Home › DORA › Register of Information

DORA Compliance

The DORA Register of Information

Key takeaway

Under Article 28, every financial entity must maintain a structured register of its contractual arrangements with ICT third-party providers, distinguishing those that support critical or important functions. It must be available to the competent authority on request, in a specified format.

The register is one of the most concrete DORA artefacts — and one the Central Bank flagged for early compliance. Here is what it is and what goes in it.

What the register is

The register of information is a complete, structured record of your ICT third-party contractual arrangements at entity, sub-consolidated and consolidated levels. In 2025, Irish firms submitted registers to the Central Bank, and maintaining it is now an ongoing obligation.

What it must contain

Diagram of the main field groups in a DORA Article 28 register of information: entity level, contracts, providers, services, functions and subcontracting chain
What the Article 28 register of information covers.

For each arrangement, the register captures details such as the provider, the service, the function it supports, whether that function is critical or important, and contract terms. It must distinguish CIF-supporting arrangements from the rest.

CIF vs non-CIF arrangements

Arrangements supporting critical or important functions carry heavier obligations (including the Article 30 contract clauses), so correctly classifying each arrangement is essential. This depends on having mapped your critical functions — see Mapping critical or important functions.

Format and keeping it current

The register must follow the specified format and be kept up to date as contracts change. It is not a one-off submission — it is a living record.

Next step

Building your register? Download our register template or ask CyberLabs for help.