with the competent authorities, will start the oversight of CTPPs following the entry into force of DORA on 17 January 2025. The first oversight activity will be the designation of CTPPs but the competent authorities will collect the registers of information from the financial entities under their supervision in advance, following their own timelines. This opens the door for a variable set of deadlines, which could be particularly problematical for financial entities reporting to multiple competent authorities.
The ESAs has encouraged financial entities to get ahead of these deadlines by commencing work now, stating:
“Although the implementing technical standards (ITS) on the Registers of information have not yet been adopted by the EU Commission, the ESAs note that the essential part of the requirements for registers of information is publicly available since the publication of the ESAs Final Report in January 2024 and that any potential changes in the registers following the rejection by the EU Commission and the ESAs Opinion on the rejection should be limited. Therefore, the ESAs encourage financial entities to anticipate as much as possible the preparation of their registers, especially for information which may not be immediately available (e.g. the relevant identifiers of their ICT providers).”






