When considering the criteria set out in Article 31(2) of Regulation (EU) 2022/2554 to designate an ICT third-party service provider that is critical for financial entities, the ESAs shall apply the following approach:
-
as a first step, the ESAs shall assess whether the ICT third-party service provider fulfils all of the ‘step 1’ sub-criteria set out in Articles 2(1), 3(1), and 5(1);
-
as a second step, for those ICT third-party service providers that fulfil all of the ‘step 1’ sub-criteria referred to in point (a), the ESAs shall carry out their assessment in the light of the ‘step 2’ sub-criteria referred to in Articles 2(5), 3(4), 4(1), and 5(5).