DEEN
Regulation

DORA register of information: content and submission

The DORA register of information: record contracts, identifiers and supply chains using the EU templates and BaFin requirements.

First version: Updated: Reading time: about 11 minutes

Symbolic image for the DORA register of information: Two compliance professionals reviewing a tabular register on a laptop, with an EU flag beside them

The DORA register of information records contractual arrangements for ICT services. It must be kept current. Submission of the full register and annual information under Article 28(3) are distinct from ongoing maintenance; BaFin submissions also follow its specific procedural requirements.

What is the DORA register of information?

The DORA register of information is a register of all contractual arrangements on the use of ICT services provided by ICT third-party service providers; it must be maintained and updated under Art. 28(3) DORA. The register of information is maintained at entity level as well as at sub-consolidated and consolidated levels, distinguishing between arrangements that support critical or important functions (CIF) and those without a CIF link. The overall system is explained in the DORA Regulation overview. The wording of the register obligation:

“As part of their ICT risk management framework, financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers.”
Art. 28(3) first subparagraph DORA, Regulation (EU) 2022/2554; official text on EUR-Lex

The register must be maintained and updated continuously. Article 28(3) DORA distinguishes this from annual information on new arrangements and from providing the register when requested by the supervisor. A BaFin submission follows the applicable collection request and format instructions. Regulation (EU) 2022/2554, DORA BaFin: Informationsregister und Anzeigepflichten

Which deadline applies: When must the register of information be submitted?

The next submission deadline follows BaFin’s current request. Changes to contracts and provider data should be recorded in the maintained register meanwhile; an expected year does not establish a supervisory deadline. BaFin: Informationsregister und Anzeigepflichten

“Financial entities shall report at least yearly to the competent authorities on the number of new arrangements on the use of ICT services, the categories of ICT third-party service providers, the type of contractual arrangements and the ICT services and functions which are being provided.”
Art. 28(3) third subparagraph DORA, Regulation (EU) 2022/2554; official text on EUR-Lex

The register must be maintained and updated continuously. Article 28(3) DORA distinguishes this from annual information on new arrangements and from providing the register when requested by the supervisor. A BaFin submission follows the applicable collection request and format instructions. Regulation (EU) 2022/2554, DORA BaFin: Informationsregister und Anzeigepflichten

Distinguish maintenance from submission
TaskRequirement
Ongoing maintenanceKeep contracts and required provider data current
Annual informationProvide the information required by Article 28(3) DORA
Full submissionFollow BaFin’s request, reference date and format

What goes into the register of information? (Content & mandatory fields)

The register of information covers all contractual arrangements on ICT services provided by ICT third-party service providers, distinguished by CIF link (Art. 28(3) DORA). The annual report to the authority comprises at least the number of new arrangements, the categories of ICT third-party service providers, the type of arrangements and the ICT services and functions provided (Art. 28(3) third subparagraph DORA).

For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. The supply chain must record the providers and ranks required by the templates. For ICT services supporting critical or important functions, the relevant subcontracting chain must be identified. A complete procurement directory and the supervisory register’s required chain are different datasets. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956

Which template applies: BaFin Excel or xBRL?

Submission must use the technical format and current template version required by BaFin. A self-designed Excel workbook does not meet those requirements merely because BaFin provides an Excel template for a collection. BaFin: Ausfüllhinweise für die RoI-Excel-Vorlage BaFin: Informationsregister und Anzeigepflichten

The 15 templates describe relationships between entities, contracts and services. Identifiers must agree across templates. DORA does not prescribe a particular software product for this task. Implementing Regulation (EU) 2024/2956, register templates

How does submission via the BaFin portal MVP work?

Submission follows BaFin’s collection request and the access procedures it specifies. Technical access and completeness of the register are prepared separately. Submission feedback must be traceable to the version sent. BaFin: Informationsregister und Anzeigepflichten

  1. 01Identify the collection request

    Use the reference date and submission window in the applicable BaFin request.

  2. 02Prepare the register state

    Produce the required contract and provider data state reproducibly.

  3. 03Validate data and format

    Submission must use the technical format and current template version required by BaFin. A self-designed Excel workbook does not meet those requirements merely because BaFin provides an Excel template for a collection.

  4. 04Retain submission evidence

    Retain transmission evidence and supervisory feedback with the submitted data version.

Which 15 templates does the register of information contain (B_01.01 to B_99.01)?

