Critical ICT Third-Party Provider
A Critical ICT Third-Party Provider (CTPP) is an information and communications technology (ICT) vendor that serves financial firms and has been formally designated by EU financial supervisors as systemically important to the stability of the EU financial system. Because these providers are considered so significant, they are subject to direct oversight rather than being monitored only by their individual financial-sector clients. The range of services involved can span core infrastructure through to business and data services.
Under the EU's Digital Operational Resilience Act (DORA), a CTPP is an ICT third-party service provider (as defined in point 19 of Article 3 of DORA) that has been designated by the European Supervisory Authorities (ESAs) as critical for financial entities. Designated CTPPs provide ICT services ranging from core infrastructure to business and data services to financial entities of varying types and sizes, and their designation triggers a dedicated oversight regime. The designation is a regulatory determination specific to the EU financial sector; it identifies systemic importance to financial stability and does not by itself constitute a certification, an attestation of security or operational adequacy, or an assessment of the provider's residual risk. Scope is limited to ICT services under DORA and to designated providers; non-designated ICT vendors and non-financial-sector relationships fall outside this specific classification.
Why it matters
The CTPP designation reflects a structural shift in how systemic ICT risk is governed in the EU financial sector. Historically, oversight of ICT vendors rested with each financial firm through its own third-party risk management program. But when many financial entities depend on the same small set of ICT providers, spanning core infrastructure to business and data services, the failure or disruption of one such provider can transmit risk across the entire financial system in ways no single client can see or manage alone. The CTPP regime addresses this concentration concern by designating systemically important providers and placing them under direct supervisory oversight rather than relying solely on client-by-client monitoring.
For risk and resilience professionals, the designation is a signal, not a guarantee. Being designated a CTPP identifies a provider as important enough to warrant dedicated oversight; it does not certify the provider's security, attest to its operational adequacy, or assess its residual risk. Financial entities that rely on a designated CTPP retain their own obligations to manage that relationship and cannot treat the oversight regime as a substitute for their own due diligence and ongoing monitoring.
The practical significance is jurisdictional and sector-specific. The classification applies to ICT services under DORA and to providers formally designated by the European Supervisory Authorities; it does not extend to non-designated ICT vendors, to non-financial-sector relationships, or to equivalent arrangements outside the EU. Professionals mapping supplier dependencies should therefore treat CTPP status as one input into concentration and single-source dependency analysis rather than a complete picture of a vendor's criticality across their own operations.
Who it's relevant to
Inside CTPP
Common questions
Answers to the questions practitioners most commonly ask about CTPP.
