Loading…
Loading…
This action is the first operative exercise of the DORA CTPP designation power under Article 31 of Regulation (EU) 2022/2554. The parent DORA framework (filed at 2022-12-14-eu-dora-regulation-2022-2554) created the legal architecture; this designation activates it.
The Joint Committee of ESAs assessed each potential CTPP against criteria in Commission Delegated Regulation 2024/1502 (criticality-assessment criteria), including:
important functions; estimated switching cost and concentration at sector level
comparable service without material operational disruption
across multiple regulated entity types simultaneously
by the provider
All 19 designated CTPPs were notified in advance and had the opportunity to submit observations before the final designation decision.
Each CTPP is assigned a single lead ESA based on the financial-sector type where the provider has the greatest systemic footprint:
The lead overseer chairs the Joint Examination Team (JET) for each CTPP. JETs comprise staff from all three ESAs plus relevant national competent authorities and may request information, conduct investigations, and carry out on-site inspections at any premises of the CTPP worldwide.
Non-compliant CTPPs face periodic penalty payments of up to 1% of average daily worldwide turnover for each day of non-compliance, until the CTPP remedies the deficiency. This is among the most aggressive extraterritorial turnover-linked penalty regimes imposed on US technology companies by an EU regulatory body (comparable in structure but not in quantum to the Digital Markets Act gatekeeper penalties under Article 26 DMA).
The 19 CTPPs span hyperscale public cloud infrastructure, core-banking platforms, financial data and analytics infrastructure, and specialist managed-service providers:
full list available in the ESMA CTPP designation list PDF
designation, EU financial entities self-assessed and disclosed ICT concentration risk under DORA Art. 28-30. Post-designation, the ESAs have independent powers to examine, restrict, and penalise the CTPPs themselves — shifting the regulatory lever from the financial-entity customer to the cloud provider directly.
where EU financial-entity workloads are hosted. AWS (us-east-1 and global), Microsoft Azure, and Google Cloud all hold significant EU financial-sector workloads in US data centres — those facilities are now nominally accessible to ESA inspection, creating a potential US-EU regulatory friction point if the US government were to assert that ESA on-site inspections at US facilities conflict with US law.
of any product tracking EU financial-sector ICT concentration risk. It gives specific, named entities against which EU banks and insurers must map their ICT supply chains — the list is no longer hypothetical.
(a) provide all information requested by the JET within statutory deadlines; (b) submit to investigations and on-site inspections; (c) carry out recommendations issued by the lead overseer; (d) comply with DORA's ICT contractual requirements when contracting with EU financial entities. Non-EU CTPPs (US and Indian firms) face EU-jurisdiction compliance costs for the first time outside NIS2/GDPR territory.
periodically. Co-location providers (Equinix, Digital Realty), managed-security-service providers, and large SaaS platforms (Salesforce, Workday) may be designated in future waves if their systemic footprint reaches the threshold.
the Financial Services and Markets Act 2023 is expected to produce its own first designation list in 2026, likely overlapping substantially with the EU CTPP list — creating a dual-jurisdiction compliance obligation for US hyperscalers.
constitute an impermissible extraterritorial exercise of EU jurisdiction?
target for the first comprehensive examination round.
JET finds unacceptable concentration? The framework allows ESAs to recommend contractual modifications but does not (yet) mandate divestment.
confidential at the provider's request?