Operational notes Regulation

DORA’s ICT register: the deadline is fixed, the subcontracting chain is not

6 min read

Aerial roots of a large tree hanging in vertical bundles from the branches down to the ground, some thick and rooted in the soil, others thin and still suspended, black and white photograph
There is one trunk. The roots that hold it up are counted one by one, and no one has ever counted them all together.

15 March 2026 is less than six months behind us, and it was the first real dry run of an obligation Regulation (EU) 2022/2554 — DORA — has imposed since 17 January 2025: keeping, and reporting to the supervisor, a complete register of every contractual arrangement with an ICT third-party service provider. Not just any supplier list: a register that must state, contract by contract, which technology services support a company’s most sensitive functions — and through how many layers of subcontracting. We already covered the concentration risk around the major cloud providers designated critical; here the question is different, and it applies to every financial entity, not only the largest ones: who inside the company can actually answer it in full?

The obligation, article by article

Article 28(3) of DORA is the direct source: “financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers.” Not every arrangement is treated the same way: they must be documented “distinguishing between those that cover ICT services supporting critical or important functions and those that do not.” At least once a year, entities report to the competent authority the number of new arrangements, the categories of providers and the services provided; on request, they must make available “the full register of information or, as requested, specified sections thereof” — and they promptly inform the authority both of any planned contractual arrangements for ICT services supporting critical or important functions and “of the time when a function has become critical or important.”

A technical regulation, and each provider’s rank

DORA does not write the templates used to fill that register: Commission Implementing Regulation (EU) 2024/2956, adopted on 29 November 2024 under Article 28(9), second subparagraph, of the parent Regulation, does. There are fifteen tables, from B_01.01 to B_99.01: who keeps the register, the contractual arrangements themselves, who signs them, who provides the service, the supply chain, the functions supported, the risk assessment. One of them, B_02.03, exists only because of a problem the Regulation names in its recitals: when an intra-group provider relies on an external one, “the register of information should include a specific template enabling the reconciliation between the intra-group contracts and the contracts with ICT third-party service providers that are external to the group.” Article 2 of the same Regulation assigns every provider a “rank”: a natural number starting at 1 for the direct provider and increasing by one for every subcontractor further down the chain. In the worked example the Regulation itself provides, a single contract can generate different chains for different services: provider X is ranked 1 for service A, which it delivers alone, but also ranked 1 for service B — with subcontractor Y, which delivers that service on its behalf, ranked 2. One contract, two supply chains, one register that must hold both.

Not every subcontractor: only those that actually support the function

The Regulation does not ask for a census of every supplier’s supplier. It says so in its recitals: providing ICT services “may rely on potentially long or complex chains of subcontracting,” but financial entities must record “only those subcontractors that effectively underpin ICT services supporting critical or important functions or material parts thereof” — the same test repeated in Article 3(2)(b) as an operative requirement for the templates. It is a proportionality filter, not an exemption: applying it requires already knowing, service by service, whether it supports a critical or important function, and whether that particular subcontractor genuinely underpins it — the question the register is meant to reflect, not the one it answers on its own.

The piece no single department holds in full

That is where the operational difficulty sits. Contracts with ICT providers live in legal or procurement. The supplier list, with registries and LEI codes, lives in vendor management. Which IT systems support which business process is something IT may or may not know with certainty. Which processes count as a critical or important function — a risk classification, not a technical judgment — is the risk function’s call, and it does not always use the same criteria as IT. And the layer furthest downstream, the direct provider’s own subcontractors, is not data the company already holds: it has to be requested from the provider itself. And the burden of getting it right stays with the financial entity, not with the supplier who answers: Article 3(6) requires the entity to ensure, “tramite il fornitore terzo diretto di servizi TIC” (through the direct ICT third-party service provider), that every subcontractor effectively underpinning the critical function uses a valid and active LEI or provides its own EUID. None of these five points, on its own, holds the complete map: which service, for which function, through how many providers.

A deadline already set, and already missed once

The date is not in the European Regulation, which only says “at least once a year”: Banca d’Italia set it, in a notice dated 13 February 2026. Italy’s central bank explained that financial entities make the register available to the competent authority by submitting it through the INFOSTAT platform, under Article 28(3) of DORA. On timing it was specific: the first collection took place in April 2025; from 2026 onward, subsequent collections are set on an annual basis, with the deadline for submitting data to Banca d’Italia falling on 15 March each year, referenced to data as of the previous 31 December. Submitted registers go through data-quality checks; where anomalies turn up, the entity must correct the errors and resubmit. The next deadline is 15 March 2027, covering data as of 31 December 2026: whoever starts mapping the chain now arrives in March with a verified register, not a form filled in a hurry in February.

What we could not verify

We do not determine whether any specific company falls within the “financial entities” covered by Article 2 of DORA: banks, investment firms, payment and e-money institutions, insurers and many other listed categories, each to be checked case by case. We have not verified whether Banca d’Italia applies proportionality carve-outs beyond those the Regulation itself grants to microenterprises, nor the specific penalties in Italy for an incomplete or late register.

See the service · Talk to an engineer

The two axes, applied to the register of information

Complying. The question “is the register filled in?” becomes, in our system, a check run per contractual arrangement: which ICT service it covers, which function it supports, whether that function is critical or important, what rank each provider holds in the chain — direct or subcontractor — and whether each one’s LEI or EUID is still valid. Not an annual form, but a map that still holds up on 16 March.

Deciding. The same system brings contracts, supplier records, the IT map and risk classification together into a single operating model, on which AI agents execute decisions with a human operator in command. Always on-premises, on autonomous machines that need no deep integration into the client’s network, or on dedicated cloud, with a dedicated VPN and a data centre in Italy. It is the method behind our platform.

Could you say today, for an ICT service supporting a critical function, how many subcontractors actually deliver it, and whether each one holds a valid LEI? Half an hour with one of our engineers is enough for the first map.

Sources