NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
DORA 'Significant': The Critical ICT Provider Test
Learn

DORA 'Significant': The Critical ICT Provider Test

·Alexander Sverdlov

If you are asking what "significant" means under DORA, the honest answer is that DORA does not use "significant" as a single defined threshold. It uses two more precise words. Incidents are classified as "major". ICT third-party providers are designated as "critical". The question most people are really asking - will the regulators treat us, or our key supplier, as important enough to face the heavy end of the regime - maps to the designation of a critical ICT third-party service provider under Article 31 of Regulation (EU) 2022/2554. This guide sets out that test: the criteria, who decides, the two-step method, the exclusions, and what designation actually triggers.

What DORA actually calls it
Governing lawWho is designatedWho decidesThe four criteriaIf designatedSignificant, major, critical: three different DORA words

The confusion is understandable, because DORA uses a small set of loaded words in specific ways, and "significant" is the one it uses least precisely. Getting them straight tells you which test you are actually facing.

TermWhere it bites
Major (incident)Critical or important functionCritical (ICT provider)

The rest of this guide is about the third one, because that is the designation with the widest consequences and the one behind the question "are we, or is our cloud provider, significant under DORA?".

The four criteria for a critical ICT provider

Article 31(2) sets four criteria the ESAs assess when deciding whether to designate a provider as critical:

  • Systemic impact. The systemic impact on the stability, continuity or quality of the provision of financial services in the Union if the provider suffered a large-scale operational failure.
  • Systemic importance of the reliant entities. The systemic character or importance of the financial entities that rely on the provider, measured in part by how many are global or other systemically important institutions (G-SIIs or O-SIIs).
  • Reliance for critical or important functions. The extent to which financial entities rely on the provider for functions that are critical or important to them.
  • Substitutability. The degree to which the provider could be replaced, taking account of the availability of alternatives and the cost and difficulty of migrating away.

These are the primary criteria in the regulation itself. The precise sub-criteria, formulas and quantitative thresholds sit one level down, in Delegated Regulation (EU) 2024/1502.

The two-step designation method

Delegated Regulation (EU) 2024/1502 turns the four high-level criteria into a two-step assessment that the ESAs apply consistently across candidate providers.

Step 1 is a quantitative gate. The provider is measured against a set of quantitative sub-criteria drawn from the four headline criteria - how many financial entities use it, the systemic weight and total assets of those entities, the extent to which it supports critical or important functions, and how substitutable it is. A provider has to meet all of the step-1 sub-criteria to move on. Providers that do not clear the gate are not designated.

Step 2 is a qualitative assessment. For providers that clear step 1, the Oversight Forum carries out a fuller assessment and recommends whether the provider should be designated. The ESAs, through the Joint Committee, make the final designation only where step 1 is met and step 2 is positive. The Delegated Regulation holds the exact sub-criteria and thresholds, so a provider or a financial entity that wants a firm answer should work through that text rather than rely on a rule of thumb.

Venvera DORA dashboard showing ICT third-party providers and critical-or-important function mapping
Mapping which providers support critical or important functions is the same evidence base the designation criteria draw on.

Who designates, and the Lead Overseer

Designation is a European, not a national, decision. The three ESAs - the European Banking Authority, the European Securities and Markets Authority, and the European Insurance and Occupational Pensions Authority - act through their Joint Committee, on a recommendation from the Oversight Forum established under Article 32. When a provider is designated, the ESAs appoint one of the three as its Lead Overseer. The Lead Overseer is the ESA responsible for the financial entities that, together, hold the largest share of total assets among all the entities using that provider, measured from their individual balance sheets.

Who is excluded from designation

Article 31(8) carves several categories out of the designation regime, even where they might otherwise look significant:

  • Financial entities that provide ICT services to other financial entities.
  • ICT providers already subject to oversight frameworks that support the tasks of the central banks of the European System of Central Banks.
  • ICT intra-group service providers.
  • Providers that supply services solely in one Member State to financial entities active only in that Member State.

The voluntary opt-in

Designation is not only top-down. Under Article 31(11), a provider that has not been designated can ask to be. It submits a reasoned application to the EBA, ESMA or EIOPA, which decides within six months. Some providers choose this route deliberately, because a single EU oversight relationship can be simpler to manage than fielding the same assurance questions from every regulated customer.

What designation actually triggers

Designation moves a provider from being supervised indirectly, through its financial-entity customers, to being supervised directly by its Lead Overseer. The Lead Overseer can request information, conduct general investigations and on-site inspections, and issue recommendations covering matters such as ICT security, subcontracting, and the provider's own risk management. Designated providers also pay oversight fees that cover the cost of that supervision.

Two consequences are worth singling out. First, a critical provider established outside the Union must set up a subsidiary in the EU within 12 months of designation, or financial entities may not continue to use it (Article 31(12)). Second, the arrangement has teeth at the customer end: where a designated provider does not follow a Lead Overseer recommendation on a serious risk, competent authorities can ultimately require financial entities to suspend or terminate their use of that provider. So even though the financial entity is not the one designated, the designation reshapes the contracts and exit plans it has to keep ready.

Frequently Asked Questions

Does DORA designate my financial firm as "significant"?

Not through the Article 31 test. That test designates ICT third-party providers as critical, not financial entities. Your firm feels the designation as a user of a critical provider - through the contractual, register, and exit-planning duties that attach to relying on one - rather than by being designated itself. If you are asking whether your firm is a "significant institution", that is a banking-supervision concept under the SSM, separate from DORA.

Who decides whether an ICT provider is critical under DORA?

The three ESAs (EBA, ESMA and EIOPA), acting through their Joint Committee on a recommendation from the Oversight Forum. It is a single European designation, not a national one, and each designated provider is assigned a Lead Overseer drawn from the three ESAs.

What is the difference between "major" and "critical" under DORA?

"Major" describes an ICT-related incident that crosses the materiality thresholds in Delegated Regulation (EU) 2024/1772 and must be reported on the 4-hour, 72-hour and one-month clock. "Critical" describes an ICT third-party provider designated under Article 31 for direct EU oversight. One is about events; the other is about suppliers.

Can a provider ask to be designated critical?

Yes. Article 31(11) lets a provider that was not designated submit a reasoned application to the EBA, ESMA or EIOPA to be treated as critical, with a decision due within six months.

Does a non-EU cloud provider have to open an EU entity if designated?

Yes. Article 31(12) requires a critical ICT third-party provider established in a third country to set up a subsidiary in the Union within 12 months of designation, otherwise financial entities may not keep using its services.

Getting ready for the critical-provider regime with Venvera

Whether or not any single provider is designated, the evidence the criteria draw on is the same evidence DORA already asks you to hold: which providers support critical or important functions, how concentrated you are on each, and how you would exit. The Venvera DORA module keeps that mapping current, and the third-party risk register lines up with the DORA Register of Information so the same records answer both your outsourcing duties and any question about a provider's criticality. If you want a fast read on where you stand, run a free compliance check.

Primary sources

This guide is drawn from Regulation (EU) 2022/2554 (DORA), in particular Article 31 and Article 32; and Commission Delegated Regulation (EU) 2024/1502 on the criteria for designating critical ICT third-party service providers. The incident materiality thresholds referenced above are in Commission Delegated Regulation (EU) 2024/1772. Confirm the current text before relying on a specific criterion.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS