A third-party ICT service provider is an external company that supplies technology services such as cloud hosting, data centre operations, software, or managed infrastructure. Under DORA, these providers matter because their failures, outages, or control gaps can directly affect the resilience of regulated financial organisations.
What a third-party ICT service provider is
A third-party ICT service provider is an external organisation that delivers technology capabilities a regulated business depends on, such as cloud hosting, data centre operations, software delivery, or managed infrastructure. The defining feature is dependence, because the provider sits outside the customer’s direct control while still supporting critical services.
This arrangement is common in modern financial and digital operations, but the security meaning is broader than vendor management. Once a provider can affect availability, integrity, confidentiality, or recoverability, its controls and failures become part of the customer’s risk surface. That is why DORA treats these providers as operationally important rather than merely contractual suppliers.
Why third-party ICT providers matter in resilience and governance
Third-party ICT providers matter because they can become single points of failure, concentration risks, or sources of cascading disruption. A small defect in one provider, such as an outage, misconfiguration, or loss of administrative control, can propagate into many downstream customers at once. For financial entities, that makes provider selection and ongoing oversight a resilience issue, not just a procurement issue.
They also matter because the customer often inherits responsibility for the business impact even when the provider owns the infrastructure. That creates a governance challenge around accountability, service criticality, exit planning, and visibility into sub-contractors and shared dependencies. DORA and related control frameworks push organisations to understand not only who the provider is, but what services are truly essential and how recoverable they are.
Common security and operational failure modes
The main failure modes are availability loss, weak access control, opaque change management, and poor segregation between customers. Third-party ICT providers can also introduce hidden dependency risk when one downstream platform, integration, or identity boundary supports many business services. If monitoring is shallow, a customer may not detect the control gap until service disruption or data exposure has already occurred.
Security exposure often appears through shared administrative pathways, long-lived credentials, weak API controls, or excess privilege in managed environments. The customer may not operate those controls directly, but the customer is still exposed to the consequences when the provider’s authentication, patching, logging, or recovery practices are weak. In practice, this is where outsourcing and cyber risk meet.
How the term is used in DORA and supplier oversight
Under DORA, the concept is tied to ICT risk management, incident resilience, and contractual oversight of critical or important functions. The term covers more than cloud brands or hosting companies, it also includes managed service providers, software providers, and infrastructure operators when their services support regulated operations. That broader scope is why third-party ICT service provider reviews should focus on service criticality, not just vendor reputation.
Organisations typically assess these providers through security assurances, resilience testing, contractual rights, exit arrangements, and ongoing monitoring of performance and control changes. The point is to verify that the provider’s service model matches the business’s tolerance for disruption and control loss. Where a provider is central to core operations, the governance bar should be correspondingly higher.
Risk and Threat Considerations
Third-party ICT service providers can create systemic exposure because one compromise or outage may affect many customers at the same time. The biggest risks are concentration, dependency opacity, and access-path abuse, especially where the provider holds privileged operational access or manages sensitive integrations on the customer’s behalf.
Failure mechanism: A provider outage, insecure remote access path, weak segregation, or compromised administrative credential can interrupt service delivery or expose customer environments and data.
Impact: The result can be downtime, regulatory breach, data exposure, recovery delay, or a cascading failure across multiple dependent services.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | ICT Third-Party Risk Management | DORA directly governs ICT third-party providers and their operational resilience impact. |
| Recommendation — Classify critical providers, test resilience assumptions, and enforce exit and oversight obligations. | ||
| NIST CSF 2.0 | GV.SC-01 — Cyber Supply Chain Risk Management | Third-party ICT providers are a supply-chain and dependency risk to operations. |
| RC.RP-01 — Recovery Plan Execution | Provider failure directly affects restoration and continuity planning. | |
| Recommendation — Map external ICT dependencies and govern supplier risk through the supply-chain risk function. Validate that recovery plans still work when a third-party ICT provider is unavailable. | ||
| CIS Controls v8 | CIS-15 — Service Provider Management | The term is fundamentally about managing external technology providers and their risk. |
| Recommendation — Maintain an inventory of service providers and review their security and resilience obligations. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier relationships govern security expectations for third-party ICT providers. |
| A.5.22 — Monitoring, review and change management of supplier services | Ongoing review is essential when provider changes can alter customer risk. | |
| Recommendation — Set security requirements for suppliers and verify that contracts reflect those obligations. Monitor supplier service changes and revalidate controls when the provider’s service model changes. | ||
Practitioner Guidance
Governance implication: Treat the provider as part of the operating model for any service it materially supports, not as an externality. Ownership should be explicit for service criticality, monitoring, exit planning, and escalation paths, because those responsibilities do not disappear when technology is outsourced.
What to watch for: Pay close attention to shared dependencies, long-lived privileged access, sub-processors, and vague outage commitments. These are the signals that a vendor relationship is drifting from routine procurement into a resilience dependency that needs stronger oversight.
Related resources from NHI Mgmt Group
- Who is accountable when a third-party service provider mishandles personal data under the Colorado Privacy Act?
- Why do third-party sub-processors increase identity and access risk even when they are not the primary service provider?
- How should financial institutions manage third-party service risk when a provider outage or breach affects customer data?
- What breaks when a third-party service provider is breached and employee data is exposed?