The Register of Information is the inventory of every ICT third-party arrangement a financial entity relies on, kept in the 15 templates of Implementing Regulation (EU) 2024/2956 and reported at least yearly to the competent authority — in France the ACPR (OneGate) or the AMF (ROSA). Its primary key is the contractual arrangement reference number; its hardest part is the provider and service inventory, because SaaS and AI tools that nobody formally declared still count.
This page lists the templates and their fields, the filing calendar, what a read-only SaaS inventory can pre-fill, and a pre-filing checklist. For how Black Cat SSPM maps to DORA more broadly, see SSPM for DORA and the DORA control mapping.
Who files, to whom, and when
DORA Art. 28(3) requires every financial entity to maintain the register at entity level and, where applicable, at sub-consolidated and consolidated level, to distinguish the arrangements that support critical or important functions, and to make the full register available to its competent authority on request and at least yearly as a report. The authority forwards the registers to the European Supervisory Authorities, which use them to designate critical ICT third-party providers.
- Reference date. From 2026, 31 December of the calendar year preceding the reporting date (EIOPA Q&A DORA-253).
- France, ACPR. 2026 cycle: reference date 31 December 2025, deadline 31 March 2026, plain-CSV files in a single .zip uploaded from the OneGate home page (domains DRB for banks, DRA for insurers; consolidation levels LEI.IND / LEI.CON; French or English; no e-signature). The 2025 cycle used the 31 December 2024 reference date with a 15 April 2025 deadline. The 2027 cycle is expected to follow the standing rule — reference 31 December 2026, deadline 31 March 2027 — but the ACPR notice was not published as of this writing.
- Significant institutions file with the ECB via CASPER, not OneGate.
- France, AMF. Asset managers and other AMF-supervised entities submit via the ROSA interface in the ESAs’ format; check the AMF’s notice for the current cycle’s dates.
The 15 templates
| Template | Official title | What it captures | Key fields |
|---|---|---|---|
| B_01.01 | Entity maintaining the register of information | Who files | LEI (0010), name, country, type of entity, competent authority, date of reporting (0060) |
| B_01.02 | List of entities within the scope of consolidation | Group entities covered | LEI, name, country, type, hierarchy, direct-parent LEI, dates of last update / integration / deletion, currency, total assets (0110) |
| B_01.03 | List of branches | Branches of those entities | Branch identification code, head-office LEI, name, country |
| B_02.01 | Contractual arrangements – general information | One row per contract with a direct provider | Contractual arrangement reference number (0010, entity-assigned, stable), type (0020), overarching arrangement (0030), currency (0040), annual expense or estimated cost (0050) |
| B_02.02 | Contractual arrangements – specific information | Contract × entity × provider × function × service | Reference number, user-entity LEI, provider ID and code type, function identifier, type of ICT service (S01–S19), start / end dates, notice periods, governing-law country, country of provision, data stored Y/N, data-at-rest and processing locations, data sensitiveness, level of reliance |
| B_02.03 | List of intra-group contractual arrangements | Links between group contracts | Reference number ↔ linked reference number |
| B_03.01 | Entities signing the contractual arrangements for receiving ICT service(s) | Signatories, entity side | Reference number, LEI of the signing financial entity |
| B_03.02 | ICT third-party service providers signing the contractual arrangements | Signatories, provider side | Reference number, provider identification code and type |
| B_03.03 | Entities signing the contractual arrangements for providing ICT service(s) | Intra-group providers | Reference number, LEI of the group entity providing the service |
| B_04.01 | Entities making use of the ICT services | Who uses each service | Reference number, LEI, branch / non-branch nature, branch identification code |
| B_05.01 | ICT third-party service providers | One row per provider | Identification code and type (LEI / EUID / CRN / VAT / PNR / NIN), legal name, name in Latin alphabet, type of person, headquarters country, currency, total annual expense (0100), ultimate-parent ID |
| B_05.02 | ICT service supply chain | Subcontracting chain | Reference number, service type, provider ID, rank (direct provider = 1), recipient of the subcontracted service |
| B_06.01 | Functions identification | The entity’s function catalogue | Function identifier (0010), licensed activity (Annex II), name, LEI, criticality or importance assessment (Yes / No / not performed), reasons, date of last assessment, RTO, RPO, impact of discontinuing |
| B_07.01 | Assessments of the ICT services | Risk view of services supporting critical or important functions | Reference number, provider ID, service type, substitutability (four levels), reason, date of last audit, exit plan Y/N, reintegration possibility, impact of discontinuing, alternatives identified, alternative provider |
| B_99.01 | Definitions from entities making use of the ICT Services | The entity’s own definitions | Column code, column name, option, description |
Identifiers and service types
Financial entities are identified by LEI only. Providers use one of six code types — LEI, EUID, CRN (corporate registration number), VAT, PNR (passport) or NIN (national ID) — with the rule that legal persons use LEI or EUID, legal persons established outside the Union use LEI only, and the alternative codes are reserved for individuals acting in a business capacity.
