European Banking AuthorityOpen source
New requirements for ICT third-party oversight
Published 10 Jul 2026
What changed
The final standards set out oversight expectations for critical ICT third-party providers and introduce requirements for due diligence, ongoing monitoring, sub-outsourcing transparency and exit strategies.
Why it matters
Firms may need to strengthen supplier classification, contract evidence, monitoring and contingency planning.
RelevanceHighImpactHighUrgencyMedium
Key dates
Entry into force17 Jan 2027
Application17 Jul 2027
Review date17 Jul 2028
How priority is determined
Priority combines the selected lens, visible workspace context, event attributes and the nearest relevant regulatory milestone.