The DORA register of information records contractual arrangements for ICT services. It must be kept current. Submission of the full register and annual information under Article 28(3) are distinct from ongoing maintenance; BaFin submissions also follow its specific procedural requirements.
What is the DORA register of information?
The DORA register of information is a register of all contractual arrangements on the use of ICT services provided by ICT third-party service providers; it must be maintained and updated under Art. 28(3) DORA. The register of information is maintained at entity level as well as at sub-consolidated and consolidated levels, distinguishing between arrangements that support critical or important functions (CIF) and those without a CIF link. The overall system is explained in the DORA Regulation overview. The wording of the register obligation:
“As part of their ICT risk management framework, financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers.”
The register must be maintained and updated continuously. Article 28(3) DORA distinguishes this from annual information on new arrangements and from providing the register when requested by the supervisor. A BaFin submission follows the applicable collection request and format instructions. Regulation (EU) 2022/2554, DORA BaFin: Informationsregister und Anzeigepflichten
Which deadline applies: When must the register of information be submitted?
The next submission deadline follows BaFin’s current request. Changes to contracts and provider data should be recorded in the maintained register meanwhile; an expected year does not establish a supervisory deadline. BaFin: Informationsregister und Anzeigepflichten
“Financial entities shall report at least yearly to the competent authorities on the number of new arrangements on the use of ICT services, the categories of ICT third-party service providers, the type of contractual arrangements and the ICT services and functions which are being provided.”
The register must be maintained and updated continuously. Article 28(3) DORA distinguishes this from annual information on new arrangements and from providing the register when requested by the supervisor. A BaFin submission follows the applicable collection request and format instructions. Regulation (EU) 2022/2554, DORA BaFin: Informationsregister und Anzeigepflichten
| Task | Requirement |
|---|---|
| Ongoing maintenance | Keep contracts and required provider data current |
| Annual information | Provide the information required by Article 28(3) DORA |
| Full submission | Follow BaFin’s request, reference date and format |
What goes into the register of information? (Content & mandatory fields)
The register of information covers all contractual arrangements on ICT services provided by ICT third-party service providers, distinguished by CIF link (Art. 28(3) DORA). The annual report to the authority comprises at least the number of new arrangements, the categories of ICT third-party service providers, the type of arrangements and the ICT services and functions provided (Art. 28(3) third subparagraph DORA).
For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. The supply chain must record the providers and ranks required by the templates. For ICT services supporting critical or important functions, the relevant subcontracting chain must be identified. A complete procurement directory and the supervisory register’s required chain are different datasets. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956
Which template applies: BaFin Excel or xBRL?
Submission must use the technical format and current template version required by BaFin. A self-designed Excel workbook does not meet those requirements merely because BaFin provides an Excel template for a collection. BaFin: Ausfüllhinweise für die RoI-Excel-Vorlage BaFin: Informationsregister und Anzeigepflichten
The 15 templates describe relationships between entities, contracts and services. Identifiers must agree across templates. DORA does not prescribe a particular software product for this task. Implementing Regulation (EU) 2024/2956, register templates
How does submission via the BaFin portal MVP work?
Submission follows BaFin’s collection request and the access procedures it specifies. Technical access and completeness of the register are prepared separately. Submission feedback must be traceable to the version sent. BaFin: Informationsregister und Anzeigepflichten
01Identify the collection request
Use the reference date and submission window in the applicable BaFin request.
02Prepare the register state
Produce the required contract and provider data state reproducibly.
03Validate data and format
Submission must use the technical format and current template version required by BaFin. A self-designed Excel workbook does not meet those requirements merely because BaFin provides an Excel template for a collection.
04Retain submission evidence
Retain transmission evidence and supervisory feedback with the submitted data version.
Which 15 templates does the register of information contain (B_01.01 to B_99.01)?
