Critical ICT third-party provider
Cloud, hosting or ICT service provider designated as “critical” by the European Supervisory Authorities.
Your obligations
- 1
Direct oversight by a European authority designated as Lead Overseer (Art. 31-44).
Being designated a critical provider triggers an in-depth review conducted by one of the three European Supervisory Authorities (EBA, ESMA or EIOPA).
- 2
Access to the information, systems and premises needed for the oversight review.
The provider must fully cooperate with the Joint Examination Teams set up by the Lead Overseer.
- 3
Implementation of the recommendations issued by the Lead Overseer.
These recommendations may cover security, operational resilience, or the management of the provider's subcontractors.
- 4
Possible daily penalty payments for non-compliance, of up to 1% of average daily worldwide turnover (Art. 35).
This penalty can be applied for up to six months, until the provider complies with the recommendations issued.