Skip to content

DORA Register of Information: Templates, Fields and Checklist

By Black Cat Security Team · Updated September 5, 2026

Version française

The Register of Information is the inventory of every ICT third-party arrangement a financial entity relies on, kept in the 15 templates of Implementing Regulation (EU) 2024/2956 and reported at least yearly to the competent authority — in France the ACPR (OneGate) or the AMF (ROSA). Its primary key is the contractual arrangement reference number; its hardest part is the provider and service inventory, because SaaS and AI tools that nobody formally declared still count.

This page lists the templates and their fields, the filing calendar, what a read-only SaaS inventory can pre-fill, and a pre-filing checklist. For how Black Cat SSPM maps to DORA more broadly, see SSPM for DORA and the DORA control mapping.

Who files, to whom, and when

DORA Art. 28(3) requires every financial entity to maintain the register at entity level and, where applicable, at sub-consolidated and consolidated level, to distinguish the arrangements that support critical or important functions, and to make the full register available to its competent authority on request and at least yearly as a report. The authority forwards the registers to the European Supervisory Authorities, which use them to designate critical ICT third-party providers.

  • Reference date. From 2026, 31 December of the calendar year preceding the reporting date (EIOPA Q&A DORA-253).
  • France, ACPR. 2026 cycle: reference date 31 December 2025, deadline 31 March 2026, plain-CSV files in a single .zip uploaded from the OneGate home page (domains DRB for banks, DRA for insurers; consolidation levels LEI.IND / LEI.CON; French or English; no e-signature). The 2025 cycle used the 31 December 2024 reference date with a 15 April 2025 deadline. The 2027 cycle is expected to follow the standing rule — reference 31 December 2026, deadline 31 March 2027 — but the ACPR notice was not published as of this writing.
  • Significant institutions file with the ECB via CASPER, not OneGate.
  • France, AMF. Asset managers and other AMF-supervised entities submit via the ROSA interface in the ESAs’ format; check the AMF’s notice for the current cycle’s dates.

The 15 templates

Annex I of Implementing Regulation (EU) 2024/2956; column codes in brackets— as of 2026-09
TemplateOfficial titleWhat it capturesKey fields
B_01.01Entity maintaining the register of informationWho filesLEI (0010), name, country, type of entity, competent authority, date of reporting (0060)
B_01.02List of entities within the scope of consolidationGroup entities coveredLEI, name, country, type, hierarchy, direct-parent LEI, dates of last update / integration / deletion, currency, total assets (0110)
B_01.03List of branchesBranches of those entitiesBranch identification code, head-office LEI, name, country
B_02.01Contractual arrangements – general informationOne row per contract with a direct providerContractual arrangement reference number (0010, entity-assigned, stable), type (0020), overarching arrangement (0030), currency (0040), annual expense or estimated cost (0050)
B_02.02Contractual arrangements – specific informationContract × entity × provider × function × serviceReference number, user-entity LEI, provider ID and code type, function identifier, type of ICT service (S01–S19), start / end dates, notice periods, governing-law country, country of provision, data stored Y/N, data-at-rest and processing locations, data sensitiveness, level of reliance
B_02.03List of intra-group contractual arrangementsLinks between group contractsReference number ↔ linked reference number
B_03.01Entities signing the contractual arrangements for receiving ICT service(s)Signatories, entity sideReference number, LEI of the signing financial entity
B_03.02ICT third-party service providers signing the contractual arrangementsSignatories, provider sideReference number, provider identification code and type
B_03.03Entities signing the contractual arrangements for providing ICT service(s)Intra-group providersReference number, LEI of the group entity providing the service
B_04.01Entities making use of the ICT servicesWho uses each serviceReference number, LEI, branch / non-branch nature, branch identification code
B_05.01ICT third-party service providersOne row per providerIdentification code and type (LEI / EUID / CRN / VAT / PNR / NIN), legal name, name in Latin alphabet, type of person, headquarters country, currency, total annual expense (0100), ultimate-parent ID
B_05.02ICT service supply chainSubcontracting chainReference number, service type, provider ID, rank (direct provider = 1), recipient of the subcontracted service
B_06.01Functions identificationThe entity’s function catalogueFunction identifier (0010), licensed activity (Annex II), name, LEI, criticality or importance assessment (Yes / No / not performed), reasons, date of last assessment, RTO, RPO, impact of discontinuing
B_07.01Assessments of the ICT servicesRisk view of services supporting critical or important functionsReference number, provider ID, service type, substitutability (four levels), reason, date of last audit, exit plan Y/N, reintegration possibility, impact of discontinuing, alternatives identified, alternative provider
B_99.01Definitions from entities making use of the ICT ServicesThe entity’s own definitionsColumn code, column name, option, description

