The ICT Third-Party Register — DORA's Register of Information, field by field
As at 25 July 2026, DORA (Regulation (EU) 2022/2554, Article 28) requires financial entities to maintain a register of information on all contractual arrangements for the use of ICT services. It is not a background document — it is a named deliverable your competent authority (the CSSF in Luxembourg) can request, in a prescribed structure.
1 · The requirement
The register must cover all ICT third-party arrangements, with heightened detail for those supporting critical or important functions. The Commission Implementing Regulation on the register templates (Implementing Reg (EU) 2024/2956) sets the standardised format authorities use to aggregate this across the sector — which is exactly why an ad-hoc spreadsheet with missing fields reads as a finding.
2 · The operational control — what each entry carries
Per arrangement, the register needs (confirm the full template against the Implementing Regulation):
- The entity making the arrangement (and, in a group, the reporting structure).
- The provider — legal identity, LEI where available, country, whether it is an intra-group provider.
- The ICT service — type, and the function it supports.
- Criticality — whether it supports a critical or important function, with the assessment behind that call.
- The contract — start/end, notice, governing law, and the substitutability / exit arrangements.
- The chain — sub-contractors underpinning a critical or important function.
3 · The deliverable
Produce it as a maintained, exportable register — not a PDF about registers. The DORA Engine builds the Register of Information against the Implementing Regulation templates; pair it with Policy Templates for the third-party risk policy that governs it, and the Risk Register so a provider's criticality flows into your ICT risk view. One source, many obligations.