DORA: 19 critical ICT providers under direct oversight, and the question of where they sit
Published by Luiz Hogrefe: August 22, 2026
What changed
The European Supervisory Authorities published, under Article 31(9) of Regulation (EU) 2022/2554 (DORA), the list of critical ICT third-party service providers designated at Union level. There are 19, in alphabetical order, among them Amazon Web Services EMEA Sarl, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, IBM, Oracle, SAP, Accenture, Capgemini, Deutsche Telekom, Orange and Tata Consultancy Services. On 3 June 2026 the same authorities published the first annual report on major ICT-related incidents required by Article 22(2) of DORA: 3,383 major incidents reported in 2025, an average of 0.18 per financial entity in scope, around one third with cross-border impact and only 10 per cent related to cybersecurity. BaFin, in its Risks in Focus 2026, notes that a large share of the ICT services used by financial institutions in Germany and across Europe comes from providers seated in third countries such as the United States, the United Kingdom, India and Japan.
Who is affected
Financial entities in scope of DORA and, indirectly, any company that depends on them for payments and export credit. The underlying subject is not the name of any provider but concentration: when a market's critical infrastructure sits outside the jurisdiction that regulates it, supervision needs instruments of its own.
What to do
Read the list published by the European authorities, not a reproduction of it, before classifying a provider as critical in the register of information. For anyone following data sovereignty, the report of 3 June 2026 is the first series of official figures on incidents inside the DORA perimeter.
Primary source
https://www.esma.europa.eu/sites/default/files/2025-11/List_of_designated_CTPPs.pdf
Checked against the primary source by Luiz Hogrefe on August 22, 2026; source opened: https://www.esma.europa.eu/sites/default/files/2025-11/List_of_designated_CTPPs.pdf.
