Guide

DORA Register of Information: A Step-by-Step Guide to What You Must Report

The Kopik team8 min read

The DORA register of information (RoI) is the inventory every EU financial entity must keep of all its contractual arrangements for ICT services from third-party providers, under Article 28(3) of Regulation (EU) 2022/2554. It follows the templates of Commission Implementing Regulation (EU) 2024/2956, applies even to firms on the simplified framework, and must list subcontractors only where they effectively underpin ICT services supporting critical or important functions. This guide walks through the build, template by template, with the points that matter most for US groups and US-based providers.

Who has to keep a register, and at what level

Article 28(3) requires financial entities to "maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers." The register must distinguish arrangements covering ICT services that support critical or important functions from those that do not.

There is no small-firm carve-out. In Q&A 2025_7388, the ESAs confirmed that entities under the Article 16(1) simplified ICT risk framework, although exempt from Articles 5 to 15, still must keep a register: Article 28(3) applies "with no exception" and "all financial entities that are subject to DORA are required to maintain a register of information." Proportionality is built into the register requirements themselves.

US-headquartered groups

The ESAs' register FAQ (version of 14 February 2025) addresses a common US situation: if an EU financial entity belongs to a third-country group and has no parent undertaking in the EU, it reports the register on an individual basis, and template B_01.02 contains only that entity. Other group entities that are not its subsidiaries are not reported as such, but if they provide ICT services to it, they are reported as intra-group service providers in template B_05.01.

Where an EU parent does exist, Q&A 2024_7098 says the sub-consolidated and consolidated registers should reflect all financial entities and branches within the consolidation scope under Directive 2013/34/EU and the relevant sectoral legislation, and Article 6 of the ITS adds that they include all financial entities and ICT intra-group service providers in the group.

Step 1: Decide what counts as an ICT service

DORA Article 3(21) defines ICT services broadly: digital and data services provided through ICT systems on an ongoing basis, including hardware as a service, excluding only traditional analogue telephone services. The ESAs' Q&A narrows the gray zones:

  • Fiber and dark fiber are in. Q&A 2025_7539 says the analogue-telephone exclusion cannot be extended to fiber optic networks, including dark fiber.
  • Payment processors and payment infrastructures are ICT third-party service providers for their services that meet the Article 3(21) definition, though business processes without a prevailing ICT component, such as clearing and settlement, are not ICT services (Q&A 2024_7290).
  • Public authorities acting in the context of State functions are essentially out of scope as ICT providers (Q&A 2025_7466).
  • Non-ICT providers fall outside the register, and so do their own ICT subcontractors (Q&A 2024_7089), unless your risk assessment shows the subcontracted ICT service is effectively equivalent to one provided to you directly for a critical or important function.

Step 2: Map the templates

Article 3 of ITS 2024/2956 requires you to use the templates in Annexes I to IV. Article 5 lists their content:

Register of information templates (ITS 2024/2956, Annex I)

TemplateWhat it captures
B_01.01-B_01.03The entity maintaining the register, the entities in the consolidation, and branches outside the home country
B_02.01-B_02.03Contractual arrangements: general information, specific information (services, functions supported, notice period, governing law), and intra-group links
B_03.01-B_03.03Who signs the contracts, on both the receiving and providing sides
B_04.01Entities making use of the ICT services
B_05.01-B_05.02ICT third-party providers (direct, intra-group, subcontractors and their ultimate parents) and the ICT service supply chain
B_06.01Functions identification, with one identifier per LEI, licensed activity and function
B_07.01Assessment of ICT services supporting critical or important functions (e.g. substitutability, date of last audit)
B_99.01Your internal definitions of the closed-list indicators you use

Each template is a table with fixed columns and as many rows as needed; each data element takes a single value, and a second valid value means a second row (Article 4). Service types must be coded with the 19 identifiers in Annex III, from S01 (ICT project management) to S19 (Cloud services: SaaS).

Step 3: Rank the supply chain and pick the subcontractors

Article 2 of the ITS sets the ranking rule: the direct ICT third-party provider is always rank 1; subcontractors are always higher than 1. The ITS gives an example: provider X delivers services A and B, and uses subcontractor Y for service B. Service A's chain is X (rank 1); service B's chain is X (rank 1) then Y (rank 2).

