DORA Enforcement 2026: the CTPP List and What It Means for Your Data Room

DORA's critical ICT third-party provider (CTPP) list designates the most systemically important technology vendors for direct ESA oversight. If your data room provider is designated, you face enhanced contract review obligations. If it is not, DORA still applies to your VDR contract through Article 30. The CTPP list does not determine DORA scope. It determines oversight intensity.

The Digital Operational Resilience Act entered force on 17 January 2025 and applies in full to EU financial entities and their ICT third-party service providers. The European Supervisory Authorities (EBA, EIOPA, ESMA) are now conducting the first wave of CTPP designations. This article explains what that process means for financial entities using a virtual data room, what Article 30 requires regardless of CTPP status, and how to review your VDR contract to ensure it meets both the baseline and the enhanced requirements.

Published: 19 July 2026. Updated: 19 July 2026.


What DORA's CTPP Designation Means for Financial Entities

DORA entered force on 17 January 2025. The European Supervisory Authorities (EBA, EIOPA, and ESMA), acting through the Joint ESA Oversight Network, are now conducting the first wave of CTPP designations. A designation as a critical ICT third-party provider triggers a new layer of regulatory engagement: the designated provider is assigned a Lead Overseer, who has the power to conduct general investigations, request information, and issue recommendations. The process is the EU equivalent of what other jurisdictions call enhanced third-party supervision.

For financial entities, a CTPP designation by one of your ICT providers creates indirect but concrete obligations. You must update your ICT third-party risk register to record the designation, review the contractual clauses you have in place with that provider to verify they satisfy both Article 30 DORA (the minimum content requirement) and any enhanced requirements the Lead Overseer may issue, and ensure that your audit rights under those contracts are exercisable in practice. The exit strategy clause becomes particularly important: DORA requires that financial entities have a credible substitution plan for any critical ICT provider.

Not every data room provider will receive a CTPP designation. Designation criteria under Article 31 DORA focus on systemic importance to the financial sector, replaceability, and the degree of interdependence among financial entities. Niche or single-sector VDR providers are unlikely to be designated in the first wave. However, the practical implication for financial entities is clear: regardless of whether your VDR provider is designated, the Article 30 minimum contractual requirements apply to every ICT third-party contract, including your data room contract.


DORA Obligations That Apply to Virtual Data Room Contracts

Even without a CTPP designation, DORA applies to all ICT third-party services used by in-scope financial entities. The in-scope entities include banks, investment firms, insurance undertakings, asset management companies, payment institutions, electronic money institutions, and crypto-asset service providers. If your organisation falls into any of these categories, your VDR contract must meet the minimum content requirements set out in Article 30 DORA.

The key obligation is that the contract must be a written agreement that covers a defined minimum set of clauses. These are not optional: competent authorities can request the contract, and a missing clause is a compliance finding. The Article 30 minimum content requirements are as follows:

  • A clear description of ICT services and functions to be performed, including whether sub-ICT services are involved and their providers.
  • Service-level targets for availability, integrity, and continuity, with measurable indicators.
  • Data location: the country or countries where data is processed, stored, and backed up.
  • Sub-processor list with the right to be informed of any changes and to object.
  • The right to audit the provider directly or through a designated third-party auditor, including by competent authorities.
  • Incident notification timelines: the provider must notify the financial entity promptly of any incidents with potential impact on the contracted services.
  • Business continuity provisions: recovery time objective (RTO) and recovery point objective (RPO), tested and documented.
  • Termination and exit assistance: the right to terminate with adequate notice and receive data return, migration support, and deletion certification.
  • Data portability and format standards so that migration is operationally feasible.

CTPP Designation Timeline and Oversight Cycle

The Joint ESA Oversight Network began preparatory work in 2025, mapping the ICT third-party landscape across the EU financial sector. The first CTPP designations are proceeding in phases through 2026, starting with providers whose services are used by the largest number of significant financial entities. The ESAs publish the list of designated CTPPs in the Official Journal of the European Union; that publication triggers the formal oversight regime.

