DORA: ESAs publish guidance on the supervisory framework for critical third-party providers

17/09/2025

On July 15, 2025, the European Supervisory Authorities (EBA, EIOPA, and ESMA) published explanatory guidance on the supervisory framework for critical third-party providers (CTPPs) under the Digital Operational Resilience Act (DORA).

This document aims to clarify the terms of “oversight,” a concept distinct from traditional supervision, which refers to direct supervision by the ESAs of certain technology providers deemed critical to the operational resilience of the European financial sector.