DORA Register of Information: What to Report, Template by Template
Every financial entity within DORA must keep a register of information covering all its contracts for ICT services with third-party providers, in the format set by Commission Implementing Regulation (EU) 2024/2956. Firms on the simplified framework are not exempt, and subcontractors need only be reported where they effectively underpin ICT services supporting critical or important functions. For UK readers, the register matters in two ways: your EU-authorised entities must file one, and if you supply ICT services to EU financial firms, your details will sit in theirs.
Why a UK organisation should care
DORA (Regulation (EU) 2022/2554) is EU law, applicable since 17 January 2025, and does not form part of UK law. It binds the financial entities listed in its Article 2(1). For a UK group, that means its EU-authorised banks, investment firms, payment institutions, insurers and so on. The sources in the DORA knowledge base are EU and ESAs texts only; they say nothing about UK requirements, and neither does this article.
A UK-incorporated technology company is, from the EU's perspective, an "ICT third-party service provider established in a third country" within Article 3(24) of DORA once it contracts with a financial entity. It will not file a register itself (the ESAs' FAQ is explicit that "the obligation of filling the RoI is for financial entities not ICT third-party service providers"), but its EU clients will need its identifiers, its supply chain and its parent company details to complete theirs.
The legal basis in three sentences
- Article 28(3) DORA: maintain and update a register of all ICT third-party contractual arrangements, at entity, sub-consolidated and consolidated level, distinguishing those supporting critical or important functions.
- Same article: report at least yearly on new arrangements, make the register available on request, and inform the authority in good time of planned arrangements for critical or important functions.
- ITS 2024/2956: use the templates in Annexes I to IV, apply six data-quality principles (accuracy, completeness, consistency, integrity, uniformity, validity) and correct errors promptly.
No small-firm exemption applies. The ESAs' answer to Q&A 2025_7388 says Article 28(3) applies "with no exception", including to firms under the Article 16(1) simplified ICT risk management framework, and that proportionality is already embedded in the register requirements.
Template by template
What each part of the register records
| Templates | Content |
|---|---|
| B_01.01, B_01.02, B_01.03 | Who maintains the register; which entities are in the consolidation; branches outside the home country |
| B_02.01, B_02.02, B_02.03 | Each contract with a direct ICT provider (with a unique reference number), its services and supported functions, notice period, governing law; links to intra-group arrangements |
| B_03.01, B_03.02, B_03.03 | Signatories on both sides of each contract |
| B_04.01 | Which entities actually use each service |
| B_05.01, B_05.02 | All providers (direct, intra-group, relevant subcontractors, ultimate parents) and the ranked supply chain |
| B_06.01 | Functions, with one identifier for each combination of LEI, licensed activity and function |
| B_07.01 | Risk assessment of services supporting critical or important functions, such as substitutability and date of last audit |
| B_99.01 | The firm's own definitions of the closed-list values it uses |
Service types are coded using the 19 categories of Annex III, S01 to S19, which run from ICT project management to cloud SaaS. Q&A 2025_7309 confirms this typology is how "categories of ICT third-party service providers" should be understood.
Groups headquartered outside the EU
The ESAs' register FAQ (version of 14 February 2025) answers the question most UK parents ask. An EU financial entity that belongs to a third-country group and has no parent undertaking in the EU reports its register on an individual basis; template B_01.02 then contains only that entity. Sister companies elsewhere in the group are not reported as consolidated entities, but if one of them, such as a UK group technology company, provides ICT services to the EU entity, it must be reported as an intra-group service provider in template B_05.01.
Intra-group chains
Where an intra-group provider relies on outside subcontractors, the FAQ says the register must show at least the first extra-group subcontractor, even if the service does not support a critical or important function. A UK shared-services company that runs EU systems on a hyperscale cloud would therefore bring that cloud provider into the EU entity's register.
