Regmindr
Compliance deadlines

DORA register of information: what to submit and when

DORA · Annually · Register as at 31 December, due in the first quarter

Under DORA Art. 28(3), every EU financial entity keeps a register of information on all its contracts for ICT services, and reports on it to its competent authority at least once a year. In practice each authority collects the full register in the first quarter, as at 31 December, and passes it to the European Supervisory Authorities by the end of March.

What goes in it

Every contractual arrangement for ICT services provided by third parties, kept at entity level and, for groups, at sub-consolidated and consolidated level. The register shows which arrangements support critical or important functions. Its templates are set by Commission Implementing Regulation (EU) 2024/2956.

When it's due

Each competent authority sets its own submission window. For the 2026 register, as at 31 December 2025, for example:

  • Luxembourg (CSSF): 11 February to 31 March 2026
  • Malta (MFSA): 1 January to 21 March 2026

Beyond the yearly submission

  • Make the full register, or parts of it, available whenever your authority asks.
  • Tell your authority in good time about any planned contract for ICT services that support critical or important functions, and when a function becomes critical or important.

Submit early

Authorities run validation checks on each submission, and the CSSF has warned that these now cover more fields, so a register accepted one year can be rejected the next. Leave time to fix errors before the window closes.

Get reminded before it's due

Regmindr tracks this alongside the rest of your compliance calendar, and emails your team before each deadline.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related