ICT Third-Party Service Provider
An ICT third-party service provider is a company that supplies information and communication technology (ICT) services, such as digital and data services, to another organization. Under the EU's Digital Operational Resilience Act (DORA), financial entities that rely on these external providers must manage the risks arising from that dependence. Some providers may be further designated as 'critical' where they are considered systemically important to the EU financial sector.
Within the EU Digital Operational Resilience Act (DORA) framework, an ICT third-party service provider (ICT TPSP) is defined as an undertaking that provides ICT services (per Article 3 point 19 DORA), where ICT services are generally understood to encompass digital and data services provided to one or more internal or external users. The use of such providers gives rise to 'ICT third-party risk', the ICT-related risk that may arise for a financial entity in connection with its use of externally provided ICT services. A subset of ICT TPSPs may be designated as 'critical ICT third-party service providers' (CTPPs) by the European Supervisory Authorities under Article 31, a designation that in the reviewed sources is described as applying where a provider is systemically important to the EU financial sector and cumulatively meets the applicable quantitative sub-criteria of the designation assessment. Note that a regulated financial entity may itself additionally qualify as an ICT TPSP where it provides ICT services to others. Precise definitional wording, criteria thresholds, effective dates, and scope of application should be verified against the primary DORA text and its implementing measures, and applicability is specific to entities within DORA's scope.
Why it matters
The concept of the ICT third-party service provider sits at the heart of DORA's approach to operational resilience in the EU financial sector. Financial entities increasingly depend on externally provided digital and data services, and that dependence introduces ICT third-party risk, the ICT-related risk that may arise for a financial entity in connection with its use of these external services. Because a disruption, failure, or security weakness at a provider can propagate into the financial entities that rely on it, DORA requires those entities to actively identify, assess, and manage the risks flowing from these relationships rather than treating outsourcing as a transfer of responsibility.
The stakes rise further where a provider is designated as a 'critical ICT third-party service provider' (CTPP). Under Article 31, the European Supervisory Authorities may designate a provider as systemically important to the EU financial sector where it cumulatively meets the applicable quantitative sub-criteria of the designation assessment. Such a designation reflects the recognition that concentration of critical services in a small number of providers can create sector-wide exposure, so certain providers warrant heightened attention. For financial entities, understanding whether a provider falls within scope, and potentially within the critical designation, shapes contractual, monitoring, and governance obligations.
A further nuance that matters in practice is that a regulated financial entity may itself additionally qualify as an ICT third-party service provider where it provides ICT services to others. This means an organization can occupy both sides of the relationship, adding complexity to how it maps and manages its obligations. Because the precise definitional wording, criteria thresholds, effective dates, and scope depend on the primary DORA text and its implementing measures, entities should verify specifics against those sources and assess applicability to their own circumstances.
Who it's relevant to
Inside ICT TPSP
Common questions
Answers to the questions practitioners most commonly ask about ICT TPSP.

