Regulations · Operational resilience

DORA reporting requirements

The Digital Operational Resilience Act sets one EU-wide rulebook for how financial entities manage ICT risk. Its most concrete reporting duty is the Register of Information on ICT third-party arrangements, filed with your competent authority.

REGREP is an independent software provider. This page explains the framework in plain language and is not legal or regulatory advice — confirm scope and timing with your competent authority.

Framework factsEU
Instrument
Regulation (EU) 2022/2554
Scope
EU financial entities and their ICT third-party providers
Reporting artefact
Register of Information
Format
Supervisory reporting format
Supervisor
National competent authority
Penalties
Administrative measures and sanctions set by each member state
In plain language

What DORA asks of you

The short version: what the framework requires, who it applies to and when it bites.

What it requires

Financial entities maintain a complete register of every contractual arrangement for ICT services, covering the provider, the service, the entity using it and the chain behind it.

Who it applies to

Banks, investment firms, payment and e-money institutions, insurers, crypto-asset service providers, fund managers and other regulated entities operating in the EU.

When it applies

DORA has applied since January 2025. Registers are submitted to the competent authority on the schedule your authority sets, and kept current between submissions.

Obligations

What has to be done

Penalty powers derive from Regulation (EU) 2022/2554 as applied through national transposition.

ObligationWhat it means in practice
Maintain the registerRecord every ICT third-party contractual arrangement, including intra-group arrangements, with the templates and fields the supervisory format prescribes.
Identify entities correctlyEach entity and provider in the chain is identified with valid identifiers, and the relationships between them must resolve consistently.
Flag critical functionsArrangements supporting critical or important functions are marked, with the assessments that support that classification.
Submit in the supervisory formatThe register is exported and filed in the prescribed format; structural or referential errors are rejected before they reach the supervisor.
Keep it currentThe register is updated as contracts are signed, changed or terminated — not reconstructed once a year.
How REGREP automates it

From your data to a validated filing

Activate only the module the obligation needs. Every price covers one regulated entity unless stated otherwise, and excludes VAT.

Self-serve

Register of Information

Build the register, validate identifiers and relationships, and export in the supervisory format. Free record keeping and validation to start.

€1,000/yearUp to 50 ICT arrangements · 1 regulated entity Create free account
Self-serve

Larger registers

The same module for single entities holding more than 100 ICT third-party arrangements, with no change to the export or validation path.

€4,000/yearOver 100 arrangements · 1 regulated entity Create free account
Solution Layers

Group and consolidated registers

Any consolidated or group-level register — multiple regulated entities filing together — is delivered as a Solution Layers engagement.

Talk to usScoped to your group structure Talk to us
Keep reading

Related to DORA

Use case

Filing a DORA Register of Information

How firms assemble, validate and submit the register without rebuilding it in spreadsheets each cycle.

Read use case
Guide

Operational resilience guide

Plain-language explainers on DORA and the wider operational resilience agenda across the EU and UK.

Read the guide
Product

Register of Information module

See how the module builds, validates and exports the register, with the full pricing detail.

See the module
FAQ

Questions, answered

Who has to keep a DORA Register of Information?
In-scope EU financial entities maintain a register of their ICT third-party contractual arrangements. That includes banks, investment firms, payment and e-money institutions, insurers, crypto-asset service providers and fund managers. Confirm your own scope with your competent authority.
What does the free tier let me do?
You can build the register and run full validation, so you can prove your data holds up before paying. The free tier does not produce the supervisory export — that is on the paid plans.
How is pricing decided?
By the number of ICT third-party arrangements in the register: up to 100 at €1,000/year, over 100 for a single entity at €2,500/year. Any consolidated or group register is a Solution Layers engagement regardless of count.
Can REGREP file the register for us?
REGREP produces the validated register in the supervisory format. Submission to your competent authority stays with you, through whatever channel that authority requires.

Build the register once, keep it filing-ready.

Create a free account, load your ICT arrangements and run full validation today.