Amazon Web Services (AWS) has been officially designated as a critical third-party provider (CTPP) by the European Supervisory Authorities under the European Union’s Digital Operational Resilience Act (DORA). This designation means AWS will be subject to direct joint oversight by the European Banking Authority, the European Securities and Markets Authority, and the European Insurance and Occupational Pensions Authority, reflecting AWS’s significant role in supporting the operational resilience of the EU financial sector. Financial institutions using AWS must now consider this regulatory oversight as part of their compliance and risk management strategies, leveraging AWS’s security and resilience features while maintaining their own compliance responsibilities.
The broader regulatory landscape in 2025 is increasingly interconnected, with DORA, GDPR, and DMARC forming a complex web of compliance obligations for organizations operating in the EU. Businesses must address overlapping requirements for data protection, operational resilience, and email security, especially when using cloud services like AWS. The integration of these frameworks underscores the need for a unified approach to digital accountability, ensuring protection of data, infrastructure, and identity across all digital operations.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
A compliance-focused industry article discussed DORA alongside DMARC and GDPR, reflecting ongoing business attention to meeting DORA-related regulatory obligations in 2025. This is commentary on the regulatory landscape rather than a new enforcement action.
AWS was designated a critical third-party provider under the EU Digital Operational Resilience Act (DORA), bringing it under the regulation's oversight framework for financial-sector ICT providers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.