UPDATE: EU and UK regulators lock DORA/CTP oversight cooperation

UPDATE: EU and UK regulators lock DORA/CTP oversight cooperation

On 14 January 2026 the European Supervisory Authorities (EBA, EIOPA and ESMA — the ESAs) signed a Memorandum of Understanding with the Bank of England, the PRA and the FCA on oversight of critical ICT third-party service providers. The MoU covers UK banks, FMIs and dual-regulated groups using designated or designatable EU CTPPs or UK CTPs (cloud, data centre, telecoms, core software), EU financial entities of London groups subject to DORA third-party and incident-reporting duties, and the CTPs/CTPPs themselves once designated. The next official date on this file is the ESAs’ first annual report on DORA major ICT-related incidents, 3 June 2026.

Why operational teams should care

The MoU does not replace your outsourcing and operational-resilience duties. The Bank of England is explicit: the UK CTP regime “does not reduce the responsibility of financial firms and Financial Market Infrastructures (FMIs) to manage their own operational resilience and third-party risks in line with existing outsourcing rules.” What changed on 14 January is a signed framework for cooperation, information sharing and coordination of CTPP/CTP oversight, including during incidents such as power outages or cyber-attacks.

Earlier on this file: the ESAs published the first CTPP list on 18 November 2025; UK CTP rules “came into effect on 1 January 2025 and apply once a CTP is designated by HM Treasury”, and designation has begun. Later: the ESAs’ first DORA major ICT-incident report on 3 June 2026. Do not treat the 5 February 2026 cutoff inside that report PDF as a firm-facing reporting deadline — the 3 June HTML does not say that.

ESMA records that the MoU was prepared under DORA Articles 36, 44 and 49, after a targeted equivalence assessment of the UK confidentiality and professional secrecy regime. Assume information you give one side of the corridor can be shared with the other. Map the 18 November 2025 CTPP list and HMT’s UK designation process onto your ICT register, then update incident and outsourcing files. A short self-check is the free DORA Readiness Diagnostic.

DORA/CTP oversight requirements by business type

Business type What is in scope What to do now
UK banks and dual-regulated groups with EU entities DORA third-party and incident reporting on the EU side; UK CTP rules once HMT designates Map each material ICT service to EU entity / UK entity / both. Flag any provider on the 18 November 2025 CTPP list.
UK FMIs UK CTP regime plus existing FMI outsourcing rules; MoU covers incident coordination Confirm which ICT providers could be HMT-designated. Align FMI incident scripts where the same CTP is used.
EU financial entities of London groups DORA ICT third-party risk, register of information, major-incident reporting Keep the register current. Check classification and notification clocks when the provider is a designated CTPP.
Designated or designatable CTPs / CTPPs ESA oversight once designated as a CTPP; UK rules once HMT designates; MoU coordinates both Expect coordinated information requests. Keep one evidence pack that can be shown to either side.
Other ICT vendors not designated Still in your outsourcing / DORA third-party file until designated Designation is a supervisor overlay, not the start of your duty. Manage concentration and exit now.

Operational tip: The BoE PDF filename contains 12-jan-26. Publication and signing are locked from the BoE news and ESMA pages as 14 January 2026. Do not diary 12 January as the signature date.

Step-by-step: initial project plan

Step Action What operational staff must deliver Official reference
1 Confirm which group entities sit under DORA and which under the UK CTP regime Entity map: legal entity, licence, home NCA, UK dual-regulated flag ESMA MoU news, 14/01/2026; BoE news, 14 January 2026
2 Overlay the 18 November 2025 CTPP list on the ICT register For each material service: provider, contracting entity, designated CTPP yes/no ESAs designate CTPPs, 18/11/2025; DORA Oversight hub
3 Record UK CTP designation status Log designated / in process / not designated; owner who watches HMT/BoE/PRA/FCA notices BoE: rules in effect 1 January 2025; designation has begun
4 Refresh major-incident scripts for cross-border sharing Who notifies which authority; what can be shared under the MoU; 24/7 CTP contacts BoE: incidents such as power outages or cyber-attacks; ESMA: information sharing
5 Align outsourcing files Audit, testing and information-sharing clauses; one evidence pack per designated provider ESMA: MoU under DORA Arts 36, 44 and 49
6 Brief the SMF/board owner and diary 3 June 2026 One-page note plus owner for the later ESA incident report ESMA and BoE MoU PDFs; ESA incident report 03/06/2026

Practical checklist for operational teams

  • ICT register vs CTPP list — Reconcile every material ICT service to the 18 November 2025 list. Record on-list / not-on-list / group affiliate.
  • UK designation watch — UK rules apply once HMT designates. Named owner on official notices; do not assume the EU list is the UK list.
  • Contracting entity — Record which legal entity signed. Intra-group support is not that record.
  • Incident clocks — DORA major-incident reporting remains a financial-entity duty. The MoU helps authorities share; it does not pause your clock.
  • Evidence pack — Policies, concentration metrics, substitutability, tests and incident logs in one folder per designated provider.
  • Self-check — Run the DORA Readiness Diagnostic and file the output with the gap analysis.

Common operational pitfalls

  • Hanging this January file on a DORA “in force” anniversary that is not on the locked 200 pages. The January lock is the 14 January 2026 MoU.
  • Treating CTPP designation as a January 2026 event. The first list is 18 November 2025.
  • Using 12 January because it appears in a PDF filename.
  • Assuming the MoU moves incident-reporting duty onto the CTP. Firms and FMIs remain responsible.
  • Treating the 5 February 2026 cutoff inside the later incident-report PDF as a firm-facing deadline.
  • Running separate EU DORA and UK operational-resilience workstreams that never compare the same provider.

How GRT Consulting can help

GRT Consulting supports operational teams with ICT-register overlay against the ESA CTPP list and UK CTP designation, major-incident playbook updates for EU–UK information sharing, and evidence packs for designated providers.

Start with the free DORA Readiness Diagnostic. For a firm-specific review: T: +44 20 3695 9251 E: info@grtconsult.com Web: grtconsult.com


Sources

.., 16th January 2026

GRT Consulting

Speak to us about how we can help you

T: +44 20 3695 9251

E: info@grtconsult.com

Submit Request for Proposal