Skip to content
Wednesday, August 26, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Regulation
Regulation

How DORA Classifies Critical ICT Third-Party Providers and What That Means for Fintech Contracts

The EU's operational-resilience regulation has applied since January 2025, and its most original machinery sits where designation of critical providers turns into contract law.

William Elliott, · March 8, 2026 · 7 min read
ShareXFacebookLinkedInTelegramEmail
Empty European data-center corridor with service-route markings

The Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA), has applied to EU financial entities since January 17, 2025, and its third-party title works a genuinely new mechanism: financial entities register their ICT contracts in a "register of information," the European Supervisory Authorities use those registers and their own indicators to designate critical ICT third-party providers, and designated providers enter direct oversight — audits, fee-funded supervision, and remediation powers that reach them without passing through their customers. For fintechs, the regulation's contract law is where the architecture becomes daily work.

3G Times publishes information, not legal advice. DORA classification and contract questions belong with European counsel and the entity's lead overseer where one exists.

What does DORA add to vendor management?

Before DORA, a cloud hyperscaler serving five hundred European banks answered to each of them separately, through contracts of uneven strength, and no supervisor saw the aggregate. DORA's design response is the designation layer. The ESAs — EBA, EIOPA, and ESMA, acting together — apply materiality indicators: criticality of the services, systemic concentration, number of clients, the substitutability of the provider. Designation does not remove the customers' duties; it adds a supervisory channel that runs in parallel, funded by fees the designated providers themselves pay. The first designations landed in the cloud and data-center world, which surprised no one who had read the concentration statistics, and financial entities' contracts with those providers now sit under two regimes at once.

What goes into the register of information?

Every ICT service contract of a financial entity, in the standardised template, goes into the register: counterparty, services, criticality, start and end dates, concentration data, sub-outsourcing chains, and the contract's compliance with DORA's mandatory provisions. The register is not a filing exercise for its own sake — it is the designation machine's input, submitted through the entity's national authority to build the Union-wide picture of who depends on whom. The practical burden fell hardest on entities with sprawling vendor estates, and the first submission cycles exposed the same gap everywhere: contract inventories that were aspirational rather than actual, sub-processor chains documented by folklore, and criticality assessments that had never been made at all. Entities that fixed the inventory fixed the register; the register was the forcing function.

DORA mechanismWho actsWhat it changes for fintechs
Register of informationEach financial entityTrue ICT contract inventory on a standard template
CTPP designationESAs jointlyKey vendors enter direct oversight
Mandatory contract provisions (Art. 30)Entity and providerAudit rights, termination rights, sub-outsourcing terms
Concentration risk analysisEntity and overseersExit and substitution planning becomes documented
Threat-led penetration testingSignificant entitiesSecurity testing under a regulated framework

What do the mandatory contract provisions require?

Article 30 sets the floor: the provider must grant the financial entity, its auditors, and the competent authorities full access and audit rights over the ICT services; termination rights must exist for material deficiency, regulatory obstruction, and the entity's own regulatory needs — with the strategic option to walk away when subcontracting changes materially; and the contract must describe the services, locations, and sub-outsourcing arrangements precisely enough to be supervised. Legacy agreements negotiated on hyperscaler paper required real renegotiation to reach that floor, and the market's answer converged on addenda riders rather than full rewrites. For a fintech buying ICT services, the Article 30 checklist is now a standard annex in vendor reviews: access rights that survive the relationship's end, audit scope that covers the actual data path, termination triggers that name the regulator's voice, and sub-outsourcing notice that arrives before, not after, the change.

DORA treats concentration not as a fact to note but as a risk to manage. Entities must identify their ICT concentrations, assess the substitutability of each critical service, and maintain documented exit strategies for the critical ones — tested, costed, and realistic enough that "exit" is a plan rather than a hope. The duty's bite shows in architecture decisions: a payments platform that runs one region, one cloud, one managed-database vendor, and one integration middleware has four concentrations, each needing an exit story. Overseers read those stories skeptically because the registers show, across the Union, how many entities wrote the same story about the same vendors — which is precisely the correlation the designation layer exists to surface.

What does designation of a vendor change for its fintech customers?

Less than feared, more than nothing. The customer's own DORA duties — register, contract floor, concentration file — persist unchanged. What arrives is leverage: a designated provider under direct oversight faces the ESAs' recommendations and remediation expectations, and contract negotiations inherit that pressure. Customers also gain a supervisory address: concerns about a designated provider's conduct can travel to the overseer, a channel that did not exist when the only escalation path was the customer's own contract. For providers, designation converts market position into supervision — fees, audits, and findings — and the hyperscalers' 2025 annual reports already discuss it as a compliance cost line.

What does this mean in practice?

DORA's third-party title is the first Union regime to regulate financial-sector concentration as infrastructure. The fintechs that internalized its logic earliest did so through the contract file — inventory, floor, exit — and that file, not the designation headlines, is where resilience is either documented or absent.

Group-level coordination has become the quiet best practice: one exit plan per critical intra-group service, written jointly and tested once, beats thirty divergent plans written to the same deadline.

What about intra-group ICT arrangements?

Intra-group providers sit in the register like any other contract, and DORA expects the same information flow even where market discipline cannot operate. Entities may apply a proportionate approach to group-internal dependencies, but concentration is concentration: a shared services center serving thirty group entities is a concentration with one exit plan written thirty times unless someone coordinates it.

Frequently asked questions

Does DORA apply to non-EU fintechs?

It binds EU financial entities and reaches third-country providers through those entities' contracts — a US fintech serving European customers as a critical ICT provider inherits the Article 30 floor and register exposure through its customers, without itself becoming a supervised entity.

What happens if a contract lacks the Article 30 provisions?

The entity carries the exposure: supervisory findings for non-compliance and a vendor relationship that cannot be audited or exited as the regulation assumes. The transitional reality was negotiated riders, and entities that left legacy paper untouched are remediating under examiner timelines.

Is the register submitted publicly?

No — registers flow to competent authorities and the ESAs and are treated as supervisory information. The public artifacts are the designation decisions and the oversight framework they trigger.

Frequently Asked Questions

Does DORA apply to non-EU fintechs?
It binds EU financial entities and reaches third-country providers through their contracts — a US fintech serving European entities inherits the Article 30 floor and register exposure without itself becoming supervised.
What happens if a contract lacks the Article 30 provisions?
The entity carries the exposure: supervisory findings and a relationship that cannot be audited or exited as assumed. The transitional answer was negotiated riders; untouched legacy paper is being remediated under examiner timelines.
Is the register submitted publicly?
No — registers flow to competent authorities and the ESAs as supervisory information. The public artifacts are the designation decisions and the oversight framework they trigger.