Operational notes Regulation

DORA names its critical suppliers: Europe’s financial sector runs on five clouds

4 min read

Corridor in a server room with rows of rack cabinets
The resilience of an entire sector hanging on a handful of suppliers. Photo: The National Archives (UK), CC BY 3.0.

On 18 November 2025 the European Supervisory Authorities (EBA, EIOPA, ESMA) published a list bound to spark debate: the first critical ICT providers designated under the DORA regulation. Nineteen names, and among the first — predictably — AWS, Google Cloud, Microsoft, Oracle, SAP, Deutsche Telekom. In plain terms: the European Union has put it in writing that the operational resilience of its own financial sector rests, to a significant degree, on a handful of providers, almost all of them non-European. Direct supervision of these entities begins in 2026. It is a banking-sector story, but the lesson — about concentration risk — applies to every company that has moved critical pieces of its operations onto a small number of suppliers.

What DORA is, in brief

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has been in force since January 2023 and applicable since 17 January 2025. It imposes five families of obligations on banks, insurers and other financial entities: ICT risk management, incident reporting, resilience testing (up to threat-led penetration testing), oversight of third-party providers and intelligence sharing. The novelty of 2025-2026 is that DORA reaches providers directly: cloud providers, data centres, software vendors and system integrators serving the financial sector fall within its scope — and for those deemed “critical”, direct supervision by the authorities kicks in, with penalties of up to 1% of average daily worldwide turnover for a maximum of six months.

The point that matters for everyone: concentration is a risk, not a detail

DORA formalises an uncomfortable insight: when an entire sector depends on the same three or four providers, the failure (or the decision) of just one becomes a systemic risk. The list of critical providers is, in effect, a map of that dependency. This is not only a banking problem: it is the same pattern that the United Kingdom called an “unacceptable point of weakness” regarding a single supplier, and it is the reason why sovereignty is measured by the exit clause, not the slogan. Every company should ask itself the question DORA imposes on banks: if my critical supplier stops tomorrow, what stops with it — and for how long?

The chain runs lower than you think

There is an effect that is easy to miss: DORA does not only touch the large players. Financial entities must govern their own ICT supply chain, and this cascades downstream — onto their suppliers, and onto their suppliers’ suppliers. If you serve a bank, an insurer or one of their system integrators, it is likely that forthcoming tender specifications will include requirements derived from DORA: demonstrable operational continuity, incident management with defined timeframes, audit rights, exit plans. Whoever turns up with these documents already in place wins the contract; whoever discovers them during negotiation loses it. It is the same preparatory work that NIS2 and the CRA already require: inventory, visibility, a response process — done once, valid for all.

What to do now (even outside the financial sector)

  1. Map your critical suppliers, not just your contracts: which services, if they stop, stop you? Cloud, connectivity, core management systems.
  2. Measure your concentration: how many vital processes depend on the same supplier? A single name appearing on too many lines is your systemic risk.
  3. Demand exit and continuity plans in your contracts: not “if it happens”, but “how do we get out, in how much time, with which data”.
  4. If you serve the financial sector, align now with the downstream DORA requirements: continuity, incident response, audit, reversibility. These will become the baseline for staying in the running.

Resilience does not mean bringing everything in-house: it means knowing who you depend on and having a plan B that works. DORA imposes this on banks; common sense suggests it to everyone — and it is the first step of every operational trial we build: data and processes under your control, suppliers replaceable by design.

Want to measure your concentration on critical suppliers — and what a plan B would cost? Half an hour with one of our experts for the first map.

Sources