Critical Third-Party Provider (CTPP)
A Critical Third-Party Provider (CTPP) is a technology vendor that supplies information and communications technology (ICT) services to financial firms and has been formally designated by EU authorities as so important that a failure or disruption on its part could affect the stability of the financial system. The designation is made by the European Supervisory Authorities under the EU's Digital Operational Resilience Act (DORA). These providers deliver services ranging from core infrastructure to business and data services to financial entities of all types.
Under DORA, a CTPP is an ICT third-party service provider (as defined in point 19 of Article 3 of DORA) that has been formally designated by the European Supervisory Authorities (ESAs) as critical, meaning systemically important, to the financial entities it serves within the EU. Designation brings the provider within DORA's direct oversight framework rather than regulating it solely through the contractual obligations of the financial entities that use it. The concept is a regulatory and operational-resilience construct specific to the EU financial-sector supervisory regime; it is not an insurance policy term, and designation as a CTPP does not by itself determine whether losses arising from that provider's disruption are covered under any cyber or operational insurance policy, which remains subject to the specific wording, exclusions, and conditions of the relevant policy. Designated CTPPs provide a range of ICT services to financial entities of all types, spanning core infrastructure through business and data services.
Why it matters
The CTPP designation reflects a structural reality of modern financial services: firms increasingly depend on a concentrated set of shared technology providers for core infrastructure, business services, and data services. When many financial entities rely on the same provider, a single disruption at that provider can propagate across the sector, creating concentration risk that individual firm-level contractual controls were not designed to address. By allowing the European Supervisory Authorities to designate such providers as critical and bring them within DORA's direct oversight framework, the EU aims to supervise these systemic dependencies at the source rather than only through the obligations imposed on each financial entity that uses them.
Who it's relevant to
Inside CTPP
Common questions
Answers to the questions practitioners most commonly ask about CTPP.
