DORA CTPP Third-Party Risk · Indirectly Bringing AWS/Anchorage under Financial Regulation
ConfidenceLikelyUpdated2026-05-26Review by2026-09-22Sources5Machine-translatedOriginal (JA)
Wiki route
This entry sits under fintech index. Read it with Japan Financial Regulation — Legal Framework for Tokens, Crypto Assets, and Payments for adjacent context and Three-Layer Structure of Japan's Stablecoin Regulatory Regime (JPYC, USDC, Project Pax) for the broader system boundary.
[!info] TL;DR The Critical Third-Party Provider (CTPP) mechanism under DORA Art. 28–44 is the EU’s legal tool for “indirectly bringing” cloud / Anchorage / Coinbase Custody and other stablecoin critical infrastructure under supervisory oversight. Every EU stablecoin issuer / CASP / custodian is required to comply with a dual-compliance regime (MiCA + DORA). The first CTPP list in 2026–Q2 is expected to include AWS / Azure / GCP / Anchorage / Coinbase Custody / Chainalysis / TRM Labs / Fireblocks / Circle Europe.
Key facts
- ESAs’ CTPP assessment criteria: systemic importance + dependency + substitutability + identified risks •
- CTPP oversight fee: €500K (medium-scale) to €5M (large-scale cloud) •
- Mandatory establishment of an EU legal entity or EU representative •
- ESAs can compel financial entities to terminate contracts •
- On-site inspections + remote audit rights •
- AWS / Azure / GCP expected to be automatically designated in 2026–Q2 •
- Anchorage / Coinbase Custody / Fireblocks / Chainalysis / TRM Labs on the expected list •
- Circle Europe has a dual status: EMT issuer + potential CTPP •
Mechanism / How it works
ESAs assessment process (DORA Art. 31):
- Quantification of systemic importance + financial entity dependency + substitutability + identified risks
- After entry onto the CTPP list: direct supervision by EBA / ESMA / EIOPA lead overseer
- Mandatory establishment of an EU legal entity or EU representative
- Annual oversight fee €0.5M–€5M
- On-site inspections + remote audit rights
- ESAs can compel financial entities to terminate contracts
Actual impact chain: Circle Europe (MiCA EMT) must simultaneously comply with DORA → its AWS supplier automatically becomes a CTPP → AWS must establish an EU legal entity and submit to ESAs supervision → BUIDL on Solana reaching EU customers → BlackRock Europe + Solana validators are also affected.
Origin & evolution
The CTPP concept traces back to concerns about cloud concentration in European banking during 2018–2021 (AWS accounting for 40%+ of EU financial cloud). EBA 2017 Recommendations on outsourcing to cloud service providers was the initial attempt. DORA’s passage in 2022 elevated CTPP from soft guidance to hard regulation. 2024–07 ESAs Level 2 RTS clarified quantitative criteria. The first “non-financial tech company brought under financial regulation”: AWS / Azure / GCP automatically designated as CTTPs → direct ESAs supervision = reinforcing EU digital sovereignty cloud requirements (Gaia-X / EuroStack) and triggering an onshore data-centre construction boom. Together with EU MiCA CASP (Crypto-Asset Service Provider) regime, this constitutes the EU’s “business + resilience” dual-track crypto-asset supervision.
Related
- Wiki Index
- DORA · EU Digital Operational Resilience Act Overview
- Deep dive into MiCA EMT vs ART sub-classification · Product shaping based on regulatory burden
- OCC trust bank charter
- GENIUS Act §501
Sources
Discovery
Keep reading
Read next
- Dual-currency arbitrage · the §501 legal hack and regulatory fragility1. An individual / company voluntarily exchanges 2 independent 1:1 stablecoins with each other = voluntary asset allocation · no FX license required 2. The DEX provides pool liquidity = auto...
- Dual-currency stablecoin exchange · execution routes and constraints for on-chain FXThe table below is an analytical checklist for transaction steps, not evidence of a single existing pool or fixed costs. It is based on Circle Mint, the supported currencies and chains list...
- Digital euro retail project — current phase, 2027 beta pilot, conditional 2029 readinessThe table reflects the ECB's current project page, progress record, and pilot FAQ, reviewed 2026-07-30.
Links here
- DORA · EU Digital Operational Resilience Act OverviewDORA was proposed as part of the 2020-09 EU Commission Digital Finance Package and was advanced in the same period as MiCA. Adopted 2022-12 , in full force 2025-01 . The ESAs (EBA + ESMA + E...
- EU MiCA Implementation Status, July 2026 · ESMA EMT/ART Registers and Restrictions on Non-Compliant StablecoinsUnder the EU Markets in Crypto-Assets Regulation (MiCA, Regulation (EU) 2023/1114), the EMT / ART provisions began to apply on 2024-06-30, the other principal provisions on 2024-12-30, and t...