DORA's First Oversight Cycle Puts Critical ICT Providers Under EU Scrutiny
The 19 critical ICT third-party providers designated under DORA now face direct ESA oversight, with joint examination teams assessing resilience against a December 2025 reference date.

What Changed
The first oversight cycle under the Digital Operational Resilience Act (DORA) is now live. On November 18, 2025, the European Supervisory Authorities (ESAs) — the EBA, ESMA and EIOPA — designated the first 19 critical ICT third-party providers (CTPPs), spanning major cloud, data-centre, telecom and financial-software firms, placing them under direct EU oversight for the first time. The latest annual registers of information, reflecting a December 31, 2025 reference date, were consolidated by national competent authorities and forwarded to the ESAs by March 31, 2026, feeding the ongoing criticality assessments and oversight. Joint Examination Teams are now assessing each CTPP's ICT risk management, incident reporting, subcontracting and cybersecurity controls, marking a shift from remediation guidance to enforcement-oriented supervision.
Who It Affects
The designated cloud, telecom, data-centre and financial-software providers, each of which must appoint an EU coordination entity and pay annual oversight fees. Indirectly, every bank, insurer, investment firm and payment institution that depends on these providers, since DORA makes financial entities accountable for the resilience of their ICT supply chain. Identity verification, fraud-detection and onboarding vendors sitting in that chain will feel the assurance expectations flow downstream from their financial-sector clients.
What to Do
Map your critical and important functions to the ICT providers that support them, and confirm your register of information reflects the December 2025 reference date accurately. Review contractual terms, exit strategies and subcontracting transparency against DORA's requirements. If you supply verification or fraud tooling to regulated firms, expect resilience, incident-reporting and audit-rights clauses to tighten. Ensure your own controls and evidence are documented well enough to satisfy a client passing DORA obligations through to you.
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds.
Learn More