DORA doesn't name "fourth parties" directly, but Article 30 requires contracts with ICT providers to state whether subcontracting of a critical function is permitted and under what conditions. Article 29 also covers concentration risk, which is exactly where fourth-party exposure tends to build up.
FAQ
Fourth-Party Risk