DORA Information Registry: Submission, Deadlines, and Reporting Requirements under Article 28, Paragraph 3
This text was generated using artificial intelligence (AI).Financial firms within the scope of DORA submit their information register to BaFin annually—exclusively through a dedicated process on the Reporting and Publication Platform (MVP), either as a structured xBRL-file or via the BaFin Excel Template. The legal basis is Article 28, paragraph 3 Regulation (EU) 2022/2554, which, pursuant to Article 64 thereof, has been in effect since January 17, 2025 applies. This article explains what needs to be included in the register, which deadlines BaFin specifies, and when a filing is considered complete.
At a Glance:
- Legal basis: DORA, Regulation (EU) 2022/2554, Article 28, paragraph 3 (Chapter V, Section I); Effective as of January 17, 2025
- Submission method: BaFin-MVP, Sector-Specific Procedure „Digital Operational Resilience Act (DORA)“
- Formats: structured file (xBRL, Taxonomy of the ESAs) or BaFin Excel Template — no other format
- Effective date starting in 2026: December 31 of the previous year; Forwarding to the ESAs by the supervisory authority through March 31 of each year
- The report is considered complete only when, when they ESAs' Validation Rules has happened successfully
What Article 28, paragraph 3 requires—and how BaFin interprets it
Article 28(3) of DORA requires financial firms to „maintain and update an information register as part of their ICT risk management framework at the enterprise level, as well as at the subconsolidated and consolidated levels,“ covering all contractual agreements regarding the use of ICT services. The second subparagraph requires appropriate documentation that distinguishes between agreements for critical or important functions and all others. The third subparagraph requires an annual report on the number of new agreements, the categories of third-party ICT service providers, and the type of services. The fourth subparagraph requires the submission of the complete register „upon request,“ while the fifth requires the prompt notification of planned agreements for critical or important functions.
The annual The requirement to submit information does not arise directly from the text of the regulation, but rather from its supervisory implementation: Because the ESAs require the registers for the annual classification of critical third-party ICT service providers, Guideline 5 of the Joint Guidelines on Supervisory Cooperation stipulates that the competent authorities must submit them. BaFin derives the annual submission requirement from this, as set forth in the fourth subparagraph.
The annual report is not a second filing
One issue regularly causes unnecessary work: the report on the Number of New ICT Contracts According to the third subparagraph, the current position of BaFin is that No separate report required. BaFin assumes that this obligation is fulfilled by the annual submission of the information register and plans to determine the number of new ICT contractual relationships on its own—specifically to further reduce the burden on financial institutions.
So anyone who sets up their own process to report this metric separately via the MVP is, as things stand today, creating a procedure that the regulator does not expect. Nevertheless, the metric remains practically relevant: It arises naturally from a well-maintained register, and its traceability over the course of the year is a good indicator of whether register maintenance is actually performed on an ongoing basis or only shortly before the reporting deadline. Since BaFin’s interpretation reflects the current state of affairs, it is one of the points that should be reviewed again before each filing cycle.
What Belongs in the Register: Subcontractors, Too
The scope is often defined too narrowly. The register is intended to provide an overview of all contracts with third-party ICT service providers that provide ICT services to the financial institution. For services that critical or important functions Supporting this is not enough: In that case, the registry includes not only direct third-party ICT service providers but also all subcontractors who ensure the provision of the service.
A separate rule applies to in-group service providers. If an in-group ICT service provider uses subcontractors to provide its services, the ICT service chain in the registry must always include at least the first subcontractor outside the group include — even if the services provided do not support critical or important functions.
For data collection, this means that the „critical or important“ classification determines the depth of the supply chain that must be documented. If a function only becomes critical during the course of the year, the number of subcontractors that must be included in the registry grows accordingly. This interdependence between functional criticality and the depth of the registry is the reason why the criticality assessment should precede the creation of the registry, and not the other way around.
Submission via the MVP: Technical Procedures, Formats, Reporter Activation
BaFin accepts information registers exclusively via the „Digital Operational Resilience Act (DORA)“ specialized procedure in the MVP. Exactly two formats are permitted: a structured file in the xBRL-format that conforms to the ESAs' taxonomy, or the BaFin Excel Template. The ESAs have not made any technical changes to the taxonomy for the 2026 submission process.
The Excel template exists for a specific reason: Unlike the test run in the summer of 2024, for the regular submission No conversion tool from the ESAs. BaFin has provided the template as an alternative to the structured file, and the specified structure must be strictly adhered to.
From an organizational standpoint, the Detector Activation The first hurdle: Every financial institution must have its designated reporters activated for the DORA technical procedure before a submission can be made. A separate technical procedure, „TEST: Digital Operational Resilience Act (DORA),“ is available for test runs. In addition, BaFin provides instructions for completing the form, a sample completed Excel template, an overview of possible error codes along with solutions, and guidance on submitting reports via the MVP portal.
Key Dates and the Annual Cycle
For the first cycle, the deadlines were set in a way that clearly explained the mechanism: The ESAs expected the competent authorities to submit the registers by April 30, 2025, it should include all contract information as of the effective date March 31, 2025. This resulted in a filing period for companies under BaFin supervision from April 14–28, 2025, with a deadline no later than April 28, 2025.
