DORA operational resilience reporting.
DORA obliges financial entities across the EU to maintain a Register of Information covering every ICT third-party arrangement. This category covers what the obligation requires, who it applies to, and the REGREP modules that deliver it.
✓ Free record keeping & validation · From €1,000/year up to 50 arrangements · No card required
One register, every ICT third-party arrangement
The Digital Operational Resilience Act (DORA) requires financial entities across the EU — banks, investment firms, payment and e-money institutions, insurers, crypto-asset service providers and more — to maintain a Register of Information covering every contractual arrangement for the use of ICT third-party services, and to make it available to their competent authority in a defined supervisory format.
The register has to hold far more than a supplier list. It links the entity maintaining the register to each ICT third-party service provider, the contractual arrangements between them, the functions those services support, any intra-group arrangements and the full subcontracting chain — with LEI references resolved and the whole structure internally consistent. Assembling that by hand across spreadsheets is where most of the effort, and most of the errors, sit.
REGREP turns that work into a self-serve module. You load your arrangements in the shape they already exist, the platform maps them to the Register of Information templates, runs the referential and consistency checks, and exports a submission-ready package — no implementation project and no consultants.
Start free, pay when you export
Plans are priced per regulated entity. The module page sets out inclusions, limits and the export step in detail.
| Plan | What it covers | Free tier | Price | Action |
|---|---|---|---|---|
| Register of InformationUp to 50 ICT arrangements | Annual submission plus updates, supervisory-format export, one regulated entity. | Record keeping & validation | €1,000per year | Create free account → |
| Register of Information51 to 250 arrangements, single entity | Same register and export with no cap on arrangement count for one regulated entity. | Record keeping & validation | €4,000per year | Create free account |
| Consolidated / group registerAny count, multiple entities | A consolidated or group register covering several regulated entities, scoped to your structure. | Scoped engagement | Solution Layers | Talk to us |
Arrangements are counted at export. Plans scale without re-implementation. Counting rules, upgrade behaviour and export pricing are set out in full on the module page.
How firms use it
DORA Register of Information, ready to file
See how a regulated firm turns its ICT arrangements into a validated supervisory register.
Read use case → Use caseGroup and multi-entity registers
Consolidated registers across several regulated entities, handled as a scoped engagement.
Read use case → Use caseService providers and outsourcers
Support the arrangements and reporting your clients depend on, at the pace they file.
Read use case →Go deeper on DORA
DORA reporting requirements
What the Register of Information covers, who has to keep one, and when it is due.
Read the guide → DeadlinesDORA filing deadlines
Reviewed submission dates across jurisdictions, each linked back to the module.
View deadlines → Resource centerOperational resilience library
Guides, templates and reviewed source references across operational resilience reporting.
Browse resources →Questions, answered
Who has to keep a DORA Register of Information?
How does REGREP price DORA, and what if I am a group?
Can I use the free tier to prepare before I file?
Start with the obligation. Finish with a validated file.
Read what DORA requires of your entity, then take the register itself to the module.