The DORA Register of Information at BaFin: Process, Formats and Common Errors

Boris Friedrich
Boris Friedrich
12 min read
The DORA Register of Information at BaFin: Process, Formats and Common Errors

Shortly before submission, the picture is the same in many institutions: the list of ICT service providers consists of three Excel files from three departments, the subcontractor chains have gaps, and nobody has produced an xBRL export yet. By the end of the submission window, all of that has to become a validated, complete register on the BaFin platform.

The register of information has to be submitted once a year under Article 28(3) DORA. BaFin opens a fixed window of roughly three weeks for this every year and accepts the register exclusively via its reporting and publication platform. In 2026 that window ran from 9 to 30 March. No extension, no goodwill.

This article explains what the register of information actually requires, which errors BaFin sees most often, and how to get a submission through validation in three weeks.

What is the DORA Information Register?

Article 28(3) of DORA requires every financial entity within the scope of the Regulation to keep a complete register of all contractual agreements with third-party ICT service providers. That sounds like a table - but it is a complex reporting system with clear technical specifications.

The register records:

  • All ICT service providers who provide services to the company - internally and externally
  • Any contractual agreements that support critical or important functions
  • The full subcontracting chain, at least up to the first external subcontractor
  • Risk classification, contract terms, notice periods and exit plans
  • Information on the data location and the legal location of the service provider

Important:The register goes far beyond classic swap directories. Other ICT services must also be recorded - i.e. services that do not constitute formal outsourcing but still support operational functions.

The BaFin submission window: a fixed period in spring

BaFin sets the submission period every year and publishes it on its DORA page. In 2026 it ran from 9 to 30 March. Within that window, every financial entity has to submit its updated register of information via the reporting and publication platform (MVP). As of August 2026, BaFin had not yet announced the date for 2027.

The most important key data:

  • Reference date: the register must reflect the status as of 31 December of the previous year
  • Format: Exclusively as a structured xBRL file (ESA taxonomy) or via the BaFin Excel template
  • Portal: Submission only via the “Digital Operational Resilience Act (DORA)” specialist procedure in the BaFin-MVP
  • Validation: After submission, companies receive an error log - errors must be corrected at short notice and the register resubmitted
  • Test procedure: Test submissions can be made in advance using the specialist procedure “TEST: DORA”.

No technical changes to the taxonomy:The ESAs have not made any changes to the xBRL taxonomy for the 2026 submission process. If you already had your data in the right format in 2025, you don't have to adjust the structure - just update the content.

600 incidents in 12 months: Why the register is so important now

The numbers speak for themselves: Since January 2025, BaFinover 600 serious ICT incidentsregistered in the German financial sector. 63 percent of these incidents were directly related to external third-party ICT service providers.

The information register is not a bureaucratic end in itself. It is the central instrument that supervisors use to identify systemic dependencies in the financial sector. Based on the registers submitted in 2025, the European Supervisory Authorities (ESAs) have for the first time named 19 critical third-party ICT service providers - including Amazon, Microsoft and Google. These are now under direct surveillance.

Blog image

Three insights from the submissions so far:

  1. Concentration risk is real: The top 10 critical ICT service providers hold over 85 percent of all contracts. An outage at a single provider can affect hundreds of institutions at the same time.
  2. 75 percent of critical service providers are located in third countries: predominantly in the USA. The data location may be European, but the decision-making power often is not.
  3. Lack of exit plans: Many financial companies do not have a documented exit plan for their key ICT contracts. The more difficult it is to replace, the less often a plan exists - exactly the opposite of what DORA demands.

What exactly needs to be included in the register?

The DORA information register is structured in several tables that follow the ESA taxonomy. Financial companies must provide comprehensive information for each ICT contract:

At the corporate level

  • LEI (Legal Entity Identifier) of the reporting company
  • Consolidation level: Individual message (.IND) or consolidated message (.CON) for groups
  • Identification of all critical and important business functions

At the contract level

  • Complete contract identification (contract type, term, notice periods)
  • Mapping to supported business functions
  • Risk Classification: Does the contract support a critical or important function?
  • Costs and compensation structure
  • Data location: Where is the data processed and stored?

At the service provider level

  • LEI or comparable identification of the ICT third-party service provider
  • Legal location and headquarters
  • Subcontractor information — the entire chain for critical functions
  • Substitutability: How easily can the service provider be replaced?

Special attention for subcontractors:If an intra-group ICT service provider uses subcontractors, the chain in the register must always include at least the first external subcontractor — even if the service does not support a critical function.

The most common errors when submitting

BaFin addressed the typical problem areas during its workshops on February 24 and 26, 2026. Experience from the first year of submissions in 2025 shows recurring sources of error:

1. Inconsistent foreign keys

The tables of the information register are linked to each other. The LEI in table B.01.02 must exactly match the LEI in the contract tables. Even one typing error leads to an automatic rejection by the validation system.

