Skip to main content
Category: Regulatory Frameworks

Critical ICT Third-Party Provider

Also known as: CTPP, Critical ICT Third-Party Service Provider, Critical Third-Party Provider
Simply put

A Critical ICT Third-Party Provider (CTPP) is an information and communications technology (ICT) vendor that serves financial firms and has been formally designated by EU financial supervisors as systemically important to the stability of the EU financial system. Because these providers are considered so significant, they are subject to direct oversight rather than being monitored only by their individual financial-sector clients. The range of services involved can span core infrastructure through to business and data services.

Formal definition

Under the EU's Digital Operational Resilience Act (DORA), a CTPP is an ICT third-party service provider (as defined in point 19 of Article 3 of DORA) that has been designated by the European Supervisory Authorities (ESAs) as critical for financial entities. Designated CTPPs provide ICT services ranging from core infrastructure to business and data services to financial entities of varying types and sizes, and their designation triggers a dedicated oversight regime. The designation is a regulatory determination specific to the EU financial sector; it identifies systemic importance to financial stability and does not by itself constitute a certification, an attestation of security or operational adequacy, or an assessment of the provider's residual risk. Scope is limited to ICT services under DORA and to designated providers; non-designated ICT vendors and non-financial-sector relationships fall outside this specific classification.

Why it matters

The CTPP designation reflects a structural shift in how systemic ICT risk is governed in the EU financial sector. Historically, oversight of ICT vendors rested with each financial firm through its own third-party risk management program. But when many financial entities depend on the same small set of ICT providers, spanning core infrastructure to business and data services, the failure or disruption of one such provider can transmit risk across the entire financial system in ways no single client can see or manage alone. The CTPP regime addresses this concentration concern by designating systemically important providers and placing them under direct supervisory oversight rather than relying solely on client-by-client monitoring.

For risk and resilience professionals, the designation is a signal, not a guarantee. Being designated a CTPP identifies a provider as important enough to warrant dedicated oversight; it does not certify the provider's security, attest to its operational adequacy, or assess its residual risk. Financial entities that rely on a designated CTPP retain their own obligations to manage that relationship and cannot treat the oversight regime as a substitute for their own due diligence and ongoing monitoring.

The practical significance is jurisdictional and sector-specific. The classification applies to ICT services under DORA and to providers formally designated by the European Supervisory Authorities; it does not extend to non-designated ICT vendors, to non-financial-sector relationships, or to equivalent arrangements outside the EU. Professionals mapping supplier dependencies should therefore treat CTPP status as one input into concentration and single-source dependency analysis rather than a complete picture of a vendor's criticality across their own operations.

Who it's relevant to

Third-party risk managers at EU financial entities
Professionals managing ICT vendor relationships at financial firms need to identify which of their providers are designated CTPPs, because this signals concentration and systemic importance within the EU financial system. Designation does not discharge the firm's own due diligence or ongoing monitoring obligations, so it should be treated as an input into risk-tiering rather than an assurance that the provider is low risk.
ICT and cloud service providers serving the financial sector
Providers delivering ICT services, ranging from core infrastructure to business and data services, to financial entities may be designated as critical by the ESAs and become subject to a dedicated oversight regime. Understanding the designation criteria and the resulting oversight expectations is relevant to how these providers structure their engagement with financial-sector clients within the EU.
Compliance and regulatory affairs teams
Teams tracking digital operational resilience obligations should understand that CTPP is a specific EU regulatory designation under DORA, distinct from certifications, attestations, or general vendor-criticality labels. This distinction matters when interpreting regulatory expectations and avoiding overstating what designation confers.
Resilience and concentration-risk analysts
Analysts assessing single-source dependencies and concentration risk across the financial system can use CTPP designations as one indicator of where shared ICT dependencies exist. Because designation is EU- and financial-sector-specific and does not assess residual risk, it should be combined with broader dependency mapping rather than relied on as a complete view.

Inside CTPP

Designation mechanism
A CTPP is not self-declared but designated by regulatory or oversight authorities based on criteria such as the systemic importance of the ICT services provided, the number and significance of financial entities relying on the provider, and the degree of substitutability of those services. The designation reflects a supervisory judgment rather than a contractual or self-assessed status.
Systemic and concentration focus
The concept targets providers whose failure or disruption could have implications across multiple financial entities simultaneously. It is closely tied to concentration risk at the sector or market level, which is distinct from a single firm's single-source dependency or single point of failure within its own architecture.
ICT service scope
The term applies specifically to information and communications technology services, for example cloud, data, or software provision, and does not extend to non-ICT outsourcing arrangements. It addresses ICT-related operational and resilience risk rather than the full spectrum of financial, ESG, or purely commercial risks a firm may face from the same provider.
Oversight relationship
Designation typically brings the provider within scope of a direct oversight regime operated by authorities, which may include information requests, inspections, and recommendations. This oversight sits alongside, and does not replace, each financial entity's own third-party risk management obligations toward that provider.
Nth-party context
A CTPP may itself rely on subcontractors, so the designation implicates fourth-party and onward dependencies. Oversight of a CTPP does not automatically extend visibility or assurance across the provider's own supply chain tiers.

