Short answer
Under the EU Digital Operational Resilience Act, which applies from 17 January 2025, financial entities must maintain a register of information covering every contractual arrangement with ICT third-party service providers, flagging those that support critical or important functions, and submit it to their competent authority on request in the prescribed format.
Key takeaways
- DORA applies from 17 January 2025.
- The register covers all ICT third-party arrangements, not only critical ones.
- Arrangements supporting critical or important functions need extra detail.
Timeline
How DORA came into force
- Published in the Official Journal
- Entered into force
- Applies to financial entitiesRegisters of information must be maintained from this date.
Who has to keep the register
All financial entities in DORA's scope, at entity level and, where applicable, at sub-consolidated and consolidated level.
What goes in it
- Contract references, dates and governing law.
- The ICT services provided and the functions they support.
- Subcontractors that effectively underpin critical services.
- Data location and processing locations.
Sources
- Regulation (EU) 2022/2554 (DORA), EUR-Lex