The ESAs, through the Joint Committee, designate which ICT third-party service providers are critical, according to systemic impact, the importance of the institutions relying on them, reliance for critical or important functions and substitutability, and publish the list yearly; each designated provider gets a Lead Overseer and must tell the financial entities it serves of its designation. Designation does not cover financial entities that supply ICT services to other financial entities, providers under oversight supporting Article 127(2) TFEU tasks, intra-group providers, or providers serving only entities active in a single Member State (Art. 31(8)). For financial entities the duty is to track which of their providers are designated and reflect it in third-party risk management; a designated provider established in a third country may be used only if it has set up a Union subsidiary within 12 months of designation (Art. 31(12)).
This control maps to 11 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
DORA DORA-Art.31 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.
The graph holds this control, the 11 it maps to, and the evidence behind each claim, over MCP and REST.