Skip to content
NISDESK

What is the DORA register of information for ICT third-party providers?

Under DORA Article 28(3), every financial entity must maintain a register of information covering all contractual arrangements with ICT third-party service providers, distinguishing those that support critical or important functions. It is kept at entity, sub-consolidated and consolidated level and must be made available to the competent authority on request.

Last updated: 2026-09-30

What the register covers

  • ▸Every contractual arrangement for ICT services with a third-party provider
  • ▸Which arrangements support critical or important functions
  • ▸Provider details and the ICT services and functions each contract supports
  • ▸Standard templates set by Commission Implementing Regulation (EU) 2024/2956

Reporting duties

  • ▸Report at least yearly to the competent authority on new ICT arrangements (Article 28(3))
  • ▸Provide the full register when the competent authority requests it
  • ▸Inform the competent authority in good time about planned contracts for critical or important functions

Registers also feed the EU-level designation of critical ICT third-party service providers, which are then overseen by the European Supervisory Authorities.

Depends on national law: Submission dates and technical format for the register are set by your national competent authority.

Related question

Who has to keep a DORA register of information?

All financial entities in DORA scope — including banks, insurers, investment firms, payment and e-money institutions and crypto-asset service providers. ICT providers do not keep the register themselves, but their customers will ask them for the data it needs.

Next steps

For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.