Each service row carries one of the 19 ICT service types of Annex III (only the code is reported):
- S01 ICT project management
- S02 ICT development
- S03 ICT help desk and first-level support
- S04 ICT security management services
- S05 Provision of data
- S06 Data analysis
- S07 ICT, facilities and hosting services (excluding cloud)
- S08 Computation
- S09 Non-cloud data storage
- S10 Telecom carrier
- S11 Network infrastructure
- S12 Hardware and physical devices
- S13 Software licencing (excluding SaaS)
- S14 ICT operation management (including maintenance)
- S15 ICT consulting
- S16 ICT risk management
- S17 Cloud services: IaaS
- S18 Cloud services: PaaS
- S19 Cloud services: SaaS
What a read-only SaaS inventory can pre-fill
The register is contract-centred and an inventory is app-centred, so every pre-filled row still has to be joined to a contractual arrangement reference. With that caveat, a read-only scan of the SaaS, cloud and AI vendors actually connected to your tenants can draft:
- B_05.01 provider identity: legal name and name in Latin alphabet, type of person, headquarters country; LEI or EUID and ultimate parent via a GLEIF lookup — but the contracting subsidiary (which Microsoft or Google entity) still comes from the contract.
- B_02.02 type of ICT service: S19 for SaaS, S17 / S18 for cloud infrastructure; AI APIs need a judgement call between S19 and S05 / S06.
- B_02.02 storage of data (Yes for almost every SaaS) and data-at-rest / processing locations where the vendor API exposes the tenant region — partial.
- B_04.01 and B_01.02 entity-to-app mapping, where tenants map to legal entities — partial.
- B_05.02 subcontractors of rank 2 and above, only where the hosting provider is public or a sub-processor list is machine-readable — partial.
- B_02.02 start date, approximated by the first-seen date of the integration — indicative only.
What still needs a human
- Contractual arrangement reference numbers, contract type, overarching links and annual expense (B_02.01, B_05.01).
- Start and end dates, notice periods, governing law, country of provision, function identifier, data sensitiveness and level of reliance (B_02.02).
- Signatories on both sides (B_03.01 – B_03.03).
- The function catalogue, criticality or importance assessment, RTO and RPO (B_06.01).
- Substitutability, exit plans, audit dates, alternatives and reintegration options (B_07.01).
- Group structure, branches and total assets (B_01.01 – B_01.03); your own definitions (B_99.01).
- Apps used without any contract — free tiers, shadow IT — fall outside the “contractual arrangement” concept; how competent authorities expect them to be treated is not settled in the published texts.
Pre-filing checklist
- Confirm the reporting level (entity, sub-consolidated, consolidated) and the reference date your authority set for this cycle.
- Obtain or renew the LEI of every entity in scope; collect LEIs or EUIDs for every provider that is a legal person (alternative codes are for individuals only).
