Key Takeaways:
- A diversified vendor estate can still hide shared ICT dependencies further down the supply chain.
- DORA’s Register of Information can extend beyond direct providers to subcontractors supporting critical or important functions.
- Concentration risk becomes more serious when shared dependencies support critical functions and are difficult to replace.
- DORA supervision in 2026 is putting greater emphasis on subcontracting, cloud-provider disruption, and usable dependency data.
- Dependency mapping needs to show how critical functions, ICT services, providers, and lower-tier subcontractors connect over time.
DORA has moved well beyond implementation planning. In 2025, the ECB completed its first collection of Registers of Information from significant institutions and found increased reliance on ICT third parties, concentration among a small number of providers, particularly cloud providers, and low levels of substitutability. The DORA oversight framework for critical ICT third-party providers has since become operational, with 19 providers currently under the EU framework.
That puts a different kind of pressure on third-party risk data in 2026. A financial institution may know who its direct vendors are and still have an incomplete picture of how those services depend on providers further down the chain. Several apparently separate technology relationships can converge on the same underlying infrastructure or subcontractor, creating common points of failure that are difficult to see from the contracted-vendor layer alone.
The following five questions get closer to what firms now need to understand about that exposure.
1. Can a diversified vendor estate still hide concentration risk?
Yes. Separate contracts do not necessarily represent separate operational dependencies.
A bank might use several SaaS providers for different critical functions, while multiple vendors rely on the same cloud platform or another common ICT subcontractor underneath. The direct supplier base can therefore appear broadly distributed even when disruption at one lower-tier provider would affect several services at once.
DORA’s subcontracting rules explicitly require financial entities to consider whether ICT services supporting critical or important functions are concentrated in a single subcontractor or a small number of subcontractors. The ECB’s first analysis of DORA Register of Information data from significant institutions also confirmed concentration among a relatively small number of ICT third-party providers, particularly cloud providers, alongside low substitutability.
Resilience teams need to know which services share underlying dependencies and which critical functions could be affected by the same failure.
2. How far down the ICT supply chain does DORA expect firms to see?
For ICT services supporting critical or important functions, the reporting structure can extend well beyond the company holding the direct contract.
Template B_05.02 of the DORA Register of Information, titled ICT service supply chains, assigns each provider a rank. The direct ICT provider is rank 1. Its subcontractor is rank 2, the next subcontractor rank 3, and the same logic continues further down the chain. Financial entities must include subcontractors that effectively underpin an ICT service supporting a critical or important function where disruption could impair the security or continuity of that service.
Commission Delegated Regulation (EU) 2025/532 reinforces that expectation by requiring firms to consider the length and complexity of subcontracting chains and the concentration of critical ICT services among lower-tier providers. It also makes clear that relying on a provider’s assessment of its own subcontractors does not remove the financial entity’s responsibility.
This is the layer commonly described as fourth-, fifth-, or nth-party risk, although DORA itself uses the language of subcontractors and provider ranks.
Series context: Third-Party Risk Is Now Your Responsibility: Understanding DORA’s Impact in 2025 covers the accountability principle behind this requirement and why outsourced ICT risk remains the financial entity’s responsibility. Read Part 1 of the DORA series.
3. What makes shared dependency a serious concentration risk?
A common provider somewhere in the supply chain does not automatically create the same level of exposure in every case. The effect depends on what sits above that dependency and what options remain if it fails.
DORA’s subcontracting rules direct financial entities to assess whether critical services are concentrated among a small number of subcontractors, while also considering the potential impact of disruption and whether those services can be transferred to another provider. Location, chain complexity, and changes in the functions being supported also form part of the assessment.
Substitutability is particularly important. The ECB’s 2025 Register of Information analysis for significant institutions found low levels of substitutability among ICT third-party providers and difficulties reintegrating outsourced services. Earlier ECB analysis of year-end 2023 outsourcing data found that 82% of critical functions outsourced to external providers were considered difficult or impossible to substitute, while 95% of those were also difficult or impossible to reintegrate.
A shared dependency becomes especially significant when it supports several critical functions and credible alternatives are limited. That combination can turn one provider disruption into a wider operational event.
4. What has changed now that DORA is in supervision rather than preparation?
The supervisory machinery is now using the information firms spent 2025 assembling.
In November 2025, the European Supervisory Authorities designated the first 19 critical ICT third-party providers, using Registers of Information as one input into assessments covering systemic importance, support for critical functions, and substitutability.
The oversight framework has been fully operational since January 2026. The ECB has said that subcontracting and the way critical ICT services are delivered to financial institutions will be areas of attention within that framework. Its 2026–28 supervisory program also includes on-site work on third-party risk management and a deep dive into banks’ preparedness for disruption at a major cloud provider.
DORA’s first annual incident report adds another layer of evidence. Financial entities reported 3,383 major ICT-related incidents during 2025, around one-third of which had cross-border impact. The ESAs linked the findings to interconnected infrastructures and services and highlighted the need for robust third-party risk management and oversight of outsourced services.
For firms, this increases the value of being able to retrieve and interrogate dependency information rather than simply demonstrate that a register exists.
Series context: Where Compliance Meets Capability: AI-Powered Oversight for DORA’s Next Phase looks at the continuous monitoring, traceability, and evidence needed once DORA oversight becomes an ongoing operating requirement. Read Part 2 of the DORA series.
5. What should a useful DORA dependency map show?
A useful dependency map should connect critical business functions to the ICT services supporting them and then trace the providers involved in delivering those services.
That relationship makes it possible to see when several contracts share the same lower-tier provider, where one subcontractor supports multiple critical functions, and which dependencies have limited alternatives. The map should also be able to show the effects of a provider disruption across connected services rather than treating every vendor relationship in isolation.
DORA’s Register of Information already provides much of the structure required to assemble that view. Template B_05.02 links providers within the same ICT service supply chain, identifies their position by rank, and records which provider receives each subcontracted service.
The operational challenge is keeping those relationships current enough to use. Subcontracting arrangements change, services move between providers, and the functions dependent on them evolve. Commission Delegated Regulation 2025/532 requires firms to reassess relevant subcontracting and concentration risks as those arrangements and the conditions around them change.
That turns dependency mapping into an ongoing data and governance capability rather than a one-time documentation exercise.
Concentration risk becomes visible in the connections
DORA requires firms to maintain a much richer record of their ICT supply chains. The value of that information depends on whether an institution can connect the records well enough to see common dependencies across contracts, services, and critical functions.
That work depends on sound data architecture and governance, with dependency information kept close enough to the live technology estate to support digital operational resilience as providers, services, and subcontracting arrangements change.
If your DORA register tells you who your providers are but leaves shared dependencies difficult to see, we can help turn that information into a clearer view of operational concentration and resilience.