Starting in 2026, a permanent schedule will apply: The submission of the registers to the ESAs will take place by March 31 of each year takes place, and the ledgers must contain all contract information as of the reference date December 31 of the previous year include. For the 2026 cycle, BaFin has set the cutoff date accordingly December 31, 2025 and a submission window from March 9–30, 2026 derived.
Under this system, the cutoff date for the next cycle is already known as soon as a year ends—however, BaFin announces the specific submission window separately each time. Those who time their registry maintenance to coincide with the end of the calendar year rather than the March window are working with the rhythm rather than against it.
When a Submission Is Considered Complete
This is where submissions often fall through in practice: Uploading the file is not the end of the process. After the submission, financial institutions receive a Error Log; any errors must be corrected promptly, and the information register must be resubmitted. The register is considered to have been submitted in compliance with regulatory requirements only when it in accordance with the ESAs' validation rules was successfully submitted.
Companies can track the status in the submission log on the MVP portal. If the submission is accepted by the ESAs, this will be indicated there—however, due to the forwarding process, it may take a few days for the submission to appear in the log. If the submission is rejected, the portal lists the errors that were flagged; these must be corrected immediately, and the corrected register must be submitted via a separate, new report to upload it again.
In addition, after receiving the registers, the ESAs conduct further data quality checks that may reveal inconsistencies in the content. The BaFin forwards this feedback via the MVP mailbox; beyond the list of anomalies, it has no further information. It is therefore up to the financial institution to resolve these issues. BaFin expressly points out that a high level of data quality—in terms of accuracy and completeness—is expected.
Reporting Requirements and the Proposed Relief for Duplicate Reports
In addition to filing a registration, Article 28(3), subparagraph 5, requires that the supervisory authority be promptly notified of any planned contractual arrangement to support critical or important functions—and likewise if a function has subsequently become critical or important.
Because the sector-specific outsourcing regulations apply in addition to DORA, this reporting requirement overlaps in many cases with existing reporting obligations. BaFin specifically identifies the legal basis for these obligations: Section 24(1)(19) of the German Banking Act (KWG), Section 47(8) and (9) of the German Insurance Supervision Act (VAG), Section 28(1)(10) of the German Capital Markets Act (ZAG), Section 36(2) of the German Capital Markets Act (KAGB), and Section 64(1)(13) of the German Securities Trading Act (WpIG).
To avoid duplicate filings, BaFin is revising the MVP specialized procedure „Notification of Outsourcing,“ which has been in use since the end of 2022: In the future, a simple checkbox will suffice to fulfill both the sector-specific and DORA requirements with a single filing. BaFin has not yet announced a date for this change. Until then, the interim procedure applies: Submit outsourcing notifications as usual via the MVP portal and add the DORA notification via a change or update report once the revision is complete. If a case arises for which no outsourcing notification is required, the company must inform BaFin via email using a provided Excel form.
What this means for data maintenance
The registry does not require a snapshot, but rather a dataset that is reliable as of the reference date and clearly tracks changes throughout the year—including contract signings and terminations, as well as changes to ICT functions. Two of these requirements can be supported technically:
- C-VRM (Vendor Monitoring) can collect information on third-party providers in a structured and ongoing manner, so that details on the ICT service providers listed in the registry are not compiled only as of the reporting date.
- EASM (Asset Inventory) can reveal and document asset holdings that are not tracked internally—or are no longer tracked—which is helpful in situations where the level of detail in the records depends on the criticality of a function.
Neither of these replaces the criticality assessment nor the regulatory classification; they provide the data foundation for both. For organizations that consider the location of processing when dealing with compliance data: LocateRisk is Made in Germany, designed in accordance with GDPR requirements, ISO 27001 Certified and is operated exclusively in certified German data centers, without any data processing by U.S. providers.
Sources and further information
—
A note on our own behalf: This article reflects the legal situation as of the date of publication. Since IT law and compliance requirements are highly complex, this text is intended solely as a general guide and does not constitute legally binding advice. If in doubt, we recommend seeking legal counsel regarding implementation within your company. We assume no liability for the content.
Frequently asked questions
The information register under Article 28(3) of DORA is a list of all contractual agreements regarding the use of ICT services provided to a financial firm by third-party ICT service providers. It is maintained at the company level as well as at the sub-consolidated and consolidated levels and is continuously updated; a distinction must be made between agreements for critical or important functions and all others. For services related to critical or important functions, subcontractors must also be included in the register.
Not upon upload. After submission, financial firms receive an error log; errors must be corrected promptly, and the register must be resubmitted. It is considered properly submitted for regulatory purposes only after it has successfully passed the ESAs’ validation rules. The status is shown in the submission log on the MVP portal; however, confirmation may take several days due to the forwarding process to the ESAs. If the submission is rejected, the corrected register must be uploaded via a separate, new submission.
Starting in 2026, the registers must include all contract information as of December 31 of the previous year; the competent authorities must forward this information to the ESAs by March 31 of each year. For the 2026 cycle, BaFin specified December 31, 2025, as the reference date and a submission window from March 9 to March 30, 2026. Only a structured xBRL file compliant with the ESAs’ taxonomy or BaFin’s Excel template is permitted.
As of August 19, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since this was published; the linked vendor advisory is always authoritative. Despite careful research, we assume no liability for the timeliness, accuracy, or completeness of this information.