Download · XLSX

DORA register of information: columns, code lists and checks before you submit

A working sheet with 33 rows of fields from templates B_01.01-B_07.01 and four checks for the whole register. For each field: the ITS column code, allowed values, when it is required, a check before you submit and the typical data source. No form, no sign-up.

What is the DORA register of information template?

The DORA register of information template is a spreadsheet for collecting and checking data on your contracts with ICT third-party service providers before you move it into your supervisor's reporting format. It covers the key fields of the templates in Implementing Regulation (EU) 2024/2956: what to enter, when a field is required, how to check it and where the data usually comes from. It is meant for ICT risk, compliance and procurement teams, and for DORA implementation projects.

Why registers fail validation

Article 28(3) of DORA requires financial entities to keep a register of information on all contractual arrangements for the use of ICT services, at entity level and at sub-consolidated and consolidated level, distinguishing services that support critical or important functions.

The templates are set out in Commission Implementing Regulation (EU) 2024/2956: 15 templates from B_01.01 to B_99.01, linked by keys such as the arrangement number, the provider code and the function identifier.

Financial entities shall use a valid and active legal entity identifier (LEI) or the European Unique Identifier referred to in Article 16 of Directive (EU) 2017/1132 ('EUID'), and where available both of these identifiers, to identify all of their ICT third-party service providers that are legal persons, except for individuals acting in a business capacity.

— Article 3(5), Implementing Regulation (EU) 2024/2956

Every cell holds a single value. Where several values apply, for example several countries where data is stored, you add a row (Article 4(2) of the ITS). A key field cannot be left blank: where the condition does not apply, you enter "Not Applicable" (ESAs register of information FAQ).

Hand-filled spreadsheets break these rules easily. In the 2024 dry run, 6.5% of the registers analyzed passed all data quality checks (ESAs press release), and 86% of the errors were missing mandatory data, most often the codes of providers and their parent undertakings (ESAs dry run report).

From 2026 the register holds data as of 31 December of the previous year (ESA Q&A 2025_7387), so the next cycle covers 31 December 2026.

National supervisors collect it. In Poland, KNF uses form SPR-PF-18 and sets the deadline in its request (KNF). In Germany, BaFin uses its MVP portal, where submission must be complete by 31 March (BaFin). Status as of 5 October 2026.

// How to use it

How to use the template in four steps

  1. Start with the list of contracts

    Collect every arrangement with an ICT third-party service provider in force on 31 December, intra-group ones included. Give each a reference number and keep it from cycle to cycle.

  2. Fill in the provider codes

    Enter an LEI or EUID for every legal person and check each LEI in the GLEIF search. Add the ultimate parent and the subcontractors from the provider's list.

  3. Link contracts to functions

    Give your functions the identifiers F1, F2 and so on, and take criticality, RTO and RPO from your business impact analysis and continuity plans. A service without a function is the first gap.

  4. Run the checks before you submit

    The "Check before you submit" column lists what to verify for each field. Record a status and an owner, then move the data into your supervisor's current form or format.

Preview: the first six fields

The full sheet has 37 rows: fields from templates B_01.01, B_01.02, B_02.01, B_02.02, B_05.01, B_05.02, B_06.01 and B_07.01, plus checks for the whole register. The notes list the types of ICT services S01-S19 from Annex III. Below are the first six rows, without the "When required" and "Typical data source" columns.

DORA register of information template, rows 1-6 (extract)
Column codeFieldWhat to enter (allowed values)Check before you submit
B_01.01.0010LEI of the entity maintaining the register20-character LEI (ISO 17442)The LEI is active in GLEIF (search.gleif.org). Do not enter a company register or tax number: in the 2024 dry run, national codes instead of LEIs were a frequent error.
B_01.02.0010LEI of each financial entity in the scope of consolidationLEI; an entity that is not part of a group reports only its own LEIThe same LEI wherever the entity appears again (B_02.02.0020, B_06.01.0040)
B_02.01.0010Contractual arrangement reference numberYour unique number for each arrangement with a direct ICT third-party service providerNo duplicates; the same number in B_02.02, B_05.02 and B_07.01
B_02.01.0020, B_02.01.0030Type of contractual arrangement and overarching arrangement reference number1 standalone, 2 overarching or master, 3 subsequent or associated; for 3 the overarching arrangement numberEvery type 3 arrangement points to an existing type 2 arrangement. For types 1 and 2 the field cannot be blank: enter "Not Applicable"
B_02.01.0040, B_02.01.0050Currency and annual expense of the arrangement for the past yearISO 4217 currency code; amount in units, not thousands (expense or estimate)No double counting between the overarching and the subsequent arrangements
B_02.02.0030, B_02.02.0040Code of the ICT third-party service provider and type of codeAs in B_05.01.0010 and B_05.01.0020Every code exists in B_05.01. In the 2024 dry run, missing provider codes were the most common gap in mandatory data.

Other versions: Polish (KNF) and German (BaFin). If the register's data is spread across several systems, start with data governance: a data dictionary and an owner for every field.

// Scope

What the template gives you, and what it cannot replace

The template gives you

  • The key fields of templates B_01.01-B_07.01 with their ITS 2024/2956 column codes
  • Allowed values from the closed lists and the ICT service types S01-S19
  • Checks that catch common errors before you submit
  • Columns for the source system, data owner and status

It cannot replace

  • Your supervisor's reporting form or a file in the ESA taxonomy format
  • Validation by your supervisor and the ESAs, the only test of whether the register is accepted
  • Your assessment of which functions are critical or important
  • Legal advice on whether DORA applies to you

A register retyped by hand once a year is only current on the day you send it.

// FAQ

Questions about the register template

Can I submit this file to my supervisor?

No. Supervisors collect the register through their own channels: KNF in Poland through form SPR-PF-18, BaFin in Germany through the MVP portal as an xBRL file or with its own Excel template. The ESAs receive the data in plain-csv format under the ESA taxonomy. This template is for collecting and checking the data first.

Does the template cover every column of ITS 2024/2956?

No. It covers the fields that link contracts, providers and functions, and the assessment fields for services that support critical or important functions. It leaves out templates B_01.03 (branches), B_02.03, B_03.01-B_03.03, B_04.01 and B_99.01 entirely, and some columns of the others. The full list of columns and the fill-in instructions are in Annex I of the regulation.

Which reference date applies to the next cycle?

According to ESA Q&A 2025_7387, from 2026 the register holds data as of 31 December of the previous year, so the next cycle uses 31 December 2026. Deadlines are set nationally: BaFin expects submission to be complete by 31 March, and KNF sets the date in its request. As of 5 October 2026; check your supervisor's latest notice.

What if a provider has no LEI?

A provider in the EU that is a legal person can be identified by its EUID if it has one in a business register. A provider established outside the EU is identified by LEI only, so ask them for one. Other code types, such as a VAT number (code type "VAT", no country prefix), are allowed only for individuals acting in a business capacity.

Do I need to give my email to download the file?

No. You download the file without a form. If you want to go through your register with us, request the first step.

First step: 5 weeks, fixed scope

A register built from data, not retyped

We check where each column of the register comes from and who updates it. Where data was typed in by hand, we link it to contracts, invoices and your system inventory, so the next cycle is an update. More on DORA implementation and data governance.

Request the first step