Identifiers and service types

Financial entities are identified by LEI only. Providers use one of six code types — LEI, EUID, CRN (corporate registration number), VAT, PNR (passport) or NIN (national ID) — with the rule that legal persons use LEI or EUID, legal persons established outside the Union use LEI only, and the alternative codes are reserved for individuals acting in a business capacity.

Each service row carries one of the 19 ICT service types of Annex III (only the code is reported):

  • S01 ICT project management
  • S02 ICT development
  • S03 ICT help desk and first-level support
  • S04 ICT security management services
  • S05 Provision of data
  • S06 Data analysis
  • S07 ICT, facilities and hosting services (excluding cloud)
  • S08 Computation
  • S09 Non-cloud data storage
  • S10 Telecom carrier
  • S11 Network infrastructure
  • S12 Hardware and physical devices
  • S13 Software licencing (excluding SaaS)
  • S14 ICT operation management (including maintenance)
  • S15 ICT consulting
  • S16 ICT risk management
  • S17 Cloud services: IaaS
  • S18 Cloud services: PaaS
  • S19 Cloud services: SaaS

What a read-only SaaS inventory can pre-fill

The register is contract-centred and an inventory is app-centred, so every pre-filled row still has to be joined to a contractual arrangement reference. With that caveat, a read-only scan of the SaaS, cloud and AI vendors actually connected to your tenants can draft:

  • B_05.01 provider identity: legal name and name in Latin alphabet, type of person, headquarters country; LEI or EUID and ultimate parent via a GLEIF lookup — but the contracting subsidiary (which Microsoft or Google entity) still comes from the contract.
  • B_02.02 type of ICT service: S19 for SaaS, S17 / S18 for cloud infrastructure; AI APIs need a judgement call between S19 and S05 / S06.
  • B_02.02 storage of data (Yes for almost every SaaS) and data-at-rest / processing locations where the vendor API exposes the tenant region — partial.
  • B_04.01 and B_01.02 entity-to-app mapping, where tenants map to legal entities — partial.
  • B_05.02 subcontractors of rank 2 and above, only where the hosting provider is public or a sub-processor list is machine-readable — partial.
  • B_02.02 start date, approximated by the first-seen date of the integration — indicative only.

What still needs a human

  • Contractual arrangement reference numbers, contract type, overarching links and annual expense (B_02.01, B_05.01).
  • Start and end dates, notice periods, governing law, country of provision, function identifier, data sensitiveness and level of reliance (B_02.02).
  • Signatories on both sides (B_03.01 – B_03.03).
  • The function catalogue, criticality or importance assessment, RTO and RPO (B_06.01).
  • Substitutability, exit plans, audit dates, alternatives and reintegration options (B_07.01).
  • Group structure, branches and total assets (B_01.01 – B_01.03); your own definitions (B_99.01).
  • Apps used without any contract — free tiers, shadow IT — fall outside the “contractual arrangement” concept; how competent authorities expect them to be treated is not settled in the published texts.