Once designated, a CTPP works with the appointed Lead Overseer (EBA for banking-sector providers, EIOPA for insurance, ESMA for investment services). The Lead Overseer conducts a general investigation, issues an assessment, and may issue recommendations. CTPPs must respond to these recommendations and document compliance. The oversight cycle is intended to run annually, with ad-hoc investigations triggered by significant incidents.

For financial entities, the pass-through effect is what matters most in practice. If your VDR provider is designated, the Lead Overseer may issue recommendations that affect how the provider operates its service, what contractual terms it offers, and what information it shares with financial entity clients. You may receive updated DPA terms, revised sub-processor documentation, or requests to refresh your contractual annexes. Building that refresh cadence into your vendor management programme now, before designations are final, reduces the operational burden when they arrive.


What Financial Entities Should Check in Their VDR Contract Now

Before the next CTPP designation wave, financial entities should run a systematic review of their VDR contract. The checklist below covers the most common gaps found in VDR contracts that were not drafted with DORA in mind.

  • Confirm the Data Processing Agreement (DPA) covers both Article 28 GDPR and Article 30 DORA. Many VDR providers issued GDPR DPAs before DORA entered force and have not yet updated them to include Article 30 clauses.
  • Confirm the sub-processor list is available and current. Article 30 requires the list to be maintained and the financial entity to be notified of changes, with a right to object.
  • Confirm audit rights are exercisable: the contract must give you (and your competent authority) the right to audit the provider, either directly or through a designated third-party auditor.
  • Confirm the exit clause gives adequate notice (6 to 12 months is typical), data export in a portable format, migration assistance, and a deletion certificate.
  • Confirm the VDR is entered in your DORA ICT third-party register. This register is a regulatory requirement under Article 28(3) DORA, and regulators are now inspecting it.
  • Confirm RTO and RPO service-level targets are documented in the contract, not just in the provider's marketing materials.
  • Confirm incident notification timelines: the provider must commit to notifying you within a defined period, aligned with DORA's 72-hour major incident reporting window.

Papermark: Best for DORA-Ready Data Rooms with EU Hosting

Papermark is best for financial entities that need a DORA-aware VDR with EU hosting, an auditable sub-processor list, and published contractual terms. The platform defaults to EU hosting in ISO 27001-certified AWS infrastructure in Frankfurt (eu-central-1), is SOC 2 Type II certified, and maintains a published GDPR DPA and sub-processor list. DORA-aware contract terms are available on request for financial entity clients. For entities that require the highest level of operational control, Papermark's self-hosted Enterprise tier allows the data room to run on the financial entity's own infrastructure, removing the VDR provider from the Article 30 ICT third-party chain entirely.

On pricing, Papermark publishes its tiers clearly: Free at EUR 0, Pro at EUR 24 per month, Business at EUR 59 per month, and Data Rooms at EUR 99 per month covering unlimited rooms and documents, granular permissions, dynamic watermarking, NDA enforcement, and a permission-based Q&A module. Enterprise pricing with SSO and self-hosting is available on request. Month-to-month billing means no long-term lock-in, which aligns well with the exit-strategy obligations that DORA imposes on financial entities. A Papermark engagement can be terminated on short notice, with data export available in standard formats.

For financial entities preparing their DORA posture, three Papermark characteristics are directly relevant. First, the EU Frankfurt hosting satisfies the data location disclosure obligation under Article 30. Second, the published DPA and sub-processor list can be attached directly to the DORA ICT third-party register entry for the VDR. Third, the self-hosting option, available at Enterprise tier, removes the ICT third-party risk from the DORA register entirely. See also /compliance/dora for the full DORA framework and /providers/papermark for the Papermark provider profile.


Common Mistakes When Assessing DORA Compliance for Data Rooms

The most common mistake is treating a GDPR DPA alone as sufficient DORA compliance. A GDPR Article 28 DPA covers data protection obligations but does not include the DORA Article 30 requirements for service levels, RTO and RPO documentation, business continuity, audit rights for the competent authority, or exit assistance. Financial entities must either obtain a separate DORA contractual annex from their VDR provider or request an updated DPA that incorporates both Article 28 GDPR and Article 30 DORA clauses.

