Critical or important function test
There is no official list. The Commission has confirmed that neither it nor the ESAs publish one, so every financial entity self-assesses against the three limbs of Article 3(22) — and has to be able to defend the answer. This works through all three and builds the reasoning trail as you go.
DORA Art. 3(22) · 3 limbs · any one triggers · reasoning shown · nothing stored
Assess one function
Runs in your browser · nothing uploadedAssess a function, not a supplier. One provider may support several functions at different criticality levels. Answer against a realistic worst-case disruption, and mark anything you would have to model as Unsure.
Limb A — Material impairment of financial performance
Article 3(22), first limb“a function, the disruption of which would materially impair the financial performance of a financial entity”
Limb B — Material impairment of soundness or continuity of services and activities
Article 3(22), second limb“or the soundness or continuity of its services and activities”
Limb C — Material impairment of continuing regulatory compliance
Article 3(22), third limb“or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law”
Every CIF determination has to be recorded against a contract. The DORA module keeps the Register of Information, carries the critical-or-important flag through to the templates, resolves the LEI chain and validates before export — with free record keeping to start.
Create free account →One flag, four downstream regimes
Misclassify a function and you mis-scope everything that hangs off it. This is the determination most worth getting right first.
Six extra clauses
Article 30(3) adds full performance targets, material-impact reporting, contingency testing, TLPT participation, unrestricted audit rights and an exit strategy — on top of the nine every contract needs.
A flag in every row
Each arrangement in your Register of Information carries whether it supports a critical or important function. That flag drives how the arrangement is reported and how closely it is examined.
Continuity, testing, concentration
Recovery objectives, business continuity planning, concentration risk assessment under Article 29 and the scope of threat-led penetration testing all follow the CIF determination.
Rules reviewed 21 August 2026 · Regulation (EU) 2022/2554 Art. 3(22), Recital 70 · European Commission Q&A on the absence of an official list
What this test does
It structures a judgement. It does not make one, and any tool claiming otherwise is overselling a principles-based definition.
It doesStructure the three limbs
- Tests all three limbs of Article 3(22) separately, since any one is sufficient.
- Shows which limb was triggered and by which answers.
- Separates a clear determination from one resting on unresolved questions.
- Sets out the downstream obligations that follow from a positive determination.
- Builds a written rationale you can use as the starting point for your own record.
- Flags the common confusion between a CIF and a designated critical ICT third-party provider.
It does notMake the determination for you
- Define what is material for your firm — that turns on your size, risk profile and business model under Article 4.
- Perform a business impact analysis or set recovery time objectives.
- Apply any sector-specific supervisory expectation your authority has published.
- Assess concentration risk under Article 29, or map subcontracting chains.
- Substitute for the documented methodology your supervisor will ask to see.
- Constitute legal or regulatory advice.
Determined it is critical or important?
Then the contract needs the six additional Article 30(3) clauses on top of the nine every ICT arrangement requires. The clause checker works through all fifteen.
Nothing you enter here leaves your browser
Your answers, and the function name if you enter one, are held in the page and discarded when you close or reload it. Nothing is sent to REGREP, written to a log, saved, or passed to any analytics tool.
Criticality assessments name internal systems and expose where a firm is fragile. We would rather not be able to see them.
About critical or important functions
Is there an official list of critical or important functions?
No. The European Commission has confirmed that neither it nor the European Supervisory Authorities publish a list, and that each financial entity must assess against the definition in Article 3(22). The definition is principles-based by design, so the assessment is yours to make and to justify.
How many limbs are there, and do I need to satisfy all of them?
Three, and no. A function is critical or important if its disruption would materially impair financial performance, or the soundness or continuity of services and activities, or if discontinued, defective or failed performance would materially impair continuing compliance with authorisation conditions or other obligations under financial services law. Any one limb is sufficient.
Is this the same as a critical function under the BRRD?
Related but broader. Recital 70 confirms the DORA definition includes the concept of critical functions from other Union legislation such as the BRRD, but DORA applies a wider operational risk lens and is not confined to resolution planning. A function critical for resolution purposes will generally be critical under DORA; the reverse does not follow.
Is it the same as the Solvency II concept for insurers?
Not necessarily. The Commission has confirmed that for DORA purposes the assessment must be made against Article 3(22), and that definitions in other sectoral legislation may differ in scope. An existing Solvency II inventory is a useful input, not an answer.
What is the difference between a CIF and a critical ICT third-party provider?
They are different things at different levels. A critical or important function is an internal classification each financial entity makes about its own functions under Article 3(22). A critical ICT third-party provider is an EU-level designation made by the ESAs under the oversight framework in Article 31, covering a small population of systemically significant providers. Using a designated provider does not make a function critical, and using an undesignated one does not make it ordinary.
What happens if we classify too few functions as critical?
Under-classification is the more dangerous error. It scopes you out of the Article 30(3) contract clauses, out of the stricter treatment in the Register of Information, and out of parts of your resilience testing. Supervisors examine methodology as much as outcome, so a defensible assessment that reaches a narrow conclusion fares better than a narrow conclusion with no method behind it.
Do you store my answers?
No. Everything is held in the page and discarded when you close or reload it. Nothing is logged, stored or sent to analytics.
The determination is yours. The record is the hard part.
Create a free account and keep every arrangement, its criticality flag and its contract in one register — validated and ready to submit.
No card required · free record keeping and validation · nothing stored from this test