From outsourcing to infrastructure: Comparing DORA to the UK’s Critical Third Party Regime
EU RegCORE Client Alert | EU Digital Single Market, financial services and crypto-assets
As financial institutions continue to operationalise the EU’s Digital Operational Resilience Act (DORA), attention is increasingly turning to the United Kingdom’s Critical Third Party (CTP) regime, with new CTP designations published 13 July 2026. Although both frameworks seek to strengthen operational resilience by introducing direct oversight of systemically important technology providers, they differ in their legal architecture, supervisory philosophy and implementation.
Those differences matter for firms operating across both jurisdictions. Yet they also reveal something more fundamental. Both regimes reflect a broader shift in financial regulation: the expansion of the reg-ulatory perimeter beyond regulated financial institutions to encompass the digital infrastructure upon which modern finance depends.
For internationally active firms and critical technology providers alike, understanding where the regimes converge - and where they diverge – will become increasingly important.
Read the full article
Download