The second mistake is assuming that CTPP designation is the only trigger for reviewing the VDR contract. Article 30 DORA applies to all ICT third-party arrangements with in-scope financial entities, regardless of whether the provider is CTPP-designated. A VDR provider that is not on the CTPP list is still an ICT third-party service provider under DORA, and the contract must meet the Article 30 minimum content from the date DORA entered force.

The third mistake is missing sub-processor chain transparency. Many VDR providers use cloud sub-processors for infrastructure, AI features, or support tooling that are not named in the standard DPA. DORA requires full transparency of the sub-processor chain, including the country where each sub-processor processes data. Financial entities should request the complete sub-processor register and verify that each sub-processor's country of processing is disclosed and consistent with the contract's data location clause.

The fourth mistake is not documenting the ICT third-party register entry for the VDR. The DORA register is an actively inspected document. Regulators are now requesting it as part of supervisory reviews. If the VDR is not listed, or is listed without the required fields (provider name, service description, data location, contract reference, RTO, RPO), the financial entity faces a finding.

The fifth mistake is confusing NIS2 obligations with DORA obligations. NIS2 applies to operators of essential and important services in 18 critical sectors and imposes supply-chain cybersecurity requirements. DORA applies specifically to financial entities and their ICT third-party providers. A financial entity may be subject to both, but the compliance requirements are distinct: NIS2 focuses on cybersecurity risk management and incident reporting, while DORA focuses on operational resilience and contractual minimum content. A VDR contract that satisfies DORA Article 30 does not automatically satisfy NIS2 Article 21, and vice versa.


Frequently Asked Questions

Does DORA apply to my data room provider?

Yes, if you are a financial entity: a bank, insurer, investment firm, payment institution, or crypto-asset service provider regulated under EU law. Your VDR provider is an ICT third-party service provider under DORA. The contract must include the Article 30 minimum clauses covering service levels, audit rights, sub-processor transparency, data location, business continuity, and exit assistance.

What is the CTPP list?

The critical ICT third-party providers (CTPP) list is maintained by the Joint ESA Oversight Network, comprising EBA, EIOPA, and ESMA. Designation triggers direct regulatory oversight by a Lead Overseer, who can conduct investigations and issue recommendations. Financial entities using a CTPP-designated provider face indirect obligations through the pass-through effect of that oversight.

Does my VDR need to be CTPP-designated to be DORA-compliant?

No. CTPP designation is a separate oversight regime that applies to the most systemically important providers. Your VDR contract must satisfy Article 30 DORA regardless of whether the provider is CTPP-designated. Every VDR used by an in-scope financial entity must meet the Article 30 minimum content requirements. Designation adds a layer of direct supervision, not a lower compliance bar.

What audit rights must my VDR contract include?

DORA Article 30 requires the right to audit the provider, either directly or through a designated third-party auditor. The contract must specify that the right is exercisable on reasonable notice and that it extends to the competent authority, not just the financial entity itself. Provisions that limit audit access to an annual schedule or that exclude certain systems should be renegotiated.

Is Papermark on the CTPP list?

Papermark is not a CTPP-designated provider as of July 2026. As an EU-hosted provider with published DPA terms and DORA-aware contracts available on request, it is well positioned for financial entity clients reviewing their DORA posture. For entities requiring zero ICT third-party exposure, Papermark's self-hosted Enterprise tier removes the provider from the ICT outsourcing chain entirely.

What happens if my VDR provider gets CTPP-designated?

You must update your ICT third-party register to record the designation and review your contractual clauses to verify they meet the enhanced requirements that the Lead Overseer may issue. Exit strategy clauses become more operationally important, because DORA requires you to maintain a credible substitution plan for any CTPP-designated provider. The Lead Overseer may also issue recommendations that affect the provider's service terms.