Implementing Regulation (EU) 2024/2956 contains 15 standard templates. The following table maps their codes to their purpose. Field definitions and identifiers follow the current instructions, including the September 2025 corrigendum. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956

The 15 ITS templates of the register of information
Template codeTemplatePurpose
B_01.01Entity maintaining the registerIdentifies the financial entity maintaining and updating the register (LEI as a mandatory field)
B_01.02Entities within the scope of consolidationAll entities belonging to the group (without a group: identical to B_01.01)
B_01.03BranchesBranches of the financial entities captured in B_01.02
B_02.01Contracts: general informationAll contracts with direct ICT third-party service providers; one unique contract reference number per contract
B_02.02Contracts: specific informationDetails per contract: ICT services included, functions supported, notice period, governing law
B_02.03Intra-group contractsLinks intra-group and external contracts via the reference numbers in the supply chain
B_03.01Entities signing the contractsEntity signing the contract for the entity making use of the ICT services
B_03.02Signing ICT third-party service providersService providers (from B_05.01) signing the contracts from B_02.01
B_03.03Signing group entitiesGroup entities (from B_01.02) signing contracts for providing services to other group entities
B_04.01Entities making use of the ICT servicesAll entities using the ICT services (financial entities or ICT intra-group service providers)
B_05.01ICT third-party service providersIdentify the required ICT providers and ultimate parent using the applicable identifier.
B_05.02ICT service supply chainIdentifies and ranks the service providers per ICT service (rank 1 = direct service provider, rank 2 = subcontractor, etc.); for CIF services supplemented by Delegated Regulation (EU) 2025/532
B_06.01Function identificationUnique function identifier per combination of LEI, licensed activity and function; CIF classification
B_07.01Assessments of the ICT servicesIncluding substitutability and the last audit for services supporting critical or important functions
B_99.01DefinitionsExplanation of the closed option lists used (e.g. “low/medium/high”)

What should a register-of-information tool demonstrate?

A vendor discussion becomes more useful when it follows one complete register case. The matrix translates the register tasks described in this article into testable questions. It is a T-NEX tool-selection aid, not an official submission format.

Requirements matrix for tool selection
Review areaQuestion for the supplierUseful demonstration evidence
Data modelCan entities, contracts, ICT services, functions and providers be linked unambiguously?One test contract with two services and a shared dependency, without duplicate master records.
Identifiers and relationshipsAre permitted identifiers and references maintained consistently?Deliberately introduce missing, duplicate and unresolved identifiers in a sample dataset.
Data qualityAre required fields, value lists and business inconsistencies explained clearly?An error list identifying field, record, rule version and owner; recheck the correction.
Supply chainCan a provider change be traced to affected contracts and functions?Enter one change and show its impact on the affected register records.
Maintenance and approvalWho can edit, review and freeze a reporting snapshot?Role changes, change history and traceable approval demonstrated in a complete workflow.
Export and versionDoes the export match the submission version actually required?Declared taxonomy/schema version and reproducible export from a recorded data snapshot.
FeedbackHow are validation failures and follow-up questions resolved?Link feedback to a register snapshot, correct it, re-export and retain the earlier version.
Operations and handoverWill data, relationships and evidence remain usable after a supplier change?Complete trial export with a field dictionary, attachments and documented limitations.

Use the same dataset to create a record, change a contract and process an invalid delivery. This reveals whether the tool supports ongoing maintenance as well as producing a table. Successful technical validation does not establish that every contract is included or that its business classification is correct.

The editable template adds priority, supplier response, result, evidence and accountable owner. The institution decides which requirements are mandatory before comparing suppliers.

Legal and professional sources: Verordnung (EU) 2022/2554: DORA, insbesondere Artikel 11, 24 und 28–30; Durchführungsverordnung (EU) 2024/2956: Vorlagen für das Informationsregister.

Download the tool matrix (Markdown)

What must be checked before submitting the register of information?

Before submission, check provider identifiers and relationships between templates. Critical or important function classification must agree with the underlying assessments. Technical validation does not replace that classification. Implementing Regulation (EU) 2024/2956, register templates

  1. 01Provider identifiers

    For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity.

  2. 02CIF classification

    Every contract is distinguished by whether it supports critical or important functions (Art. 28(3) DORA).

  3. 03Supply chain ranks

    The supply chain must record the providers and ranks required by the templates. For ICT services supporting critical or important functions, the relevant subcontracting chain must be identified. A complete procurement directory and the supervisory register’s required chain are different datasets.

  4. 04Contract reference numbers

    Every arrangement carries a unique reference number, consistent across all template boundaries (Implementing Regulation (EU) 2024/2956, Annex I).