Implementing Regulation (EU) 2024/2956 contains 15 standard templates. The following table maps their codes to their purpose. Field definitions and identifiers follow the current instructions, including the September 2025 corrigendum. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956
| Template code | Template | Purpose |
|---|---|---|
| B_01.01 | Entity maintaining the register | Identifies the financial entity maintaining and updating the register (LEI as a mandatory field) |
| B_01.02 | Entities within the scope of consolidation | All entities belonging to the group (without a group: identical to B_01.01) |
| B_01.03 | Branches | Branches of the financial entities captured in B_01.02 |
| B_02.01 | Contracts: general information | All contracts with direct ICT third-party service providers; one unique contract reference number per contract |
| B_02.02 | Contracts: specific information | Details per contract: ICT services included, functions supported, notice period, governing law |
| B_02.03 | Intra-group contracts | Links intra-group and external contracts via the reference numbers in the supply chain |
| B_03.01 | Entities signing the contracts | Entity signing the contract for the entity making use of the ICT services |
| B_03.02 | Signing ICT third-party service providers | Service providers (from B_05.01) signing the contracts from B_02.01 |
| B_03.03 | Signing group entities | Group entities (from B_01.02) signing contracts for providing services to other group entities |
| B_04.01 | Entities making use of the ICT services | All entities using the ICT services (financial entities or ICT intra-group service providers) |
| B_05.01 | ICT third-party service providers | Identify the required ICT providers and ultimate parent using the applicable identifier. |
| B_05.02 | ICT service supply chain | Identifies and ranks the service providers per ICT service (rank 1 = direct service provider, rank 2 = subcontractor, etc.); for CIF services supplemented by Delegated Regulation (EU) 2025/532 |
| B_06.01 | Function identification | Unique function identifier per combination of LEI, licensed activity and function; CIF classification |
| B_07.01 | Assessments of the ICT services | Including substitutability and the last audit for services supporting critical or important functions |
| B_99.01 | Definitions | Explanation of the closed option lists used (e.g. “low/medium/high”) |
What should a register-of-information tool demonstrate?
A vendor discussion becomes more useful when it follows one complete register case. The matrix translates the register tasks described in this article into testable questions. It is a T-NEX tool-selection aid, not an official submission format.
| Review area | Question for the supplier | Useful demonstration evidence |
|---|---|---|
| Data model | Can entities, contracts, ICT services, functions and providers be linked unambiguously? | One test contract with two services and a shared dependency, without duplicate master records. |
| Identifiers and relationships | Are permitted identifiers and references maintained consistently? | Deliberately introduce missing, duplicate and unresolved identifiers in a sample dataset. |
| Data quality | Are required fields, value lists and business inconsistencies explained clearly? | An error list identifying field, record, rule version and owner; recheck the correction. |
| Supply chain | Can a provider change be traced to affected contracts and functions? | Enter one change and show its impact on the affected register records. |
| Maintenance and approval | Who can edit, review and freeze a reporting snapshot? | Role changes, change history and traceable approval demonstrated in a complete workflow. |
| Export and version | Does the export match the submission version actually required? | Declared taxonomy/schema version and reproducible export from a recorded data snapshot. |
| Feedback | How are validation failures and follow-up questions resolved? | Link feedback to a register snapshot, correct it, re-export and retain the earlier version. |
| Operations and handover | Will data, relationships and evidence remain usable after a supplier change? | Complete trial export with a field dictionary, attachments and documented limitations. |
Use the same dataset to create a record, change a contract and process an invalid delivery. This reveals whether the tool supports ongoing maintenance as well as producing a table. Successful technical validation does not establish that every contract is included or that its business classification is correct.
The editable template adds priority, supplier response, result, evidence and accountable owner. The institution decides which requirements are mandatory before comparing suppliers.
Legal and professional sources: Verordnung (EU) 2022/2554: DORA, insbesondere Artikel 11, 24 und 28–30; Durchführungsverordnung (EU) 2024/2956: Vorlagen für das Informationsregister.
Download the tool matrix (Markdown)
What must be checked before submitting the register of information?
Before submission, check provider identifiers and relationships between templates. Critical or important function classification must agree with the underlying assessments. Technical validation does not replace that classification. Implementing Regulation (EU) 2024/2956, register templates
01Provider identifiers
For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity.
02CIF classification
Every contract is distinguished by whether it supports critical or important functions (Art. 28(3) DORA).
03Supply chain ranks
The supply chain must record the providers and ranks required by the templates. For ICT services supporting critical or important functions, the relevant subcontracting chain must be identified. A complete procurement directory and the supervisory register’s required chain are different datasets.
04Contract reference numbers
Every arrangement carries a unique reference number, consistent across all template boundaries (Implementing Regulation (EU) 2024/2956, Annex I).
05Format validation
Country codes (ISO 3166-1 alpha-2), date formats (ISO 8601) and closed option lists are checked; the xBRL taxonomy version is reconciled against the current BaFin/ESA requirements.