Subcontractors: who goes in
Article 2 of the ITS ranks each provider in the supply chain: the direct provider is always rank 1, subcontractors always above 1, with no theoretical ceiling. Article 3(2)(b) limits subcontractor reporting to those that effectively underpin ICT services supporting critical or important functions or material parts thereof. The FAQ clarifies that this includes every subcontractor whose disruption would impair the security or continuity of the service, assessed with business continuity, ICT service continuity and ICT security in mind.
Two boundary cases from the Q&A. First, if your direct supplier does not provide an ICT service at all, the arrangement and the supplier's own ICT subcontractors fall outside the register (Q&A 2024_7089), unless your risk assessment shows the subcontracted ICT service is effectively equivalent to one provided to you directly for a critical or important function. Second, fibre, including dark fibre, is an ICT service and does not benefit from the analogue telephone exclusion (Q&A 2025_7539).
Identifiers, parents and third-country points
- LEI or EUID: Article 3(5) of the ITS requires a valid, active LEI or EUID (both where available) for providers that are legal persons. The FAQ notes that providers registered in third countries can only be identified by LEI, so a UK supplier without one should expect to be asked to obtain it.
- Missing LEI: identifiers are key values and cannot be blank, or the whole file fails. Using another available identifier avoids rejection but is flagged as a data-quality issue.
- Subcontractor identifiers: for services supporting critical or important functions, the financial entity must ensure through the direct provider that relevant subcontractors supply an LEI or EUID (Article 3(6)).
- Headquarters and data location: the register records the country of the provider's global operating headquarters and the countries where data is stored and processed, as ISO 3166-1 alpha-2 codes.
- Third-country risk: for critical or important functions supplied from a third country, Article 29(2) DORA asks financial entities to consider insolvency law, compliance with Union data protection rules and the effective enforcement of the law in that country.
Submitting the register
Registers go first to the national competent authority, which passes them to the ESAs. Per the FAQ, competent authorities reported to the ESAs by 30 April 2025 for the first cycle (reference date 31 March 2025); from 2026 the deadline is 31 March each year, with a reference date of 31 December of the previous year. Each competent authority sets an earlier deadline for its firms. The format is plain-csv, in .csv and .zip files. The register may be reported in a language other than English, provided one consistent language is used across all entities in the same register.
To check a template field or an edge case, ask the DORA knowledge base directly, for example: "We use the simplified ICT risk management framework under Article 16. Do we still have to keep a register of our ICT third-party contracts?"
Search the register rules in seconds
The DORA base brings together ITS 2024/2956, the ESAs' register FAQ and the joint Q&A, with each answer citing its source.
This is guidance on the rules, not legal advice; the ESAs describe their FAQ as best-efforts staff answers rather than legal interpretation. Official text: ITS 2024/2956 on EUR-Lex.
Frequently asked questions
Does a UK ICT provider have to file a DORA register of information?
No. The ESAs' FAQ states that the obligation to fill in the register lies with financial entities, not ICT third-party service providers. EU clients will, however, need the provider's LEI, supply chain and parent details.
How does an EU subsidiary of a UK group report its register?
If it has no parent undertaking in the EU, it reports on an individual basis with only itself in template B_01.02, according to the ESAs' FAQ. Group companies that provide it with ICT services are reported as intra-group providers in B_05.01.
Must every subcontractor be listed in the DORA register?
No. Only subcontractors that effectively underpin ICT services supporting critical or important functions, including those whose disruption would impair security or continuity (ITS 2024/2956, Article 3(2)(b), and the ESAs' FAQ).
Can a non-EU provider be identified by something other than an LEI?
The FAQ says third-country legal persons can only be identified by LEI. If no LEI exists, another identifier can be used to avoid rejection, but it is flagged as a data-quality issue.
Is the simplified framework an exemption from the register?
No. Q&A 2025_7388 confirms Article 28(3) applies with no exception, including to firms under Article 16(1).
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.