DORA reporting requirements
The Digital Operational Resilience Act sets one EU-wide rulebook for how financial entities manage ICT risk. Its most concrete reporting duty is the Register of Information on ICT third-party arrangements, filed with your competent authority.
REGREP is an independent software provider. This page explains the framework in plain language and is not legal or regulatory advice — confirm scope and timing with your competent authority.
- Instrument
- Regulation (EU) 2022/2554
- Scope
- EU financial entities and their ICT third-party providers
- Reporting artefact
- Register of Information
- Format
- Supervisory reporting format
- Supervisor
- National competent authority
- Penalties
- Administrative measures and sanctions set by each member state
What DORA asks of you
The short version: what the framework requires, who it applies to and when it bites.
What it requires
Financial entities maintain a complete register of every contractual arrangement for ICT services, covering the provider, the service, the entity using it and the chain behind it.
Who it applies to
Banks, investment firms, payment and e-money institutions, insurers, crypto-asset service providers, fund managers and other regulated entities operating in the EU.
When it applies
DORA has applied since January 2025. Registers are submitted to the competent authority on the schedule your authority sets, and kept current between submissions.
What has to be done
Penalty powers derive from Regulation (EU) 2022/2554 as applied through national transposition.
| Obligation | What it means in practice |
|---|---|
| Maintain the register | Record every ICT third-party contractual arrangement, including intra-group arrangements, with the templates and fields the supervisory format prescribes. |
| Identify entities correctly | Each entity and provider in the chain is identified with valid identifiers, and the relationships between them must resolve consistently. |
| Flag critical functions | Arrangements supporting critical or important functions are marked, with the assessments that support that classification. |
| Submit in the supervisory format | The register is exported and filed in the prescribed format; structural or referential errors are rejected before they reach the supervisor. |
| Keep it current | The register is updated as contracts are signed, changed or terminated — not reconstructed once a year. |
From your data to a validated filing
Activate only the module the obligation needs. Every price covers one regulated entity unless stated otherwise, and excludes VAT.
Register of Information
Build the register, validate identifiers and relationships, and export in the supervisory format. Free record keeping and validation to start.
€1,000/yearUp to 50 ICT arrangements · 1 regulated entity Create free account →Larger registers
The same module for single entities holding more than 100 ICT third-party arrangements, with no change to the export or validation path.
€4,000/yearOver 100 arrangements · 1 regulated entity Create free account →Group and consolidated registers
Any consolidated or group-level register — multiple regulated entities filing together — is delivered as a Solution Layers engagement.
Talk to usScoped to your group structure Talk to usRelated to DORA
Filing a DORA Register of Information
How firms assemble, validate and submit the register without rebuilding it in spreadsheets each cycle.
Read use case →Operational resilience guide
Plain-language explainers on DORA and the wider operational resilience agenda across the EU and UK.
Read the guide →Register of Information module
See how the module builds, validates and exports the register, with the full pricing detail.
See the module →Questions, answered
Who has to keep a DORA Register of Information?
What does the free tier let me do?
How is pricing decided?
Can REGREP file the register for us?
Build the register once, keep it filing-ready.
Create a free account, load your ICT arrangements and run full validation today.