What do supervisors do with the data from the register of information?
The ESAs (EBA, ESMA, EIOPA) use the submitted register data as the basis for designating critical ICT third-party service providers (CTPPs) under Art. 31 DORA: on 18 November 2025 they designated 19 CTPPs for the first time (ESAs press release of 18 November 2025). The classification draws in particular on the ranked supply chain and the service provider identification from templates B_05.01/B_05.02. Practical note: Comparing your own list of service providers against the 19 designated CTPPs shows which of your providers fall under the European oversight framework (Art. 31–44 DORA); this does not change your own register obligations but is relevant for risk assessment and board reporting.
The European Supervisory Authorities reported 3,383 major ICT-related incidents under DORA for 2025. Around one third involved third-party providers. These figures come from their first annual report, published on 3 June 2026. ESAs: first DORA report on major ICT-related incidents
Register of information vs. outsourcing register: what is the difference?
The outsourcing register under section 25b(1), fourth sentence, KWG covers material and non-material outsourcing. The DORA register of information covers contractual arrangements for ICT services. A service may fall within both scopes. The ninth MaRisk amendment limits the scope of AT 9; it does not create a blanket exemption from the statutory register obligation. Section 25b KWG therefore requires a separate assessment. The explanatory note on AT 9 paragraph 1 states:
“Outsourced or externally procured ICT services within the meaning of Art. 3 No. 21 DORA that are subject to ICT third-party risk management under Art. 28-30 DORA do not fall within the scope of AT 9.”
The ninth MaRisk amendment has applied since 30 June 2026. The transition until 1 January 2027 applies only where additional requirements arise in an individual case. The exception in MaRisk AT 9 covers ICT services under Article 3(21) DORA that are subject to ICT third-party risk management under Articles 28 to 30. Other components of mixed services require separate classification. BaFin: Rundschreiben 06/2026 (BA), MaRisk
Does the register obligation also apply to small institutions?
For a small institution covered by DORA, size alone does not remove the register duty. The first step is to assess scope, including the exclusions in Article 2. Article 28 covers the relevant ICT contracts regardless of whether they support critical or important functions. Regulation (EU) 2022/2554, DORA
Related topics
- DORA Regulation overview: scope, core obligations and pillars.
- MaRisk: current version Circular 06/2026, AT/BT structure and amendments: incl. the AT 9 carve-out for ICT services and the transition period 1 January 2027.
- Banking regulation roadmap: deadlines on a timeline, incl. the expected 2027 register cycle.
Frequently asked questions about the DORA register of information
Sources & further reading
- Regulation (EU) 2022/2554 (DORA), esp. Art. 28(3), EUR-Lex/ELI: official texteur-lex.europa.eu
- Implementing Regulation (EU) 2024/2956: ITS with the standard templates for the register of information (Annex I)eur-lex.europa.eu
- BaFin: Register of information and notification requirementsbafin.de
- BaFin: FAQ on the DORA register of information and the notification obligations (MVP submission route, formats, cycles)bafin.de
- Delegated Regulation (EU) 2025/532: RTS on subcontracting for critical or important functionseur-lex.europa.eu
- Delegated Regulation (EU) 2024/1773: RTS on the contractual policy for ICT services supporting critical or important functionseur-lex.europa.eu
- BaFin: DORA topic page (incl. supervisory notice 08/2025)bafin.de
- BaFin: Circular 06/2026 (BA), MaRisk, download page incl. cover letter (AT 9 delineation from DORA)bafin.de
- ESAs (EBA/EIOPA/ESMA): first annual report on major ICT-related incidents under DORA (3 June 2026)eba.europa.eu
- ESAs (EBA/EIOPA/ESMA): press release on the designation of the first 19 critical ICT third-party service providers (18 November 2025)eba.europa.eu
- Implementing Regulation (EU) 2024/2956, register templateseur-lex.europa.eu
- BaFin: Ausfüllhinweise für die RoI-Excel-Vorlagebafin.de
- Corrigendum to Implementing Regulation (EU) 2024/2956eur-lex.europa.eu
- Regulation (EU) 2022/2554, DORAeur-lex.europa.eu
An offer from T-NEX GmbH
Discuss the project with T-NEX
Register maintenance starts with a data model and clear ownership. T-NEX supports business design and, where needed, develops appropriate interfaces or workflows. This article does not promise a standalone submission-ready register product.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
