Critical third party, a designation, not a description
A critical third party is a provider whose failure would threaten the stability of a whole financial system rather than one firm, and which regulators have therefore designated for direct oversight. In the UK, HM Treasury designates; under DORA, the European Supervisory Authorities do. It is a formal status, not a synonym for an important vendor. Also called CTP, Critical ICT third-party service provider.
Two meanings, and only one of them is regulatory
Internally, most firms call a vendor critical when its failure would stop a business service. That is a tiering judgement, made by you, using your own criteria, and it drives how much diligence the vendor gets.
The regulatory meaning is narrower and is not yours to make. It applies where a provider is systemically important across many firms — the cloud platforms, payment infrastructure and core banking providers a sector concentrates on — and designation brings that provider itself into scope for direct requirements and supervision. In the UK, HM Treasury designates critical third parties and the Bank of England, PRA and FCA set the rules, which took effect at the start of 2025. Under DORA, the ESAs designate critical ICT third-party service providers and one of them acts as Lead Overseer.
What designation changes for you
Less than firms expect. Designation puts obligations on the provider; it does not transfer your own. You remain accountable for the outsourced service, for your exit arrangements, and for the resilience of the business service the provider supports. Supervisors have been consistent that a designated provider is not a provider you may stop managing.
What it does change is what you can rely on. Designated providers face direct oversight and testing, which improves the evidence available to you and reduces the argument about whether a hyperscaler will complete your questionnaire. The obligation to understand your own concentration in that provider is unaffected.
Common questions
Who decides that a third party is critical?
Does a designated critical third party still need assessing?
Is "critical third party" the same as our internal critical tier?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.