  5. 05Format validation

    Country codes (ISO 3166-1 alpha-2), date formats (ISO 8601) and closed option lists are checked; the xBRL taxonomy version is reconciled against the current BaFin/ESA requirements.

What do supervisors do with the data from the register of information?

The ESAs (EBA, ESMA, EIOPA) use the submitted register data as the basis for designating critical ICT third-party service providers (CTPPs) under Art. 31 DORA: on 18 November 2025 they designated 19 CTPPs for the first time (ESAs press release of 18 November 2025). The classification draws in particular on the ranked supply chain and the service provider identification from templates B_05.01/B_05.02. Practical note: Comparing your own list of service providers against the 19 designated CTPPs shows which of your providers fall under the European oversight framework (Art. 31–44 DORA); this does not change your own register obligations but is relevant for risk assessment and board reporting.

The European Supervisory Authorities reported 3,383 major ICT-related incidents under DORA for 2025. Around one third involved third-party providers. These figures come from their first annual report, published on 3 June 2026. ESAs: first DORA report on major ICT-related incidents

Register of information vs. outsourcing register: what is the difference?

The outsourcing register under section 25b(1), fourth sentence, KWG covers material and non-material outsourcing. The DORA register of information covers contractual arrangements for ICT services. A service may fall within both scopes. The ninth MaRisk amendment limits the scope of AT 9; it does not create a blanket exemption from the statutory register obligation. Section 25b KWG therefore requires a separate assessment. The explanatory note on AT 9 paragraph 1 states:

“Outsourced or externally procured ICT services within the meaning of Art. 3 No. 21 DORA that are subject to ICT third-party risk management under Art. 28-30 DORA do not fall within the scope of AT 9.”
Explanatory note on AT 9 para. 1, MaRisk Circular 06/2026 (BA) of 30 June 2026, unofficial translation; BaFin download page

The ninth MaRisk amendment has applied since 30 June 2026. The transition until 1 January 2027 applies only where additional requirements arise in an individual case. The exception in MaRisk AT 9 covers ICT services under Article 3(21) DORA that are subject to ICT third-party risk management under Articles 28 to 30. Other components of mixed services require separate classification. BaFin: Rundschreiben 06/2026 (BA), MaRisk

Does the register obligation also apply to small institutions?

For a small institution covered by DORA, size alone does not remove the register duty. The first step is to assess scope, including the exclusions in Article 2. Article 28 covers the relevant ICT contracts regardless of whether they support critical or important functions. Regulation (EU) 2022/2554, DORA

FAQ

Frequently asked questions about the DORA register of information

Do subcontractors have to be listed individually in the DORA register of information?

The supply chain must record the providers and ranks required by the templates. For ICT services supporting critical or important functions, the relevant subcontracting chain must be identified. A complete procurement directory and the supervisory register’s required chain are different datasets.

Who must maintain the register of information (including groups and branches)?

Financial entities within the scope of DORA maintain the register of information under Art. 28(3) DORA at entity level as well as at sub-consolidated and consolidated levels. Groups therefore map the register across the scope of consolidation; among other things, the ITS templates capture the scope of consolidation (B_01.02), branches (B_01.03) and intra-group contracts (B_02.03).

What happens if the submission deadline for the register of information was missed?

The register obligation continues to apply regardless of the submission window: under Art. 28(3) DORA the register of information must be maintained on an ongoing basis and made available to the supervisor upon request at any time, in full or in part. Breaches can trigger supervisory measures; DORA contains its own supervisory and sanction provisions for this. An officially regulated grace period is not documented in our sources; BaFin's requirements are authoritative.

When is the next submission of the DORA register of information due?

The next submission deadline follows BaFin’s current request. Changes to contracts and provider data should be recorded in the maintained register meanwhile; an expected year does not establish a supervisory deadline.

In which format is the register of information submitted to BaFin?

Submission must use the technical format and current template version required by BaFin. A self-designed Excel workbook does not meet those requirements merely because BaFin provides an Excel template for a collection.

Does the register obligation also apply to small institutions?

For a small institution covered by DORA, size alone does not remove the register duty. The first step is to assess scope, including the exclusions in Article 2. Article 28 covers the relevant ICT contracts regardless of whether they support critical or important functions. Regulation (EU) 2022/2554, DORA

An offer from T-NEX GmbH

Discuss the project with T-NEX

Register maintenance starts with a data model and clear ownership. T-NEX supports business design and, where needed, develops appropriate interfaces or workflows. This article does not promise a standalone submission-ready register product.

Management: Andreas Unruh and Christoph Gembruch.

Published by T-NEX GmbH.