The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have set out a roadmap to explain the process for implementing a pan-European oversight framework for critical ICT third-party service providers (CTPPs) under DORA. The ESAs say that the objective is to designate the CTPPs and to start the oversight engagement “this year”.
The roadmap for CTPP designation and engagement is:
Collection of the Registers of Information
Deadline: 30 April 2025
Competent Authorities are required to submit the Registers of Information on ICT third-party arrangements that they have received from financial entities to the ESAs.
Criticality assessments
Target: July 2025
The ESAs will perform the criticality assessments mandated by DORA and notify ICT third-party service providers of their classification as critical by July 2025. This notification will start a six-week period during which ICT third-party service providers may object to the assessment with a reasoned statement and relevant supporting information.
Final Designation
Target: Late Summer / early Autumn 2025
After the six-week period, the ESAs will designate CTPPs and start oversight engagement with them.
ICT third-party service providers not designated as critical may voluntarily request to be designated as critical once the list of CTPPs is published. Details on how to request this “will be provided soon,” say the ESAs.
To provide clarity to the market on preparatory activities, the designation process, and on the ESAs’ oversight approach, the ESAs plan to organize an online workshop with ICT third-party providers in the second quarter of 2025.
Source: ESMA






