Skip to main content
Glossary termPublished inDORA

Critical ICT third-party service provider

What does "Critical ICT third-party service provider" mean under DORA?

An ICT third-party provider designated as systemically critical by European Supervisory Authorities (ESAs) based on cross-border reliance, substitutability, and systemic relevance.

Defined in / by

Last updated: 22 August 2026.

Regulations

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    Next
    Next register of information cycle, reference date expected 31 December 2026

    Checked