You do not list every subcontractor. Article 3(2)(b) of the ITS requires information on "all subcontractors that effectively underpin ICT services supporting critical or important functions or material parts thereof." The ESAs' FAQ adds that this includes all subcontractors whose disruption would impair the security or continuity of the service, and that you should consider business and ICT service continuity and ICT security when identifying them. One exception: where an intra-group provider uses subcontractors, report at least the first extra-group subcontractor, even if the service does not support a critical or important function. There is no theoretical limit to the rank.

Step 4: Identify every provider correctly

Article 3(5) of the ITS requires a valid and active LEI or the EUID (European Unique Identifier), and both where available, for every ICT provider that is a legal person. For subcontractors underpinning critical or important functions, you must obtain these identifiers through the direct provider (Article 3(6)).

  • US and other non-EU providers: the FAQ notes that for legal persons registered in third countries, only the LEI can be used.
  • No LEI available? Key values cannot be left empty or the whole file is rejected. The FAQ says to populate the field with another available identifier; it will be flagged as a data quality issue but the file will not be rejected.
  • Ultimate parents: template B_05.01 also lists the ultimate parent undertaking of each provider. The FAQ confirms that all ICT providers are listed there with their ultimate parent information, which is how, for example, the US parent of an EU-based provider appears in the register.
  • Headquarters country: use the ISO 3166-1 alpha-2 code of the provider's global operating headquarters, usually its country of tax residence.

Step 5: Report on time and in the right format

Reporting is sequential: entities send the register to their competent authority, which forwards it to the ESAs. According to the FAQ (14 February 2025 version), competent authorities had to report registers to the ESAs by 30 April 2025, with a reference date of 31 March 2025; from 2026, the deadline is 31 March each year, with a reference date of 31 December of the preceding year. Competent authorities set their own, earlier deadlines for financial entities, so check with yours. Files go in plain-csv format, packaged as .csv and .zip files, per the ESAs' technical specifications; the ESAs do not prescribe how you keep the register internally, so Excel or a dedicated system both work.

That yearly submission generally also fulfils the Article 28(3) duty to report new arrangements annually, according to Q&A 2025_7309. Two further duties remain: make the register available on request, and inform the authority in a timely manner of planned arrangements for critical or important functions, or when a function becomes critical or important.

Common mistakes

  1. Assuming the simplified framework exempts you from the register.
  2. Listing the whole supply chain instead of the subcontractors that effectively underpin critical or important functions, or missing those whose failure would impair security or continuity.
  3. Leaving LEI fields blank for US providers, which gets the file rejected.
  4. Forgetting the ultimate parent undertaking of each provider.
  5. Treating fiber connectivity as excluded "telephone" service.

When a specific field or edge case comes up, the fastest route is to ask the DORA knowledge base, which indexes the ITS, the full FAQ and the Q&A. A typical question: "Do we have to list every single subcontractor in our ICT provider's supply chain in the DORA register of information?"

Answer register questions with citations

Search ITS 2024/2956, the ESAs' register FAQ and the DORA Q&A in plain English. Every answer links back to its source passage.

This guide is informational, not legal advice. The ESAs state that their FAQ answers are given on a best-efforts basis and are not a legal interpretation. Official text: ITS 2024/2956 on EUR-Lex.

Frequently asked questions

What is the DORA register of information?

It is the register, required by Article 28(3) of DORA, of all contractual arrangements for ICT services provided by ICT third-party service providers, kept at entity, sub-consolidated and consolidated levels using the templates of ITS 2024/2956.

Do small firms under Article 16 need a register of information?

Yes. ESAs Q&A 2025_7388 states that Article 28(3) applies with no exception and that all financial entities subject to DORA must maintain a register of information.

Which subcontractors must be reported in the register?

Only those that effectively underpin ICT services supporting critical or important functions or material parts thereof, including those whose disruption would impair security or continuity, plus at least the first extra-group subcontractor of an intra-group provider.

What identifier should we use for a US ICT provider?

The LEI. The ESAs' FAQ explains that legal persons registered outside the EU can only be identified by LEI. If none exists, use another available identifier so the file is not rejected; it will be flagged as a data quality issue.

When is the register of information due?

From 2026, competent authorities report registers to the ESAs by 31 March each year, with a 31 December reference date, according to the ESAs' FAQ. Your competent authority sets an earlier deadline for you.

Does the annual register replace the Article 28(3) annual report on new arrangements?

Generally yes, according to Q&A 2025_7309: the yearly register submission fulfils that requirement, and no second specific communication is needed.

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.