What the Register Is
The Register of Information (Articles 28–29) is a complete, structured inventory of every ICT third-party arrangement, maintained at entity and group level and submitted to supervisors in a prescribed format.
Why it exists
Supervisors use the Register to see, across the whole sector, who depends on which ICT providers — the raw material for identifying Critical ICT Third-Party Providers (CTPPs) and systemic concentration risk. Your Register is not just an internal asset; it feeds EU-level oversight.
A regulated dataset, not an internal spreadsheet
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025, and the Register is defined in detail by the ITS on the Register of Information (Reg (EU) 2024/2956). Unlike an internal vendor list, the Register has a fixed, machine-readable structure: legal entities carry valid LEIs, fields use controlled vocabularies (service types, country and currency codes), and records must be internally consistent so they can be aggregated across the whole EU. It is maintained at entity level and, where a group exists, at (sub-)consolidated level, and it must reach beyond direct providers into the subcontracting chain that supports critical or important functions.
Complete
Every ICT third-party arrangement, not a sample.
Structured
Related templates, LEIs, controlled vocabularies.
Submitted
Filed to the competent authority in the ITS format.
Worked example. A mid-size German payment institution had a tidy procurement spreadsheet of 140 suppliers. Asked for its Register, it discovered the spreadsheet had no LEIs, no criticality flags, and no subcontracting chain — none of what the ITS demands. The lesson: the Register is a regulated dataset that must be built to the template, not an existing list relabelled.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate — lifetime access.
Secure payment via Stripe · 30-day money-back guarantee.