- Freeze the function catalogue (B_06.01) with a criticality decision and a date for each function; the register cannot be filed with assessments “not performed” on critical functions.
- Export the inventory of SaaS, cloud and AI vendors actually in use — including tools no one formally declared — and reconcile it with the contract list.
- Assign a stable contractual arrangement reference number to every contract; it is the key of every other template.
- Classify each service with an S01–S19 code and record data storage and processing countries per row.
- Fill the provider block (B_05.01) with legal names in Latin script, headquarters country and annual spend in the reporting currency.
- Map the supply chain (B_05.02) at least for services supporting critical or important functions, with the direct provider at rank 1.
- Complete B_07.01 for every service supporting a critical or important function: substitutability, exit plan, last audit, alternatives.
- Validate the CSV package against your authority’s rules (for the ACPR: plain-CSV files in a single .zip, uploaded from the OneGate home page) and keep the accepted receipt with the register.
Frequently asked questions
Who has to file the DORA Register of Information?
Every financial entity in scope of DORA (Regulation (EU) 2022/2554, Art. 28(3)): it maintains the register at entity, sub-consolidated and consolidated level, flags the arrangements that support critical or important functions, and reports it at least yearly to its competent authority, which forwards it to the European Supervisory Authorities.
When is the register due in France?
For the 2026 cycle the ACPR set the reference date at 31 December 2025 and the deadline at 31 March 2026, in plain-CSV format via OneGate. The standing rule on the ACPR’s DORA pages is reference date 31 December of year N, deadline 31 March of year N+1, so the next cycle is expected to close on 31 March 2027 — confirm with the ACPR notice once published. Significant institutions file with the ECB via CASPER; AMF-supervised entities file via ROSA.
Which file format is accepted?
The ESAs publish an xBRL-CSV taxonomy and a “plain CSV” reporting package (one CSV per template plus a report-package.json, zipped). The ACPR accepts plain CSV in a .zip only; Excel is for preparation and must be converted. Other authorities differ — the CSSF also takes plain-CSV zips, the DNB accepts xBRL-CSV converted from its Excel template.
How much of the register can a SaaS inventory fill in?
The provider block and the service-type, data-storage and (partly) data-location columns — that is, the parts that describe what is in use. Contract references, costs, notice periods, function criticality, RTO/RPO, substitutability and exit plans are decisions and contract facts that only your legal, procurement and risk teams can supply. Black Cat SSPM generates the ICT-provider section from a read-only scan of the connected SaaS and AI vendors; see SSPM for DORA.
Related
- SSPM for DORA: automating the ICT third-party register
- DORA control mapping in the Black Cat policy catalog
- SSPM for NIS2 & ReCyF — the ReCyF referential is not yet published; that page explains what is mapped today.
Sources (accessed 2026-09-05)
- Commission Implementing Regulation (EU) 2024/2956 (ITS on the register of information), OJ L 2 Dec 2024 — https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj/eng
- Regulation (EU) 2022/2554 (DORA), Art. 28 — https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
- ESAs timeline for the collection of registers (2024-11-15) — https://www.eiopa.europa.eu/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers-2024-11-15_hr
- EIOPA Q&A DORA-253 (reference date from 2026) — https://www.eiopa.europa.eu/qa-regulation/questions-and-answers-database/dora-253-3393_en
- ACPR — FAQ DORA and “Remise des registres d’information” (2025-04-11) — https://acpr.banque-france.fr/fr/actualites/remise-des-registres-dinformation
- ACPR / eSurfi — Modalités de remise de la collecte DORA (banque, 2026-06-23; assurance, 2025-12-16) — https://esurfi.banque-france.fr/
- AMF — DORA page (2025-02-26) — https://www.amf-france.org/en/news-publications/depth/dora
- EBA — Preparation for DORA application: DPM, xBRL-CSV and plain-CSV packages — https://eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act/preparation-dora-application