Overview
- The European Supervisory Authorities published the first list of designated critical ICT third‑party providers, marking the start of active DORA oversight.
- Designees include Amazon Web Services, Google Cloud, Microsoft, Bloomberg, IBM, London Stock Exchange Group, Orange and Tata Consultancy Services.
- Supervisors will test risk management and governance and can mandate audits, incident reporting and onsite inspections of the named providers.
- The designations followed DORA’s formal process using financial firms’ Registers of Information, EU‑wide criticality assessments, notifications and a right to be heard.
- LSEG and Google Cloud welcomed the move, Microsoft pledged compliance, AWS said it was prepared to engage, and EU financial firms are expected to adjust sourcing and third‑party risk arrangements as the UK pursues a similar regime without final designations yet.