Common questions

Answers to the questions practitioners most commonly ask about CTPP.

Does being designated a Critical ICT Third-Party Provider mean the provider is directly regulated in the same way as the financial entities it serves?
Not in the same manner. A CTPP designation typically brings the provider within an oversight framework directed at the provider itself, but this is distinct from the prudential and conduct regulation applied to the financial entities that consume its services. The nature, scope, and consequences of oversight over a designated provider differ from the direct supervision of a regulated financial institution, and designation does not convert the provider into a licensed or authorized financial entity. Programs should not assume the designation transfers or discharges the financial entity's own responsibilities for managing that relationship.
If we use a Critical ICT Third-Party Provider, does its designation and any associated oversight relieve us of our own third-party risk management obligations for that provider?
No. Oversight applied to a designated provider operates in addition to, not as a substitute for, the contracting entity's own obligations. The financial entity generally remains responsible for its own due diligence, contractual arrangements, ongoing monitoring, and management of concentration and exit considerations relating to that provider. Treating the designation as a form of pre-clearance or as independent verification of the provider's controls would conflate an external oversight status with the entity's own accountability, which typically remains intact.
How is a provider identified as a CTPP, and who makes that determination?
Designation is typically made by the relevant supervisory or oversight authorities rather than by the financial entities that use the provider or by the provider itself. Criteria commonly considered include the systemic importance of the services provided, the degree to which financial entities depend on them, the substitutability of the provider, and the potential impact of disruption. Because designation rests with authorities, an organization cannot assume a given provider is or is not a CTPP without reference to the applicable authority's determinations, which may change over time.
What should a third-party risk program do differently for a provider that is or may be a CTPP?
In many programs, a CTPP relationship warrants heightened attention proportionate to its potential impact, which may include closer monitoring of service performance and resilience, clearer contractual provisions on continuity and information rights, and more deliberate consideration of exit and substitutability. However, the specific expected practices depend on the applicable regulatory regime and the entity's own risk tiering, so programs should map their approach to the requirements that actually apply rather than assuming a uniform standard.
How does a CTPP relationship interact with concentration risk assessment?
Reliance on a CTPP can be a source of concentration risk where many functions, or many entities across a sector, depend on the same provider. It is useful to distinguish concentration risk, single-source dependency, and single point of failure when analyzing this: a provider may be widely used (concentration) without every individual dependency being unsubstitutable. Programs typically assess where a CTPP represents a material dependency, whether alternatives exist, and how disruption would propagate, recognizing that visibility may be limited beyond the direct contractual tier.
How does CTPP oversight relate to exit planning and substitutability?
Because designated providers are often significant and may be difficult to replace, exit planning and substitutability analysis are commonly emphasized for these relationships. This typically involves considering what would be required to transition away from the provider, the availability of alternatives, and the time and cost involved. It is worth noting that the existence of an oversight regime does not by itself guarantee that a provider is substitutable or that exit is feasible; those remain matters for the contracting entity's own assessment, and the practicality of exit can vary by service and by jurisdiction.

Common misconceptions

Designation as a CTPP means the provider is certified, approved, or endorsed as safe or compliant to use.
Designation is a supervisory classification signaling systemic importance and bringing the provider into an oversight regime; it is not an attestation, certification, or assurance of the provider's security or resilience. Financial entities retain their own due diligence and monitoring responsibilities.
Once a provider is designated a CTPP, individual financial entities no longer need to manage risk from that provider themselves.
Direct oversight of a CTPP operates at the level of the provider and typically does not discharge a firm's own third-party risk management duties, including contractual controls, exit planning, and ongoing monitoring for its specific arrangements.
The CTPP concept covers all risks arising from the provider relationship.
The designation is centered on ICT-related operational resilience and systemic risk. It does not, on its own, address financial, ESG, geopolitical, or broader commercial risks a firm may carry with the same provider, which remain within the firm's own risk program.

Best practices

Treat CTPP designation as an input to, not a substitute for, your own third-party risk assessment, retaining contractual, monitoring, and exit-planning controls for each ICT arrangement.
Map where your firm's critical or important functions depend on providers that are, or could plausibly become, designated CTPPs, and evaluate concentration risk at the portfolio level rather than only per-contract.
Extend due diligence beyond the direct provider to material subcontractors, recognizing that oversight of a CTPP does not automatically provide visibility into its Nth-party dependencies.
Avoid interpreting designation as certification or assurance; continue to seek independent verification of controls where risk tier warrants rather than relying on supervisory status.
Develop and test substitutability and exit strategies for reliance on systemically important ICT providers, acknowledging that limited alternatives may constrain realistic options.
Track how oversight expectations for CTPPs vary by jurisdiction and sector, and align internal governance accordingly rather than assuming a single global regime applies.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.