Skip to content

Independent R&D project · Cologne

DORA · Article 31(9) and Article 22(2)Applicable

DORA: 19 critical ICT providers under direct oversight, and the question of where they sit

Published by Luiz Hogrefe: August 22, 2026

What changed

The European Supervisory Authorities published, under Article 31(9) of Regulation (EU) 2022/2554 (DORA), the list of critical ICT third-party service providers designated at Union level. There are 19, in alphabetical order, among them Amazon Web Services EMEA Sarl, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, IBM, Oracle, SAP, Accenture, Capgemini, Deutsche Telekom, Orange and Tata Consultancy Services. On 3 June 2026 the same authorities published the first annual report on major ICT-related incidents required by Article 22(2) of DORA: 3,383 major incidents reported in 2025, an average of 0.18 per financial entity in scope, around one third with cross-border impact and only 10 per cent related to cybersecurity. BaFin, in its Risks in Focus 2026, notes that a large share of the ICT services used by financial institutions in Germany and across Europe comes from providers seated in third countries such as the United States, the United Kingdom, India and Japan.

Who is affected

Financial entities in scope of DORA and, indirectly, any company that depends on them for payments and export credit. The underlying subject is not the name of any provider but concentration: when a market's critical infrastructure sits outside the jurisdiction that regulates it, supervision needs instruments of its own.

What to do

Read the list published by the European authorities, not a reproduction of it, before classifying a provider as critical in the register of information. For anyone following data sovereignty, the report of 3 June 2026 is the first series of official figures on incidents inside the DORA perimeter.

Primary source

https://www.esma.europa.eu/sites/default/files/2025-11/List_of_designated_CTPPs.pdf

Checked against the primary source by Luiz Hogrefe on August 22, 2026; source opened: https://www.esma.europa.eu/sites/default/files/2025-11/List_of_designated_CTPPs.pdf.

Information verified against a primary source on the date indicated. This content is informational and does not constitute legal advice. Confirm applicability to your specific situation with your own advisor.

AnyLAI - AI-assisted, human-verified.