Pre-filing checklist

  1. Confirm the reporting level (entity, sub-consolidated, consolidated) and the reference date your authority set for this cycle.
  2. Obtain or renew the LEI of every entity in scope; collect LEIs or EUIDs for every provider that is a legal person (alternative codes are for individuals only).
  3. Freeze the function catalogue (B_06.01) with a criticality decision and a date for each function; the register cannot be filed with assessments “not performed” on critical functions.
  4. Export the inventory of SaaS, cloud and AI vendors actually in use — including tools no one formally declared — and reconcile it with the contract list.
  5. Assign a stable contractual arrangement reference number to every contract; it is the key of every other template.
  6. Classify each service with an S01–S19 code and record data storage and processing countries per row.
  7. Fill the provider block (B_05.01) with legal names in Latin script, headquarters country and annual spend in the reporting currency.
  8. Map the supply chain (B_05.02) at least for services supporting critical or important functions, with the direct provider at rank 1.
  9. Complete B_07.01 for every service supporting a critical or important function: substitutability, exit plan, last audit, alternatives.
  10. Validate the CSV package against your authority’s rules (for the ACPR: plain-CSV files in a single .zip, uploaded from the OneGate home page) and keep the accepted receipt with the register.

Frequently asked questions

Who has to file the DORA Register of Information?

Every financial entity in scope of DORA (Regulation (EU) 2022/2554, Art. 28(3)): it maintains the register at entity, sub-consolidated and consolidated level, flags the arrangements that support critical or important functions, and reports it at least yearly to its competent authority, which forwards it to the European Supervisory Authorities.

When is the register due in France?

For the 2026 cycle the ACPR set the reference date at 31 December 2025 and the deadline at 31 March 2026, in plain-CSV format via OneGate. The standing rule on the ACPR’s DORA pages is reference date 31 December of year N, deadline 31 March of year N+1, so the next cycle is expected to close on 31 March 2027 — confirm with the ACPR notice once published. Significant institutions file with the ECB via CASPER; AMF-supervised entities file via ROSA.

Which file format is accepted?

The ESAs publish an xBRL-CSV taxonomy and a “plain CSV” reporting package (one CSV per template plus a report-package.json, zipped). The ACPR accepts plain CSV in a .zip only; Excel is for preparation and must be converted. Other authorities differ — the CSSF also takes plain-CSV zips, the DNB accepts xBRL-CSV converted from its Excel template.

How much of the register can a SaaS inventory fill in?

The provider block and the service-type, data-storage and (partly) data-location columns — that is, the parts that describe what is in use. Contract references, costs, notice periods, function criticality, RTO/RPO, substitutability and exit plans are decisions and contract facts that only your legal, procurement and risk teams can supply. Black Cat SSPM generates the ICT-provider section from a read-only scan of the connected SaaS and AI vendors; see SSPM for DORA.

Sources (accessed 2026-09-05)

  • Commission Implementing Regulation (EU) 2024/2956 (ITS on the register of information), OJ L 2 Dec 2024 — https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj/eng
  • Regulation (EU) 2022/2554 (DORA), Art. 28 — https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
  • ESAs timeline for the collection of registers (2024-11-15) — https://www.eiopa.europa.eu/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers-2024-11-15_hr
  • EIOPA Q&A DORA-253 (reference date from 2026) — https://www.eiopa.europa.eu/qa-regulation/questions-and-answers-database/dora-253-3393_en
  • ACPR — FAQ DORA and “Remise des registres d’information” (2025-04-11) — https://acpr.banque-france.fr/fr/actualites/remise-des-registres-dinformation
  • ACPR / eSurfi — Modalités de remise de la collecte DORA (banque, 2026-06-23; assurance, 2025-12-16) — https://esurfi.banque-france.fr/
  • AMF — DORA page (2025-02-26) — https://www.amf-france.org/en/news-publications/depth/dora
  • EBA — Preparation for DORA application: DPM, xBRL-CSV and plain-CSV packages — https://eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act/preparation-dora-application

Competitor information on this page is drawn from publicly available sources (vendor websites, product pages, and independent press coverage) as of the date noted next to each claim, and is believed accurate at time of writing. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Vendor offerings change over time — verify current details directly with the vendor before making a purchasing decision.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default OAuth access you can revoke any time.

Run a free posture scan