Nineteen Vendors Just Became Directly Regulated By The EU
On 18 November 2025, the EU's three financial regulators, the EBA, ESMA and EIOPA, together designated 19 technology companies as critical ICT third-party providers under the Digital Operational Resilience Act, putting each one under direct EU oversight for the first time. The list includes the major cloud providers AWS, Google Cloud, Microsoft and Oracle, alongside SAP, the telecom operators Deutsche Telekom and Orange, and specialist data and fintech providers including Bloomberg and NTT.
The designation followed a two-step process set out in the law itself: the regulators first pulled data from the Registers of Information that financial firms are required to file listing their ICT contracts, then ran a criticality assessment against each provider's systemic importance, market concentration and how easily a financial firm could switch away from it. Every provider under review was given the right to be heard and could submit a reasoned statement before the final list was published.
What Regulatory Oversight Actually Means For These 19
Each designated provider now answers to a Lead Overseer, one of the three EU regulators acting on behalf of all of them, which can inspect the provider's risk management and governance and order changes to how it serves its financial clients. That is a level of direct scrutiny cloud and telecom vendors have never faced from EU financial regulators before, and it runs alongside whatever national data protection or cybersecurity rules already applied to them.
The Lead Overseer charges the provider fees proportional to its turnover to cover the cost of that oversight, under Article 43 of the law. Separately, if a provider fails to comply with a measure the Lead Overseer orders, it can face a penalty payment of up to 1 percent of its average daily worldwide turnover for every day the non-compliance continues, capped at six months.
| Metric | Figure |
|---|---|
| Providers designated critical | 19 |
| DORA compliance became mandatory | 17 January 2025 |
| Critical providers designated | 18 November 2025 |
| Maximum daily penalty for non-compliance | 1 percent of average daily worldwide turnover, up to 180 days |
Why Only Nineteen, And What That Leaves Out
Being named critical is a narrow test, not a general judgment about a vendor's size or importance. The regulators asked how many financial institutions depend on a given provider, how concentrated that dependency is across the market, and whether financial firms could realistically switch to an alternative if the provider failed, and only 19 companies cleared that bar.
Every other cloud, software or data vendor a European financial firm uses still falls outside direct EU oversight entirely. Those relationships stay governed by the financial firm's own DORA compliance program and by the annual Register of Information filing, whose second full cycle closed in March 2026, which is how the regulators will keep spotting which vendors deserve critical status next.
What Changes In A Vendor Contract Today
A procurement or legal team negotiating with one of the 19 designated providers now has a regulator to point to that the vendor already answers to directly, which changes what a reasonable incident reporting clause or exit strategy clause can demand. An institution can reference the Lead Overseer's own oversight findings and penalty powers instead of relying solely on contractual promises the vendor wrote itself.
The opposite is just as important for a budget conversation. If a firm's cloud or software vendor is not one of the 19, none of this direct oversight applies, and the entire compliance burden for that relationship still sits with the buyer's own Register of Information entry and its own risk assessment, not with Brussels.
Why We Do This
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: The EU Just Moved Your AI Act Deadline by 16 Months | Three AI Vendors Went Down in One Window on Sept 3



