On 14 January 2026 the European Supervisory Authorities (EBA, EIOPA and ESMA — the ESAs) signed a Memorandum of Understanding with the Bank of England, the PRA and the FCA on oversight of critical ICT third-party service providers. The MoU covers UK banks, FMIs and dual-regulated groups using designated or designatable EU CTPPs or UK CTPs (cloud, data centre, telecoms, core software), EU financial entities of London groups subject to DORA third-party and incident-reporting duties, and the CTPs/CTPPs themselves once designated. The next official date on this file is the ESAs’ first annual report on DORA major ICT-related incidents, 3 June 2026.
The MoU does not replace your outsourcing and operational-resilience duties. The Bank of England is explicit: the UK CTP regime “does not reduce the responsibility of financial firms and Financial Market Infrastructures (FMIs) to manage their own operational resilience and third-party risks in line with existing outsourcing rules.” What changed on 14 January is a signed framework for cooperation, information sharing and coordination of CTPP/CTP oversight, including during incidents such as power outages or cyber-attacks.
Earlier on this file: the ESAs published the first CTPP list on 18 November 2025; UK CTP rules “came into effect on 1 January 2025 and apply once a CTP is designated by HM Treasury”, and designation has begun. Later: the ESAs’ first DORA major ICT-incident report on 3 June 2026. Do not treat the 5 February 2026 cutoff inside that report PDF as a firm-facing reporting deadline — the 3 June HTML does not say that.
ESMA records that the MoU was prepared under DORA Articles 36, 44 and 49, after a targeted equivalence assessment of the UK confidentiality and professional secrecy regime. Assume information you give one side of the corridor can be shared with the other. Map the 18 November 2025 CTPP list and HMT’s UK designation process onto your ICT register, then update incident and outsourcing files. A short self-check is the free DORA Readiness Diagnostic.
| Business type | What is in scope | What to do now |
|---|---|---|
| UK banks and dual-regulated groups with EU entities | DORA third-party and incident reporting on the EU side; UK CTP rules once HMT designates | Map each material ICT service to EU entity / UK entity / both. Flag any provider on the 18 November 2025 CTPP list. |
| UK FMIs | UK CTP regime plus existing FMI outsourcing rules; MoU covers incident coordination | Confirm which ICT providers could be HMT-designated. Align FMI incident scripts where the same CTP is used. |
| EU financial entities of London groups | DORA ICT third-party risk, register of information, major-incident reporting | Keep the register current. Check classification and notification clocks when the provider is a designated CTPP. |
| Designated or designatable CTPs / CTPPs | ESA oversight once designated as a CTPP; UK rules once HMT designates; MoU coordinates both | Expect coordinated information requests. Keep one evidence pack that can be shown to either side. |
| Other ICT vendors not designated | Still in your outsourcing / DORA third-party file until designated | Designation is a supervisor overlay, not the start of your duty. Manage concentration and exit now. |
Operational tip: The BoE PDF filename contains 12-jan-26. Publication and signing are locked from the BoE news and ESMA pages as 14 January 2026. Do not diary 12 January as the signature date.
| Step | Action | What operational staff must deliver | Official reference |
|---|---|---|---|
| 1 | Confirm which group entities sit under DORA and which under the UK CTP regime | Entity map: legal entity, licence, home NCA, UK dual-regulated flag | ESMA MoU news, 14/01/2026; BoE news, 14 January 2026 |
| 2 | Overlay the 18 November 2025 CTPP list on the ICT register | For each material service: provider, contracting entity, designated CTPP yes/no | ESAs designate CTPPs, 18/11/2025; DORA Oversight hub |
| 3 | Record UK CTP designation status | Log designated / in process / not designated; owner who watches HMT/BoE/PRA/FCA notices | BoE: rules in effect 1 January 2025; designation has begun |
| 4 | Refresh major-incident scripts for cross-border sharing | Who notifies which authority; what can be shared under the MoU; 24/7 CTP contacts | BoE: incidents such as power outages or cyber-attacks; ESMA: information sharing |
| 5 | Align outsourcing files | Audit, testing and information-sharing clauses; one evidence pack per designated provider | ESMA: MoU under DORA Arts 36, 44 and 49 |
| 6 | Brief the SMF/board owner and diary 3 June 2026 | One-page note plus owner for the later ESA incident report | ESMA and BoE MoU PDFs; ESA incident report 03/06/2026 |
GRT Consulting supports operational teams with ICT-register overlay against the ESA CTPP list and UK CTP designation, major-incident playbook updates for EU–UK information sharing, and evidence packs for designated providers.
Start with the free DORA Readiness Diagnostic. For a firm-specific review: T: +44 20 3695 9251 E: info@grtconsult.com Web: grtconsult.com
Sources