2. Incomplete subcontractor chains

Many institutions only record their direct service providers, but not their subcontractors. DORA requires the full chain — especially for services that support critical functions.

3. Incorrect file formats

BaFin only accepts xBRL files according to the ESA taxonomy or the official Excel template. Custom Excel formats, CSV exports or PDF uploads will be rejected.

4. Lack of risk classification

Not every ICT contract is equally critical. But the “supports critical/important function” assignment must be documented for each contract. Companies that make general classifications here risk questions.

5. Outdated contract data

The register must reflect the status as of December 31, 2025. Contracts concluded or terminated in 2025 must be recorded accordingly. A register based on the status of 2024 will not be accepted.

Practical guide: the submission in three weeks

Three weeks is short. But doable. Here is the timetable:

Blog image

Week 1: Data collection and consolidation

  • Merge existing contract registers from purchasing, IT, compliance and risk management
  • Identify gaps: Which ICT service providers are missing? Which subcontractors are not included?
  • Verify LEIs of all service providers
  • Carry out test submission via the BaFin test procedure

Week 2: Validation and quality assurance

  • Evaluate and correct error log of test submission
  • Check foreign keys and cross-references between tables
  • Coordinate risk classification with the specialist departments
  • Document exit plans for contracts with critical functions

Week 3: Submission and correction

  • Carry out final submission via BaFin-MVP
  • Check the productive submission error log immediately
  • Submit corrections within the deadline
  • Secure internal documentation of the submission for audit purposes

What happens if you miss the deadline?

DORA is an EU regulation with direct application. BaFin has defined the submission of the information register as a supervisory obligation. Anyone who does not submit on time must expect:

  • Supervisory inquiries and measures by BaFin
  • Increased inspection intensity for upcoming on-site inspections
  • Reputation risks in internal and external reporting
  • In extreme cases: fines according to the Financial Market Digitization Act (FinmadiG)

BaFin made it clear in its workshop: Onehigh data qualityis expected. “Correctness and completeness” were the core messages. The days when you could submit a half-finished register are over.

The larger context: DORA 2026 goes far beyond the register

The information register is just one of the five DORA pillars. BaFin has set its audit priorities for 2026:

  • ICT risk management framework: Is it documented, approved by management and embedded in operations?
  • Incident Reporting: Can your company meet the 4-hour initial reporting deadline for serious ICT incidents?
  • Resilience testing: BaFin expects the first evidence of basic tests carried out and - for systemically important institutions - threat-led penetration tests (TLPT) in 2026.
  • Contract adjustment: Existing ICT contracts must be adapted to the DORA minimum contract contents. For institutes under BAIT/VAIT/KAIT/ZAIT, a transition period applies until January 1, 2027

Conclusion: The information register is the litmus test for your DORA readiness

Submitting the information register is not just a reporting requirement. It is the first real test by which BaFin recognizes how seriously an institution takes DORA. Anyone who submits a complete, validated register on time signals compliance maturity. Anyone who does not do so will be on the list for the next on-site inspection.

Do not wait for the window. Institutions that keep the register, their contracts and their exit plans current all year reduce the submission to a formality. The BaFin materials, Filling instructions, Excel template and Error codes, are solid. Use them.

If you need support with DORA implementation — from register preparation to the overall strategy —talk to our experts. ADVISORI has been supporting financial companies in regulatory transformation projects for years.

Frequently asked questions about the DORA information register

Which companies must submit the information register?

All financial companies within the scope of DORA - banks, insurance companies, payment service providers, investment firms, crypto service providers and other players in the financial sector.

In what format must the register be submitted?

As a structured xBRL file according to ESA taxonomy or via the official BaFin Excel template. Other formats are not accepted.

What happens after submission?

BaFin carries out an automatic validation and sends an error log. Incorrect submissions must be corrected and resubmitted within the deadline.

Do ICT service providers within the group also have to be recorded?

Yes. Internal ICT service providers and their external subcontractors must also be recorded in the register.

What is the difference between individual and consolidated reporting?

Sole proprietorships file an individual report (.IND). Financial groups can submit a consolidated report (.CON) at the group level, but must cover all individual companies in the group. Where the boundary between individual and consolidated reporting is unclear, our DORA reporting and register support helps you draw it.

Hat ihnen der Beitrag gefallen? Teilen Sie es mit:

DORA in 12 Weeks — from ICT Register to TLPT

We structure your DORA implementation in a 30-minute strategy session and deliver gap-analysis plus the rollout roadmap.

30 Minuten • Unverbindlich • Sofort verfügbar

Further reading

Continue exploring with related insights from our experts.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance