Commission Delegated Regulation that supports DORA regulation
Full Text of CDR 2025-295
Information to be provided by ICT third-party service provider
Article 1 – Information to be provided by ICT third-party service provider in the application to be designated as critical
- The information and communication technology (ICT) third-party service provider shall submit the following information in the reasoned application for a voluntary request under Article 31(11) of Regulation (EU) 2022/2554 to be designated as critical pursuant to Article 31(1), point (a), of Regulation (EU) 2022/2554:
- name of the legal entity;
- legal entity identification code;
- name of contact person and contact details of the critical ICT third-party service provider;
- country where the legal entity has registered office;
- description of the corporate structure including at least information on its parent company and other related undertakings providing ICT services to Union financial entities. That information shall include where applicable;
- name of the legal entities;
- legal entity identification code;
- country where the legal entity has registered office;
- an estimation of the market share of the ICT third-party service provider in the Union financial sector and estimation of the market share per type of financial entity as referred to in Article 2(1) of Regulation (EU) 2022/2554 as of the year of submission of the application to be designated as critical and the year before that application;
- a description of each ICT service provided to Union financial entities including:
- a description of the nature of business and the type of ICT services provided to financial entities;
- a list of the functions of financial entities supported by the ICT services provided, where available;
- information whether the ICT services provided to financial entities support critical or important functions, where available;
- a list of financial entities that make use of the ICT services provided by the ICT third-party service provider, including the following information for each of the financial entity serviced, where available:
- name of the legal entity;
- legal entity identification code, where known to the ICT third-party service provider;
- type of financial entity as specified in Article 2(1) of Regulation (EU) 2022/2554;
- the geographic location from which the ICT services are provided to that specific legal entity;
- a list of the critical ICT third-party service providers included in the latest available list of such providers published by the ESAs pursuant to Article 31(9) of Regulation (EU) 2022/2554 that rely on the services provided by the applicant where available;
- a self-assessment as regards the following:
- the degree of substitutability for each ICT service provided by the applicant considering the following:
- the market share of the ICT third-party service provider in the Union financial sector;
- the number of known relevant competitors per type of ICT services, or group of ICT services;
- description of specificities relating to the ICT services offered, including in relation to any proprietary technology, or the specific features of the ICT third-party service provider’s organisation or activity;
- knowledge about the availability of the alternative ICT third-party service providers to provide the same ICT services as the ICT third-party service provider submitting the application;
- information on a future business strategy in relation to the provision of ICT services and infrastructure to financial entities in the Union, including any planned changes in the group or management structure, entry into new markets or activities;
- identification of the subcontractors of the ICT third-party service provider which have been designated as critical ICT third-party service providers;
- any other reasons relevant for the ICT third-party service provider’s application to be designated as critical.
- Where the ICT third-party service provider belongs to a group, the information referred to in paragraph 1 shall be provided in relation to the ICT services provided by the group as a whole.