Under Article 28, every financial entity must maintain a structured register of its contractual arrangements with ICT third-party providers, distinguishing those that support critical or important functions. It must be available to the competent authority on request, in a specified format.
The register is one of the most concrete DORA artefacts — and one the Central Bank flagged for early compliance. Here is what it is and what goes in it.
What the register is
The register of information is a complete, structured record of your ICT third-party contractual arrangements at entity, sub-consolidated and consolidated levels. In 2025, Irish firms submitted registers to the Central Bank, and maintaining it is now an ongoing obligation.
What it must contain
For each arrangement, the register captures details such as the provider, the service, the function it supports, whether that function is critical or important, and contract terms. It must distinguish CIF-supporting arrangements from the rest.
CIF vs non-CIF arrangements
Arrangements supporting critical or important functions carry heavier obligations (including the Article 30 contract clauses), so correctly classifying each arrangement is essential. This depends on having mapped your critical functions — see Mapping critical or important functions.
Format and keeping it current
The register must follow the specified format and be kept up to date as contracts change. It is not a one-off submission — it is a living record.
Building your register? Download our register template or ask CyberLabs for help.